What evidence should support an incident-notification decision?
Keep the controlling law, contract, policy, or authority instruction beside the decision record. Record the covered entity or service, jurisdiction, incident category, threshold analysis, facts known at the time, when any reporting clock began, decision owner, approver, recipients, submission channel, content and attachments sent, delivery evidence, acknowledgement, and required updates or final reports. A can receive the report, but the notification matrix should identify who has authority to decide and submit each external notice.
Preserve decisions not to notify. The record should identify the threshold applied, facts and uncertainty considered, legal or contractual review where needed, approval, and the change in facts that would trigger reassessment. ISO/IEC 27035 organizes this work but does not supply the external deadline or reporting threshold.
- Separate internal operational alerts, management escalation, regulator or contractual notices, affected-person communications, law-enforcement reports, insurer notices, and public statements; each can have a different trigger, clock, content rule, recipient, and approver.
- Version each notification with its preparation and submission times so later updates do not overwrite what was known and sent earlier.
- Restrict sensitive content, use the authorized channel, and retain a copy of the submitted content plus transmission, delivery, rejection, and acknowledgement records.
Supports notification-evidence ownership by tying incident reporting, assessment, response, and retained records to the ISO/IEC 27035 process.
Primary ISO listing for planning, preparing, and lessons-learned guidance.