ISO/IEC 27035 vs ISO 22301 side-by-sideGlobalISO/IEC 27035

ISO/IEC 27035 ISO/IEC 27035 vs ISO 22301

Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Validate legal, contractual, regulatory, and certification claims against the controlling source.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use ISO/IEC 27035 to manage the information security incident and an ISO 22301 to maintain or restore prioritized products and services during the disruption. A cyber incident can activate both, but containment and eradication do not by themselves decide which activities must continue, at what capacity, or by when.

Side-by-side comparison

ISO/IEC 27035 vs ISO 22301: scope, duties, evidence, and decision rule

This comparison separates information security incident handling under ISO/IEC 27035 from business continuity management under ISO 22301 and shows how to coordinate activation, recovery, exercises, and records.

Review all sources
First framework
ISO/IEC 27035

Use ISO/IEC 27035 to structure information security incident preparation, detection, assessment, response, records, and lessons learned. It is guidance rather than a certifiable management-system requirements standard.

Second framework
ISO 22301

Use ISO 22301:2019 to establish, maintain, assess, and improve a (BCMS) that continues or restores prioritized products and services at predefined capacity within acceptable time frames.

Comparison row 1

Scope and covered activity

ISO/IEC 27035

ISO/IEC 27035 structures information security incident management from preparation and detection through response and lessons learned.

ISO 22301

ISO 22301:2019 specifies BCMS requirements for scope, leadership, business impact analysis, disruption risk assessment, continuity strategies and solutions, response procedures, exercises, evaluation, audit, management review, and improvement.

Operational implication

A cyber incident may invoke both. ISO/IEC 27035 guides handling the security incident; the BCMS decides how prioritized activities continue or recover at the required capacity and within approved time frames.

Comparison row 2

Who must act

ISO/IEC 27035

ISO/IEC 27035 uses management, an incident coordinator, an Incident Management Team, Incident Response Teams, points of contact, monitoring teams, business roles, and external responders according to the organization's design.

ISO 22301

ISO 22301 requires top-management leadership and assigned BCMS responsibilities. Response structures need personnel and alternates with authority and competence, while activity, plan, communication, audit, and management-review owners support the system.

Operational implication

Name who declares the security incident, who activates continuity arrangements, who can authorize disruptive containment, and who accepts temporary service capacity. These decisions may belong to different roles.

Comparison row 3

Trigger or threshold

ISO/IEC 27035

Preparation is continuous. A reported event is assessed under organization-defined criteria and is either closed or declared and prioritized as an information security incident.

ISO 22301

The BCMS is maintained before disruption. During an incident, organization-defined warning, escalation, and activation procedures trigger continuity solutions when products, services, or prioritized activities are at risk of unacceptable disruption.

Operational implication

Map incident declaration, crisis escalation, continuity-plan activation, and return-to-normal as separate states with named authorities and evidence.

Comparison row 4

Core obligations

ISO/IEC 27035

The series guides an incident-management policy, plan, classification and escalation arrangements, response capability, communications, documentation, operational handling, and learning.

ISO 22301

ISO 22301 requires context and scope, leadership, objectives, resources, competence, communications, controlled information, business impact analysis, disruption risk assessment, continuity solutions, response procedures, exercises, evaluation, audit, management review, and improvement.

Operational implication

Cross-reference incident and continuity plans, but keep the incident coordinator's assessment and response authority distinct from continuity activation, service-priority, and temporary-capacity decisions.

Comparison row 5

Evidence and records

ISO/IEC 27035

ISO/IEC 27035 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.

ISO 22301

ISO 22301 evidence includes BCMS scope and exclusions, legal and interested-party requirements, policy and objectives, business impact analysis, disruption risk assessment, continuity solutions and plans, activation and recovery records, exercises, evaluations, audits, management reviews, and corrective actions.

Operational implication

Use one incident identifier across both evidence sets, then label each decision, authority, objective, timestamp, exception, and corrective action by the process it supports.

