---
title: "ISO/IEC 27035 Incident Management FAQ"
canonical_url: "https://www.sorena.io/artifacts/global/iso-27035/faq"
source_url: "https://www.sorena.io/artifacts/global/iso-27035/faq/items/page/3"
author: "Sorena AI"
description: "Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned."
published_at: "2026-05-09"
updated_at: "2026-07-24"
keywords:
  - "ISO/IEC 27035 FAQ"
  - "ISO/IEC 27035"
  - "ISO/IEC 27035 Information Security Incident Management"
  - "ISO/IEC 27035 FAQ checklist"
  - "ISO/IEC 27035 FAQ evidence"
  - "ISO/IEC 27035 FAQ implementation"
  - "FAQ"
  - "incident management"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# ISO/IEC 27035 Incident Management FAQ

Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.

*FAQ* *Global* *ISO/IEC 27035*

## ISO/IEC 27035 FAQ

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Validate legal, contractual, regulatory, and certification claims against the controlling source.

ISO/IEC 27035 treats an information security event as something that indicates a possible breach or control failure, then calls for assessment before it is declared an incident. It organizes incident management into five phases: plan and prepare, detect and report, assess and decide, respond, and learn lessons. The series is voluntary guidance; it does not create legal notification deadlines, prescribe one team design, or provide standalone certification.

## Definitions

### Information security event

An information security event is an occurrence that indicates a possible breach of information security or failure of controls. The event enters assessment, where the incident coordinator applies prepared criteria and decides whether it is a possible or confirmed incident or a false alarm.

**Why it matters here:** The event-versus-incident decision controls whether normal handling is enough or the organization activates incident response, assigns teams, starts its response timer, and opens the full incident record.

Sources:

- [ISO/IEC 27035-1:2023, terms and assess-and-decide phase](https://www.iso.org/standard/78973.html?ref=sorena.io)

## Browse sub-FAQ modules

### [ISO/IEC 27035 CSIRT Roles FAQ](/artifacts/global/iso-27035/faq/csirt-roles.md)

Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.

- 4 items

### [ISO/IEC 27035 Escalation FAQ](/artifacts/global/iso-27035/faq/escalation.md)

Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.

- 5 items

### [ISO/IEC 27035 Event vs Incident FAQ](/artifacts/global/iso-27035/faq/event-vs-incident.md)

Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.

- 5 items

### [ISO/IEC 27035 Lessons Learned FAQ](/artifacts/global/iso-27035/faq/lessons-learned.md)

Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.

- 5 items

### [ISO/IEC 27035 Notification Evidence FAQ](/artifacts/global/iso-27035/faq/notification-evidence.md)

Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.

- 5 items

### [ISO/IEC 27035 Post Incident Review FAQ](/artifacts/global/iso-27035/faq/post-incident-review.md)

Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.

- 5 items

### [ISO/IEC 27035 Retained Logs FAQ](/artifacts/global/iso-27035/faq/retained-logs.md)

Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.

- 5 items

### [ISO/IEC 27035 Severity Classification FAQ](/artifacts/global/iso-27035/faq/severity-classification.md)

Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.

- 5 items

Browse all indexed questions: [/artifacts/global/iso-27035/faq/items](/artifacts/global/iso-27035/faq/items.md)

## All FAQ items

*Page 3 of 3. Showing 9 of 39 items.*

### [How should incident records and digital evidence be protected?](/artifacts/global/iso-27035/faq/retained-logs.md#how-should-incident-records-and-digital-evidence-be-protected)

*Module: [ISO/IEC 27035 Retained Logs](/artifacts/global/iso-27035/faq/retained-logs.md)*

For records used only to manage the case, preserve authenticity, access control, version history, timestamps, and links to the incident register. For potential digital evidence, use procedures suited to the intended investigation or proceeding, including identification, collection, acquisition, preservation, integrity verification, access logs, and chain of custody.

- Record who collected or exported the material, when, from which source, by what method, and where it is stored.
- Protect original data where feasible and record examinations, copies, transfers, transformations, and integrity checks.
- Restrict sensitive logs and evidence by role, and keep access records for the full retention period.

Sources for this answer:

- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 supports planning, preparation, and lessons-learned records that retained logs should preserve for incident response review.
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - ISO/IEC 27035-3 supports ICT incident-response operations where operational logs, triage records, and response evidence are used.

### [Who should own retention and disposal decisions?](/artifacts/global/iso-27035/faq/retained-logs.md#who-should-own-retention-and-disposal-decisions)

*Module: [ISO/IEC 27035 Retained Logs](/artifacts/global/iso-27035/faq/retained-logs.md)*

The incident-management owner should define the operational record set with records, system, and security owners. Legal, privacy, human resources, regulatory, insurance, and contract owners should approve the rules that fall within their authority, including holds and restrictions on personal or employee data.

