FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
39of39items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
ISO/IEC 27035 Retained Logs

How should incident records and digital evidence be protected?

For records used only to manage the case, preserve authenticity, access control, version history, timestamps, and links to the incident register. For potential digital evidence, use procedures suited to the intended investigation or proceeding, including identification, collection, acquisition, preservation, integrity verification, access logs, and chain of custody.

Do not describe every operational log as forensic evidence. Apply the stronger handling process when legal prosecution, disciplinary action, litigation, regulatory review, or another evidential purpose is reasonably possible.

  • Record who collected or exported the material, when, from which source, by what method, and where it is stored.
  • Protect original data where feasible and record examinations, copies, transfers, transformations, and integrity checks.
  • Restrict sensitive logs and evidence by role, and keep access records for the full retention period.
Citations
ISO/IEC 27035 Retained Logs

Who should own retention and disposal decisions?

The incident-management owner should define the operational record set with records, system, and security owners. Legal, privacy, human resources, regulatory, insurance, and contract owners should approve the rules that fall within their authority, including holds and restrictions on personal or employee data.

The incident coordinator or evidence custodian should apply the rule to each case and record exceptions. No one should dispose of material covered by an active hold merely because the ordinary retention period expired.

  • Name who can issue, modify, and release a hold.
  • Separate authority to investigate evidence from authority to delete it.
  • Require disposal evidence for sensitive or high-value records when policy or the controlling rule calls for it.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.

ISO/IEC 27035 Retained Logs

When should records be reviewed or disposed of?

Review the schedule when laws, contracts, systems, services, suppliers, storage locations, evidence needs, or incident types change. For each case, check for active investigations, claims, audits, regulator requests, or holds before disposal.

At the end of the approved period, dispose of the record securely unless a documented exception applies. Record the category, authority, date, method, scope, and person responsible without retaining unnecessary copies as proof.

  • Confirm that backups, replicas, archives, provider systems, and exported copies follow the rule or have a documented exception.
  • Test restoration and integrity for records that must remain usable over long periods.
  • Apply data minimization and access restrictions throughout retention, not only at disposal.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.

ISO/IEC 27035 Retained Logs

How should retention periods differ by record category?

Start with the event or incident record's purpose and retention trigger. An intake report can be retained from closure; a case file from incident resolution; evidence from collection or release of a hold; a notification record from submission, acknowledgement, or final resolution; and a contract-specific record from the event defined by that contract. State the trigger explicitly so the period can be calculated consistently.

Examples of distinct categories include searchable case records, security telemetry, authentication and access logs, communications, regulator submissions, malware samples, forensic images, employee-related records, supplier evidence, and lessons-learned actions. These are examples, not ISO-mandated periods. Each category can require a different owner, repository, access group, integrity control, hold rule, period, and disposal method.

  • Apply the edition named by the organization's policy or contract: Part 1:2023 covers the generic process and records, Part 2:2023 covers planning and legal or recordkeeping considerations, and Part 3:2020 covers ICT evidence and report storage.
  • Resolve conflicting minimum and maximum periods with the authorized legal, privacy, records, contractual, and security owners; record the decision and any jurisdiction or data-location limit.
  • Recalculate or suspend disposal when an investigation, claim, audit, regulator request, litigation hold, contract change, or new legal requirement changes the controlling rule.
Citations
ISO/IEC 27035 Severity Classification

What should an ISO/IEC 27035 severity classification consider?

Base the rating on actual or projected adverse consequences for the organization's operations, individuals, and other organizations. Useful criteria include asset or service criticality, confidentiality, integrity and availability impact, scope, affected parties, spread, threat activity, recoverability, safety, and uncertainty. ISO examples include partial or complete interruption of core services, minor or large disclosure of sensitive information, system destruction, network failure, physical damage, infrastructure failure, malware, technical attack, rule breach, and compromise of information.

Keep category, severity, urgency, and notification analysis distinct. Severity expresses impact under the organization's scale; priority also reflects time and response needs. A statutory or contractual reporting threshold must be assessed against its own wording.

