FAQGlobalISO/IEC 27035

ISO/IEC 27035 FAQ Retained Logs

Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Apply separate legal, contractual, regulatory, privacy, and evidence requirements where relevant.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27035 expects an and other incident records, but it does not set one universal retention period. The organization should define periods and safeguards by record category, purpose, investigative need, applicable law, contracts, litigation holds, privacy duties, and policy.

Search this module

Find a question or answer quickly

5 of 5 questions
Question 1

Which incident records should be retained, and for how long?

Preserve the event report, , classification and escalation decisions, response actions, communications, notification records, recovery validation, incident report, lessons learned, and linked evidence needed to reconstruct the case. Maintain an for oversight and trend analysis. Raw telemetry, working notes, malware samples, exports, and forensic images can need different storage, access, and retention rules.

ISO/IEC 27035 does not set a universal number of days or years. Define retention by record purpose, investigation and operational need, applicable law and contracts, privacy and employment rules, limitation periods, insurance terms, and litigation or regulatory holds. A hold is an authorized instruction that suspends ordinary disposal for specified material. Document which rule wins when periods conflict.

  • Document record category, purpose, owner, storage, access, integrity control, retention trigger, period, disposal method, and hold process.
  • Minimize personal or sensitive data while retaining what the justified purpose requires.
  • Review retention rules after legal changes, new services or suppliers, investigations, exercises, and lessons learned.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.

Question 2

How should incident records and digital evidence be protected?

For records used only to manage the case, preserve authenticity, access control, version history, timestamps, and links to the . For potential digital evidence, use procedures suited to the intended investigation or proceeding, including identification, collection, acquisition, preservation, integrity verification, access logs, and .

Do not describe every operational log as forensic evidence. Apply the stronger handling process when legal prosecution, disciplinary action, litigation, regulatory review, or another evidential purpose is reasonably possible.

  • Record who collected or exported the material, when, from which source, by what method, and where it is stored.
  • Protect original data where feasible and record examinations, copies, transfers, transformations, and integrity checks.
  • Restrict sensitive logs and evidence by role, and keep access records for the full retention period.
Citations
Question 3

Who should own retention and disposal decisions?

The incident-management owner should define the operational record set with records, system, and security owners. Legal, privacy, human resources, regulatory, insurance, and contract owners should approve the rules that fall within their authority, including holds and restrictions on personal or employee data.

The incident coordinator or evidence custodian should apply the rule to each case and record exceptions. No one should dispose of material covered by an active hold merely because the ordinary retention period expired.

  • Name who can issue, modify, and release a hold.
  • Separate authority to investigate evidence from authority to delete it.
  • Require disposal evidence for sensitive or high-value records when policy or the controlling rule calls for it.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.

Question 4

When should records be reviewed or disposed of?

Review the schedule when laws, contracts, systems, services, suppliers, storage locations, evidence needs, or incident types change. For each case, check for active investigations, claims, audits, regulator requests, or holds before disposal.

At the end of the approved period, dispose of the record securely unless a documented exception applies. Record the category, authority, date, method, scope, and person responsible without retaining unnecessary copies as proof.

  • Confirm that backups, replicas, archives, provider systems, and exported copies follow the rule or have a documented exception.
  • Test restoration and integrity for records that must remain usable over long periods.
  • Apply data minimization and access restrictions throughout retention, not only at disposal.
Citations
ISO/IEC 27035-1:2023 standard page

ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.

Question 5

How should retention periods differ by record category?

Start with the event or incident record's purpose and retention trigger. An intake report can be retained from closure; a case file from incident resolution; evidence from collection or release of a hold; a notification record from submission, acknowledgement, or final resolution; and a contract-specific record from the event defined by that contract. State the trigger explicitly so the period can be calculated consistently.

Examples of distinct categories include searchable case records, security telemetry, authentication and access logs, communications, regulator submissions, malware samples, forensic images, employee-related records, supplier evidence, and lessons-learned actions. These are examples, not ISO-mandated periods. Each category can require a different owner, repository, access group, integrity control, hold rule, period, and disposal method.

  • Apply the edition named by the organization's policy or contract: Part 1:2023 covers the generic process and records, Part 2:2023 covers planning and legal or recordkeeping considerations, and Part 3:2020 covers ICT evidence and report storage.
  • Resolve conflicting minimum and maximum periods with the authorized legal, privacy, records, contractual, and security owners; record the decision and any jurisdiction or data-location limit.
  • Recalculate or suspend disposal when an investigation, claim, audit, regulator request, litigation hold, contract change, or new legal requirement changes the controlling rule.
Citations
Primary sources

References and citations

iso.org
Referenced sections
  • ISO identifies Part 1:2023 as the generic incident-management foundation and source for incident documentation.
iso.org
Referenced sections
  • ISO identifies Part 2:2023 as planning and preparation guidance; its legal considerations include recordkeeping and retention questions.
iso.org
Referenced sections
  • ISO identifies Part 3:2020 as ICT response operations guidance, including preservation of evidence and storage of reports.
Related guides

Explore more topics

ISO/IEC 27035 Compliance Guide
Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Evidence FAQ
Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs ISO 22301 Comparison
Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
ISO/IEC 27035 vs NIS2 Comparison
Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 vs NIST SP 800-61 Comparison
Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.
ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison
Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.