FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
39of39items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
ISO/IEC 27035 Lessons Learned

What evidence should connect a lesson to action?

Link each lesson to the incident report, timeline, exercise observation, vulnerability, metric, or repeated event pattern that supports it. Keep the proposed change, affected control or plan element, risk, owner, priority, due date, dependency, approval, implementation evidence, and effectiveness result.

Preserve decisions not to act. The record should identify the decision authority, rationale, residual risk, review trigger, and any compensating action instead of making the recommendation disappear.

  • Distinguish an observation, a proposed lesson, an approved action, and a verified improvement.
  • Use version-controlled plan, playbook, control, training, contract, or tool changes as implementation evidence.
  • Verify high-risk changes through an exercise, control test, later incident, or another suitable measure.
Citations
ISO/IEC 27035 Lessons Learned

Who should own and approve lessons learned?

The incident coordinator and incident management team should assemble the evidence and propose improvements. The owner who controls the affected system, process, supplier, control, budget, or policy should accept the action; the relevant risk or management authority should approve rejection, deferral, or residual risk.

Include affected responders and business owners when validating the finding. Legal, privacy, human resources, communications, safety, continuity, or supplier owners should join only when the lesson falls within their responsibility.

  • Assign one owner for each action even when several teams contribute.
  • Escalate overdue or disputed high-risk actions to the forum that can fund work or accept risk.
  • Keep approval and closure evidence with the action record.
Citations
ISO/IEC 27035 Lessons Learned

When should lessons be identified and verified?

Begin after the incident is resolved and enough evidence is stable for useful analysis. Do not wait for one large incident: ISO/IEC 27035 also supports learning from multiple incidents, reported vulnerabilities, exercises, and performance data.

Review open actions at planned intervals and when their assumptions, risk, owner, dependency, or target system changes. Close an action only after checking the agreed acceptance criteria and recording the result.

  • Aggregate recurring weak signals that do not justify separate major reviews.
  • Feed unresolved material items into risk management or management review.
  • Reopen a closed lesson when later evidence shows that the change did not work.
Citations
ISO/IEC 27035 Lessons Learned

What is the scope and cadence of the ISO/IEC 27035 phase?

ISO/IEC 27035-1:2023 makes learning lessons part of the generic incident-management process for organizations of any type, size, or nature. ISO/IEC 27035-2:2023 provides the detailed improvement activities: review the plan, evaluate team performance, improve control implementation, update risk assessment and management-review inputs, strengthen awareness and training, and improve relationships, tools, and metrics. ISO/IEC 27035-3:2020 supplies operational evidence from ICT response.

The standards do not prescribe a universal meeting deadline, review period, action due date, or closure threshold. The organization should set a cadence proportional to incident risk and capability needs. A severe or novel incident can justify an immediate review; recurring low-impact events can be aggregated; urgent containment and control fixes should proceed without waiting for the full lessons cycle.

  • Apply the edition named by the organization's policy, adoption decision, contract, or management-system scope.
  • Trigger an out-of-cycle review after a material incident, failed exercise, repeated classification error, supplier failure, or significant change to services, risks, law, or authority.
  • Keep an action open until implementation and effectiveness are evidenced, or the authorized owner records rejection, deferral, or accepted residual risk with a review trigger.
Citations
ISO/IEC 27035 Notification Evidence

What evidence should support an incident-notification decision?

Keep the controlling law, contract, policy, or authority instruction beside the decision record. Record the covered entity or service, jurisdiction, incident category, threshold analysis, facts known at the time, when any reporting clock began, decision owner, approver, recipients, submission channel, content and attachments sent, delivery evidence, acknowledgement, and required updates or final reports. A point of contact can receive the report, but the notification matrix should identify who has authority to decide and submit each external notice.

Preserve decisions not to notify. The record should identify the threshold applied, facts and uncertainty considered, legal or contractual review where needed, approval, and the change in facts that would trigger reassessment. ISO/IEC 27035 organizes this work but does not supply the external deadline or reporting threshold.

  • Separate internal operational alerts, management escalation, regulator or contractual notices, affected-person communications, law-enforcement reports, insurer notices, and public statements; each can have a different trigger, clock, content rule, recipient, and approver.
  • Version each notification with its preparation and submission times so later updates do not overwrite what was known and sent earlier.
  • Restrict sensitive content, use the authorized channel, and retain a copy of the submitted content plus transmission, delivery, rejection, and acknowledgement records.
Citations
ISO/IEC 27035 Notification Evidence

How should notification evidence be tested and maintained?