- Name who can issue, modify, and release a hold.
- Separate authority to investigate evidence from authority to delete it.
- Require disposal evidence for sensitive or high-value records when policy or the controlling rule calls for it.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 supports planning, preparation, and lessons-learned records that retained logs should preserve for incident response review.

### [When should records be reviewed or disposed of?](/artifacts/global/iso-27035/faq/retained-logs.md#when-should-records-be-reviewed-or-disposed-of)

*Module: [ISO/IEC 27035 Retained Logs](/artifacts/global/iso-27035/faq/retained-logs.md)*

Review the schedule when laws, contracts, systems, services, suppliers, storage locations, evidence needs, or incident types change. For each case, check for active investigations, claims, audits, regulator requests, or holds before disposal.

- Confirm that backups, replicas, archives, provider systems, and exported copies follow the rule or have a documented exception.
- Test restoration and integrity for records that must remain usable over long periods.
- Apply data minimization and access restrictions throughout retention, not only at disposal.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 supports planning, preparation, and lessons-learned records that retained logs should preserve for incident response review.

### [How should retention periods differ by record category?](/artifacts/global/iso-27035/faq/retained-logs.md#how-should-retention-periods-differ-by-record-category)

*Module: [ISO/IEC 27035 Retained Logs](/artifacts/global/iso-27035/faq/retained-logs.md)*

Start with the event or incident record's purpose and retention trigger. An intake report can be retained from closure; a case file from incident resolution; evidence from collection or release of a hold; a notification record from submission, acknowledgement, or final resolution; and a contract-specific record from the event defined by that contract. State the trigger explicitly so the period can be calculated consistently.

- Apply the edition named by the organization's policy or contract: Part 1:2023 covers the generic process and records, Part 2:2023 covers planning and legal or recordkeeping considerations, and Part 3:2020 covers ICT evidence and report storage.
- Resolve conflicting minimum and maximum periods with the authorized legal, privacy, records, contractual, and security owners; record the decision and any jurisdiction or data-location limit.
- Recalculate or suspend disposal when an investigation, claim, audit, regulator request, litigation hold, contract change, or new legal requirement changes the controlling rule.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO identifies Part 1:2023 as the generic incident-management foundation and source for incident documentation.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO identifies Part 2:2023 as planning and preparation guidance; its legal considerations include recordkeeping and retention questions.
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - ISO identifies Part 3:2020 as ICT response operations guidance, including preservation of evidence and storage of reports.

### [What should an ISO/IEC 27035 severity classification consider?](/artifacts/global/iso-27035/faq/severity-classification.md#what-should-an-isoiec-27035-severity-classification-consider)

*Module: [ISO/IEC 27035 Severity Classification](/artifacts/global/iso-27035/faq/severity-classification.md)*

Base the rating on actual or projected adverse consequences for the organization's operations, individuals, and other organizations. Useful criteria include asset or service criticality, confidentiality, integrity and availability impact, scope, affected parties, spread, threat activity, recoverability, safety, and uncertainty. ISO examples include partial or complete interruption of core services, minor or large disclosure of sensitive information, system destruction, network failure, physical damage, infrastructure failure, malware, technical attack, rule breach, and compromise of information.

- Define each level with observable criteria, required coordinator or team, decision authority, response target, and escalation route.
- Keep initial and revised ratings with timestamps and reasons rather than overwriting the record.
- Do not treat the internal severity label as proof that a statutory reporting threshold is or is not met.

Sources for this answer:

- [NIST SP 800-61r3](https://csrc.nist.gov/pubs/sp/800/61/r3/final?ref=sorena.io) - NIST supports risk-based incident triage, prioritization, escalation, and elevation using factors such as asset criticality, functional and data impact, observed activity, threat actor characteristics, and recoverability.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 covers the incident classification scale created during planning and preparation.

### [What should a severity matrix and case record contain?](/artifacts/global/iso-27035/faq/severity-classification.md#what-should-a-severity-matrix-and-case-record-contain)

*Module: [ISO/IEC 27035 Severity Classification](/artifacts/global/iso-27035/faq/severity-classification.md)*

Define each level with observable impact or consequence criteria, examples, required response roles, authority, target times, communication route, escalation trigger, and exit criteria. Avoid labels such as low, medium, and high without tests that different assessors can apply consistently. ISO/IEC 27035-3 includes an informative four-level example, but its names and thresholds are not mandatory and should not be copied without adapting them to the organization's services and risk.

