How should teams handle Retained Logs under ISO/IEC 27035?
Start with the operational decision: define what Retained Logs means in your ISO/IEC 27035 scope, who owns it, and what record proves the decision is current.
For retained incident logs, decide in advance which event records, timestamps, triage notes, escalation decisions, containment actions, recovery evidence, and lessons-learned records must be preserved, who can access them, and when legal or privacy review is needed.
- Name the accountable owner and reviewer for Retained Logs.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when Retained Logs changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.
ISO/IEC 27035-2 supports planning, preparation, and lessons-learned records that retained logs should preserve for incident response review.