Capture an event report, assess it against prepared criteria, and decide whether it is a false alarm, an event for normal handling, or an information security incident. If it is an incident, assign the incident coordinator and required IRTs, set the response timer, classify and prioritize it, and activate the applicable response and communication procedures.
During response, reassess severity and scope as facts change, preserve decisions and evidence, escalate incidents that are not under control or exceed authority, and validate recovery with affected services. Close according to the policy, notify interested parties as required, then feed the incident report into lessons learned.
Who decides whether an event is an incident?
Under ISO/IEC 27035-1:2023, the incident coordinator evaluates the event report against criteria defined during planning and declares whether it is a possible or confirmed information security incident or a false alarm. The organization may use another title for the role, but it should define the person's authority, alternates, quality-review route, and handover requirements before an event occurs.
Does ISO/IEC 27035 prescribe severity levels or response times?
ISO/IEC 27035 calls for prepared criteria and a classification scale based on actual or projected adverse consequences, but it does not prescribe universal labels such as low, high, or critical, a mandatory scoring formula, or universal response times. The organization sets and tests its own criteria, target resolution times, authority limits, and reassessment intervals. Legal, regulatory, contractual, privacy, safety, and continuity triggers remain separate.
When should incident severity be reassessed?
Reassess severity whenever new information changes the incident's scope, business or technical impact, affected people or services, threat activity, recoverability, evidence risk, or possible external-reporting duties. Also reassess at the next time set in the incident record. Preserve the earlier rating and record the new facts, decision owner, rationale, actions, affected notifications, and next checkpoint.
When must an incident be reported outside the organization?
ISO/IEC 27035 does not create a universal external-reporting threshold or deadline. External reporting depends on the law, regulator, contract, insurer term, customer commitment, law-enforcement basis, or other rule that applies to the organization and incident. Record each possible duty separately with its source, scope test, trigger, clock start, recipient, required content, decision owner, approval, submission time, and update obligations.
Can technical recovery close an incident?
Technical recovery alone should not close an incident. The authorized owner should accept the restored service, system, or data against prepared recovery criteria, while the incident record assigns continuing monitoring, notifications, evidence preservation, investigation, residual risk, final reporting, and improvement work. The active response may conclude while controlled follow-up remains open, but the owner and status of that work must remain traceable.