- Test borderline and multi-service scenarios in exercises.
- State how cumulative events, unknown scope, safety impact, and critical suppliers affect the rating.
- Compare similar incidents periodically to find inconsistent classifications.

Sources for this answer:

- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 supports planning and lessons-learned practices that keep severity criteria and escalation paths reviewable.
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - ISO/IEC 27035-3 supports ICT incident-response operations where severity classification guides triage and response coordination.

### [Who should assign and approve severity?](/artifacts/global/iso-27035/faq/severity-classification.md#who-should-assign-and-approve-severity)

*Module: [ISO/IEC 27035 Severity Classification](/artifacts/global/iso-27035/faq/severity-classification.md)*

The incident coordinator should assess the event or incident against the approved scale and assign the initial rating, with input from affected business, asset, service, privacy, safety, and supplier owners as needed. The policy should identify who may confirm, raise, or lower each level.

- Allow provisional high ratings when the potential impact is serious and facts are incomplete.
- Record disagreements, the final decision, and the authority used.
- Do not let an incident owner lower severity only to meet a service target.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO/IEC 27035-1 defines the incident-management process context for assessing incidents, which supports severity classification and escalation decisions.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 supports planning and lessons-learned practices that keep severity criteria and escalation paths reviewable.

### [When should severity be reassessed?](/artifacts/global/iso-27035/faq/severity-classification.md#when-should-severity-be-reassessed)

*Module: [ISO/IEC 27035 Severity Classification](/artifacts/global/iso-27035/faq/severity-classification.md)*

Reassess after analysis, containment attempts, discovery of additional affected systems or people, recovery setbacks, supplier updates, or a change in legal or contractual notification analysis. Review at the frequency set for the current level and whenever the incident leaves its defined criteria.

- Keep response and notification clocks running according to their controlling rules.
- Escalate when the incident is not under control or exceeds authority even if the numeric rating has not changed.
- Use post-incident review to correct criteria that produced delay, ambiguity, or inconsistent results.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO/IEC 27035-1 defines the incident-management process context for assessing incidents, which supports severity classification and escalation decisions.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO/IEC 27035-2 supports planning and lessons-learned practices that keep severity criteria and escalation paths reviewable.

### [Which ISO parts and external thresholds apply?](/artifacts/global/iso-27035/faq/severity-classification.md#which-iso-parts-and-external-thresholds-apply)

*Module: [ISO/IEC 27035 Severity Classification](/artifacts/global/iso-27035/faq/severity-classification.md)*

ISO/IEC 27035-1:2023 supplies the generic process and roles. ISO/IEC 27035-2:2023 covers planning for categorization, evaluation, prioritization, forms, escalation, and response capability. ISO/IEC 27035-3:2020 covers operational triage and gives informative examples based on incident type, impact, information or system importance, damage scale, alarm level and severity, organizational spread, and financial loss. The examples illustrate a method and do not create a universal scoring formula.

- Record the edition, matrix version, facts, evidence, uncertainty, assessor, timestamp, rating, required actions, and next review trigger.
- Review the matrix after incidents, exercises, material service or supplier changes, new threat patterns, inconsistent ratings, and changes to law or contracts.
- Keep category, severity, priority, escalation, crisis activation, and external notification as linked but separate decisions.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO identifies Part 1:2023 as the generic incident-management process and role foundation.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO identifies Part 2:2023 as planning and preparation guidance, including creation of a classification scale.
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - ISO identifies Part 3:2020 as ICT operations guidance; its triage and annex examples inform organization-specific severity criteria.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/global/iso-27035/faq/items](/artifacts/global/iso-27035/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 3 of 3

Pages: [1](/artifacts/global/iso-27035/faq/items.md) | [2](/artifacts/global/iso-27035/faq/items/page/2.md) | [3](/artifacts/global/iso-27035/faq/items/page/3.md)

[Previous page](/artifacts/global/iso-27035/faq/items/page/2.md)

*Recommended next step*

*Placement: after implementation guidance*

## Assign the decisions, records, and reviews

Connect ISO/IEC 27035 guidance to named owners, incident records, decisions, and review triggers.

- [Open Assessment Autopilot for ISO/IEC 27035](/solutions/assessment.md): Convert ISO/IEC 27035 FAQ into accountable tasks, evidence requests, and review checkpoints.
- [Talk through implementation](/contact.md): Review your current scope, evidence gaps, and next implementation steps.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/iso-27035/faq/items/page/3.md