Test the notification procedure in exercises and sample completed incidents. A reviewer should be able to trace the alert or incident through threshold assessment, approval, submission, acknowledgement, follow-up, and closure without reconstructing the record from personal mailboxes.

Maintain a notification matrix by jurisdiction, entity, service, incident type, recipient, threshold, clock-start rule, channel, required content, approver, update cadence, and evidence location. Legal or regulatory owners should verify entries when the controlling source changes.

  • Test backup contacts, unavailable portals, rejected submissions, partial facts, and out-of-hours approval.
  • Keep clocks in the time zone and format required by the controlling rule, and record the basis for the chosen start time.
  • After an incident or exercise, correct contact details, decision criteria, templates, access rights, and handoffs that failed.
Citations
ISO/IEC 27035 Notification Evidence

Who should decide and approve an external notification?

The incident coordinator should assemble the operational facts and keep the record moving. The person authorized under the controlling law, contract, or policy should decide or approve the notification; that can involve legal, privacy, regulatory, customer, insurance, communications, or business leadership.

Predefine substitutes and emergency authority. Approval must not become an avoidable delay where a deadline applies, and the incident team should continue containment and evidence preservation while the notification decision is pending.

  • Record who supplied facts, who interpreted the threshold, who approved the content, and who submitted it.
  • Escalate conflicts between operational facts and legal interpretation to the named decision authority.
  • Limit factual, privileged, personal, or security-sensitive material to recipients and channels that are authorized to receive it.
Citations
ISO/IEC 27035 Notification Evidence

When should a notification decision be reassessed?

Reassess whenever new facts change the affected systems, people, geography, duration, impact, cause, or confidence in the original analysis. Also reassess when containment fails, a supplier supplies new facts, another authority becomes relevant, or the controlling rule requires an update or final report.

Do not silently replace the first decision. Add a timestamped decision showing what changed, which threshold was reconsidered, who approved the result, and whether another communication is due.

  • Track pending facts and the person responsible for obtaining them.
  • Link each update to the earlier submission and retain both versions.
  • Close the notification record only after required acknowledgements, corrections, updates, and final reports are resolved.
Citations
ISO/IEC 27035 Notification Evidence

Which ISO parts and dates govern notification evidence?

ISO/IEC 27035-1:2023 supplies the generic incident-management process and core roles. ISO/IEC 27035-2:2023 covers policy, plans, relationships, legal and regulatory considerations, recordkeeping, forms, exercises, and lessons learned. ISO/IEC 27035-3:2020 covers ICT notification, triage, internal reporting, external reporting where required, and report storage. These editions apply when the organization adopts or is contractually required to use them; the standards do not set a statutory commencement date.

No ISO/IEC 27035 part supplies one global threshold or deadline for external notice. The controlling jurisdiction, regulated entity or service, affected people, contract, insurer term, or authority instruction determines whether a report is required, when its clock starts, what it must contain, and whether interim, corrected, or final reports are due. Treat ISO as the operating framework and the external rule as the source of the duty.

  • Record the ISO edition, local procedure version, and controlling external source used for each decision.
  • Reassess the matrix when laws, regulator forms, contracts, services, suppliers, contacts, portals, or time-zone rules change.
  • Do not stop response, containment, or evidence preservation while an external notification decision is pending.
Citations
ISO/IEC 27035 Post Incident Review

How should a post-incident review be run?

After recovery, create a timeline from event and incident records and compare actual detection, assessment, decisions, response, communications, recovery, and evidence handling with the plan. Include the incident coordinator, relevant responders, affected business or service owners, providers, control owners, and the incident management team members needed to route improvements.

The depth should match the incident's nature and severity. Separate urgent remediation from longer-term improvements, and record unresolved facts rather than forcing a final cause. Each action needs a risk-based priority, owner, due date, acceptance criteria, dependency, evidence, and closure authority.

  • Review what worked as well as failures, including informal adaptations worth formalizing; for example, a monitoring rule that detected lateral movement, an emergency authority that allowed timely isolation, or a supplier handoff that delayed recovery.
  • Address technical, process, people, supplier, communications, legal, continuity, and evidence issues.
  • Feed conclusions into the incident plan, playbooks, risk assessment, controls, training, exercises, metrics, and management review.
Citations
ISO/IEC 27035 Post Incident Review

What should the post-incident review record contain?

