When should an ISO/IEC 27035 incident be escalated?
Escalate when the incident is not under control, can cause severe adverse impact, exceeds the current coordinator's authority, needs more or different responders, or approaches an organization-defined time or impact limit. Route the relevant decision when legal, contractual, safety, privacy, insurance, supplier, continuity, or communications criteria may apply. Examples include seeking approval to isolate a critical production service, activating crisis management after core services stop, asking privacy counsel to assess an affected-person notice, or calling a supplier whose evidence or recovery action is required.
The handoff should state current facts and uncertainty, severity and scope, affected information, systems and services, actions taken, outstanding decisions, evidence location, time constraints, required authority, and the next checkpoint. A named recipient must acknowledge the request and either accept ownership or redirect it to a named alternate; copying a mailbox or manager does not complete the handoff.
- Define escalation triggers and contacts by severity and incident type, with primary and backup routes.
- Allow responders to escalate on uncertainty when waiting for certainty would increase harm.
- Record who escalated, who accepted, when, why, what changed, and whether notification or response targets changed.
ISO listing for the 27035-1 incident-management process, including detecting, reporting, assessing, responding, and escalation-relevant coordination.
Primary ISO listing for planning, preparing, and lessons-learned guidance.
NIST distinguishes escalation, which generally increases resources or changes time frames, from elevation, which involves a higher management level; it recommends risk-based criteria for both.