  • Define each level with observable criteria, required coordinator or team, decision authority, response target, and escalation route.
  • Keep initial and revised ratings with timestamps and reasons rather than overwriting the record.
  • Do not treat the internal severity label as proof that a statutory reporting threshold is or is not met.
Citations
NIST SP 800-61r3

NIST supports risk-based incident triage, prioritization, escalation, and elevation using factors such as asset criticality, functional and data impact, observed activity, threat actor characteristics, and recoverability.

ISO/IEC 27035 Severity Classification

What should a severity matrix and case record contain?

Define each level with observable impact or consequence criteria, examples, required response roles, authority, target times, communication route, escalation trigger, and exit criteria. Avoid labels such as low, medium, and high without tests that different assessors can apply consistently. ISO/IEC 27035-3 includes an informative four-level example, but its names and thresholds are not mandatory and should not be copied without adapting them to the organization's services and risk.

For each case, retain the initial rating, evidence used, uncertainty, assessor, time, and required actions. Add later ratings instead of overwriting the first one so the record shows how the incident evolved.

  • Test borderline and multi-service scenarios in exercises.
  • State how cumulative events, unknown scope, safety impact, and critical suppliers affect the rating.
  • Compare similar incidents periodically to find inconsistent classifications.
Citations
ISO/IEC 27035 Severity Classification

Who should assign and approve severity?

The incident coordinator should assess the event or incident against the approved scale and assign the initial rating, with input from affected business, asset, service, privacy, safety, and supplier owners as needed. The policy should identify who may confirm, raise, or lower each level.

The rating should activate response resources and authority, not wait for a committee. Decisions outside delegated authority, including crisis activation or material business interruption, should follow the escalation path.

  • Allow provisional high ratings when the potential impact is serious and facts are incomplete.
  • Record disagreements, the final decision, and the authority used.
  • Do not let an incident owner lower severity only to meet a service target.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 defines the incident-management process context for assessing incidents, which supports severity classification and escalation decisions.

ISO/IEC 27035 Severity Classification

When should severity be reassessed?

Reassess after analysis, containment attempts, discovery of additional affected systems or people, recovery setbacks, supplier updates, or a change in legal or contractual notification analysis. Review at the frequency set for the current level and whenever the incident leaves its defined criteria.

A lower rating should follow evidence that impact and uncertainty have reduced, not only elapsed time. Record the new rating, time, facts, decision maker, and changes to resources, communications, or targets.

  • Keep response and notification clocks running according to their controlling rules.
  • Escalate when the incident is not under control or exceeds authority even if the numeric rating has not changed.
  • Use post-incident review to correct criteria that produced delay, ambiguity, or inconsistent results.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 defines the incident-management process context for assessing incidents, which supports severity classification and escalation decisions.

ISO/IEC 27035 Severity Classification

Which ISO parts and external thresholds apply?

ISO/IEC 27035-1:2023 supplies the generic process and roles. ISO/IEC 27035-2:2023 covers planning for categorization, evaluation, prioritization, forms, escalation, and response capability. ISO/IEC 27035-3:2020 covers operational triage and gives informative examples based on incident type, impact, information or system importance, damage scale, alarm level and severity, organizational spread, and financial loss. The examples illustrate a method and do not create a universal scoring formula.

The series is voluntary global guidance for organizations of any type, size, or nature. It does not create a certification class, legal incident category, regulator threshold, notification deadline, recovery objective, or service-level target. Apply binding laws, regulator rules, contracts, insurance terms, safety duties, and customer commitments against their own wording even when the internal severity stays unchanged.

  • Record the edition, matrix version, facts, evidence, uncertainty, assessor, timestamp, rating, required actions, and next review trigger.
  • Review the matrix after incidents, exercises, material service or supplier changes, new threat patterns, inconsistent ratings, and changes to law or contracts.
  • Keep category, severity, priority, escalation, crisis activation, and external notification as linked but separate decisions.
Citations
Page 3 of 3