FAQGlobalISO/IEC 27035

ISO/IEC 27035 FAQ Notification Evidence

Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Apply separate legal, contractual, regulatory, privacy, and evidence requirements where relevant.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27035 supports notification and reporting procedures, forms, roles, and records. The should preserve the facts and decision trail, but the duty to notify a regulator, customer, affected person, insurer, supplier, or law-enforcement body comes from separate law, contract, policy, or authority guidance.

Search this module

Find a question or answer quickly

5 of 5 questions
Question 1

What evidence should support an incident-notification decision?

Keep the controlling law, contract, policy, or authority instruction beside the decision record. Record the covered entity or service, jurisdiction, incident category, threshold analysis, facts known at the time, when any reporting clock began, decision owner, approver, recipients, submission channel, content and attachments sent, delivery evidence, acknowledgement, and required updates or final reports. A can receive the report, but the notification matrix should identify who has authority to decide and submit each external notice.

Preserve decisions not to notify. The record should identify the threshold applied, facts and uncertainty considered, legal or contractual review where needed, approval, and the change in facts that would trigger reassessment. ISO/IEC 27035 organizes this work but does not supply the external deadline or reporting threshold.

  • Separate internal operational alerts, management escalation, regulator or contractual notices, affected-person communications, law-enforcement reports, insurer notices, and public statements; each can have a different trigger, clock, content rule, recipient, and approver.
  • Version each notification with its preparation and submission times so later updates do not overwrite what was known and sent earlier.
  • Restrict sensitive content, use the authorized channel, and retain a copy of the submitted content plus transmission, delivery, rejection, and acknowledgement records.
Citations
Question 2

How should notification evidence be tested and maintained?

Test the notification procedure in exercises and sample completed incidents. A reviewer should be able to trace the alert or incident through threshold assessment, approval, submission, acknowledgement, follow-up, and closure without reconstructing the record from personal mailboxes.

Maintain a notification matrix by jurisdiction, entity, service, incident type, recipient, threshold, clock-start rule, channel, required content, approver, update cadence, and evidence location. Legal or regulatory owners should verify entries when the controlling source changes.

  • Test backup contacts, unavailable portals, rejected submissions, partial facts, and out-of-hours approval.
  • Keep clocks in the time zone and format required by the controlling rule, and record the basis for the chosen start time.
  • After an incident or exercise, correct contact details, decision criteria, templates, access rights, and handoffs that failed.
Citations
Question 3

Who should decide and approve an external notification?

The should assemble the operational facts and keep the record moving. The person authorized under the controlling law, contract, or policy should decide or approve the notification; that can involve legal, privacy, regulatory, customer, insurance, communications, or business leadership.

Predefine substitutes and emergency authority. Approval must not become an avoidable delay where a deadline applies, and the incident team should continue containment and evidence preservation while the notification decision is pending.

  • Record who supplied facts, who interpreted the threshold, who approved the content, and who submitted it.
  • Escalate conflicts between operational facts and legal interpretation to the named decision authority.
  • Limit factual, privileged, personal, or security-sensitive material to recipients and channels that are authorized to receive it.
Citations
Question 4

When should a notification decision be reassessed?

Reassess whenever new facts change the affected systems, people, geography, duration, impact, cause, or confidence in the original analysis. Also reassess when containment fails, a supplier supplies new facts, another authority becomes relevant, or the controlling rule requires an update or final report.

Do not silently replace the first decision. Add a timestamped decision showing what changed, which threshold was reconsidered, who approved the result, and whether another communication is due.

  • Track pending facts and the person responsible for obtaining them.
  • Link each update to the earlier submission and retain both versions.
  • Close the notification record only after required acknowledgements, corrections, updates, and final reports are resolved.
Citations
Question 5

Which ISO parts and dates govern notification evidence?

ISO/IEC 27035-1:2023 supplies the generic incident-management process and core roles. ISO/IEC 27035-2:2023 covers policy, plans, relationships, legal and regulatory considerations, recordkeeping, forms, exercises, and lessons learned. ISO/IEC 27035-3:2020 covers ICT notification, triage, internal reporting, external reporting where required, and report storage. These editions apply when the organization adopts or is contractually required to use them; the standards do not set a statutory commencement date.

No ISO/IEC 27035 part supplies one global threshold or deadline for external notice. The controlling jurisdiction, regulated entity or service, affected people, contract, insurer term, or authority instruction determines whether a report is required, when its clock starts, what it must contain, and whether interim, corrected, or final reports are due. Treat ISO as the operating framework and the external rule as the source of the duty.

  • Record the ISO edition, local procedure version, and controlling external source used for each decision.
  • Reassess the matrix when laws, regulator forms, contracts, services, suppliers, contacts, portals, or time-zone rules change.
  • Do not stop response, containment, or evidence preservation while an external notification decision is pending.
Citations
Primary sources

References and citations

iso.org
Referenced sections
  • ISO identifies Part 2:2023 as planning and preparation guidance, including relationships, records, exercises, and lessons learned.
iso.org
Referenced sections
  • ISO identifies Part 3:2020 as ICT incident-response operations guidance, including notification and reporting operations.
Related guides

Explore more topics

ISO/IEC 27035 Compliance Guide
Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Retained Logs FAQ
Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs ISO 22301 Comparison
Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
ISO/IEC 27035 vs NIS2 Comparison
Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 vs NIST SP 800-61 Comparison
Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.
ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison
Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.