Keep the reviewed timeline, participants, evidence consulted, scope and limitations, confirmed findings, unresolved questions, causes and contributing conditions where supported, what worked, failed controls or handoffs, and recommended actions. Link the review to the incident report without duplicating sensitive evidence unnecessarily.

Distinguish facts from hypotheses and recommendations. If legal privilege, personnel confidentiality, law-enforcement restrictions, or supplier terms limit circulation, retain a controlled full record and an appropriate operational version rather than omitting the limitation.

  • Reconcile conflicting timestamps and identify the clock source used.
  • Record who validated each material finding and what evidence supports it.
  • Move approved actions into the normal system used to track owners, due dates, evidence, and closure.
Citations
ISO/IEC 27035 Post Incident Review

Who should lead and approve the review?

The incident coordinator should ensure the post-incident activity occurs and that the incident report is complete. A reviewer with enough independence to challenge the response should lead or validate significant reviews, while affected teams confirm factual accuracy.

The owner with authority over each affected control, service, supplier, policy, or budget should accept the related action. The appropriate risk or management authority should approve rejected, deferred, or residual-risk decisions.

  • Separate factual validation from approval of corrective action.
  • Avoid assigning final approval only to the team whose performance is being reviewed.
  • Record disagreements and the authority that resolved them.
Citations
ISO/IEC 27035 Post Incident Review

When should a post-incident review occur and close?

Start after recovery when the incident's nature and severity justify a dedicated review and the essential records and participants are available. Immediate containment or safety actions should not wait for the review, and a complex investigation may require an interim review before all facts are final.

The meeting or report can close once its scope, evidence limits, findings, and actions are approved. Corrective actions remain open in their tracking system until implemented, evidenced, and checked against their acceptance criteria.

  • Set a review trigger by incident type and severity rather than requiring the same ceremony for every event.
  • Reopen findings when later forensic, supplier, regulator, or recovery evidence changes the analysis.
  • Aggregate minor incidents when a pattern offers more useful evidence than separate reviews.
Citations
ISO/IEC 27035 Post Incident Review

How does a post-incident review fit the ISO/IEC 27035 editions?

ISO/IEC 27035-1:2023 defines the generic process and its records, including the incident-management log and incident report. ISO/IEC 27035-2:2023 provides the detailed lessons-learned activities for the plan, teams, controls, risk assessment, management review, training, relationships, tools, and metrics. ISO/IEC 27035-3:2020 provides ICT operational evidence from notification, triage, analysis, containment, eradication, recovery, and reporting.

The standards apply globally to organizations of any type, size, or nature and can be adapted to risk and resources. They do not require the same meeting for every event, prescribe a fixed review deadline, or create legal privilege. The organization should define which incident types, severity levels, near misses, failed exercises, or recurring patterns trigger a dedicated review and should apply separate employment, privacy, litigation, regulatory, contractual, and evidence rules.

  • Record the edition and procedure version applied to the review.
  • Start urgent remediation immediately; do not hold a known containment or safety fix for the review meeting.
  • Reassess findings when later forensic, supplier, regulator, legal, or recovery evidence changes a material fact or assumption.
Citations
ISO/IEC 27035 Retained Logs

Which incident records should be retained, and for how long?

Preserve the event report, incident management log, classification and escalation decisions, response actions, communications, notification records, recovery validation, incident report, lessons learned, and linked evidence needed to reconstruct the case. Maintain an incident register for oversight and trend analysis. Raw telemetry, working notes, malware samples, exports, and forensic images can need different storage, access, and retention rules.

ISO/IEC 27035 does not set a universal number of days or years. Define retention by record purpose, investigation and operational need, applicable law and contracts, privacy and employment rules, limitation periods, insurance terms, and litigation or regulatory holds. A hold is an authorized instruction that suspends ordinary disposal for specified material. Document which rule wins when periods conflict.

  • Document record category, purpose, owner, storage, access, integrity control, retention trigger, period, disposal method, and hold process.
  • Minimize personal or sensitive data while retaining what the justified purpose requires.
  • Review retention rules after legal changes, new services or suppliers, investigations, exercises, and lessons learned.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.

Page 2 of 3