What should an ISO/IEC 27035 severity classification consider?
Base the rating on actual or projected adverse consequences for the organization's operations, individuals, and other organizations. Useful criteria include asset or service criticality, confidentiality, integrity and availability impact, scope, affected parties, spread, threat activity, recoverability, safety, and uncertainty. ISO examples include partial or complete interruption of core services, minor or large disclosure of sensitive information, system destruction, network failure, physical damage, infrastructure failure, malware, technical attack, rule breach, and compromise of information.
Keep category, severity, urgency, and notification analysis distinct. Severity expresses impact under the organization's scale; priority also reflects time and response needs. A statutory or contractual reporting threshold must be assessed against its own wording.
- Define each level with observable criteria, required coordinator or team, decision authority, response target, and escalation route.
- Keep initial and revised ratings with timestamps and reasons rather than overwriting the record.
- Do not treat the internal severity label as proof that a statutory reporting threshold is or is not met.
NIST supports risk-based incident triage, prioritization, escalation, and elevation using factors such as asset criticality, functional and data impact, observed activity, threat actor characteristics, and recoverability.
ISO/IEC 27035-2 covers the incident classification scale created during planning and preparation.