How should teams handle CSIRT Roles under ISO/IEC 27035?
Start with the operational decision: define what CSIRT Roles means in your ISO/IEC 27035 scope, who owns it, and what record proves the decision is current.
In practice, CSIRT work is usually split across a lead who coordinates the response, incident handlers who verify and analyze the event, legal reviewers who check compliance and contract issues, public affairs or media relations who handle external messaging, asset owners who set recovery priorities, and third parties who may assist under contract. The incident lead should also make sure response records are safeguarded, while the communications owner keeps status updates and notifications aligned with policy and law.
- Name the accountable owner and reviewer for CSIRT Roles.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when CSIRT Roles changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
Primary ISO listing for incident management principles and process.
Primary ISO listing for planning, preparing, and lessons-learned guidance.
Lists common incident response roles and responsibilities, including leadership, incident handlers, legal, public affairs and media relations, asset owners, and third parties.