Comparison row 6

Timing and cadence

ISO/IEC 27035

ISO/IEC 27035 timing follows implementation, exercise, review, supplier, incident, or change cycles rather than a single universal deadline.

ISO 22301

The business impact analysis identifies when disruption impacts become unacceptable and sets prioritized time frames for resuming activities at a specified minimum acceptable capacity. The organization also sets exercise and evaluation schedules.

Operational implication

Connect incident escalation to continuity activation criteria, capacity targets, and recovery priorities. Neither standard supplies a universal statutory notification clock; applicable law and contracts can.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27035

ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme.

ISO 22301

ISO 22301 contains requirements for conformity assessment. An organization may self-declare, seek interested-party or external confirmation, or seek third-party certification of its BCMS; certification does not prove every incident decision or legal duty was satisfied.

Operational implication

Keep ISO/IEC 27035 adoption evidence distinct from ISO 22301 conformity and certification evidence, even where the same exercise or incident record supports both.

Comparison row 8

Overlap and reuse

ISO/IEC 27035

ISO/IEC 27035 can supply the incident chronology, affected assets and services, assessment, response actions, communications, recovery status, and lessons.

ISO 22301

The BCMS can reuse those facts while adding continuity requirements, activity and dependency impacts, activation decisions, workarounds, capacity, recovery time, and return from temporary measures.

Operational implication

Share facts but preserve separate decisions. Technical containment, service continuity, investigation, and return-to-normal can require different authorities and acceptance criteria.

Comparison row 9

Practical decision rule

ISO/IEC 27035

Use ISO/IEC 27035 when the decision concerns recognizing, assessing, coordinating, containing, eradicating, recovering from, documenting, or learning from an information security incident.

ISO 22301

Use ISO 22301 when the decision concerns continuity priorities, acceptable disruption, continuity solutions, plan activation, recovery of prioritized activities, or BCMS conformity.

Operational implication

If both apply, record two linked decisions: how the security incident is handled and whether continuity or crisis arrangements are activated.

Practical decision rule

How should teams decide between ISO/IEC 27035 and ISO 22301 for compliance planning?

  • Start with the trigger: risk review, customer assurance, incident, supplier, privacy, law, certification-system support, or framework mapping.
  • Identify the binding or chosen source for each claim before assigning controls or collecting evidence.
  • Reuse evidence only where the same owner, scope, time period, system, supplier, data type, and acceptance criteria apply.
Section 1

How should ISO/IEC 27035 and ISO 22301 work together?

ISO/IEC 27035-1 uses five phases: plan and prepare; detect and report; assess and decide; respond; and learn lessons. Parts 2 and 3 add preparation, team, communication, triage, analysis, containment, eradication, recovery, evidence, and reporting detail. ISO 22301:2019 requires a BCMS that identifies continuity needs, selects continuity strategies and solutions, maintains plans, exercises them, evaluates performance, and improves the system.

Connect the two at explicit handoffs. The incident coordinator should provide the affected services, likely duration, dependencies, containment choices, and revised impact estimate. The continuity or crisis authority should use the business impact analysis and approved continuity procedures to decide whether to activate workarounds, which prioritized activities to recover, the minimum acceptable capacity, and the target time.

  • Define separate thresholds for declaring an information security incident, escalating a crisis, and activating a business continuity plan.
  • Resolve conflicts before an incident, such as preserving a compromised system for investigation versus rebuilding it quickly to meet a recovery time objective.
  • ISO 22301 contains requirements against which a BCMS can be assessed or certified. ISO/IEC 27035 is guidance and is not a standalone certification scheme.
Section 2

Which records should prove ISO/IEC 27035 vs ISO 22301 is implemented correctly?

Keep one incident chronology, but label the decisions and approvals it feeds. ISO/IEC 27035 records should show event reporting, the incident declaration, priority changes, response authority, actions, communications, evidence handling, closure, and lessons learned. ISO 22301 records should show the BCMS scope, business impact analysis, disruption risk assessment, continuity strategies and solutions, plan activation, recovery of prioritized activities, exercises, evaluation, audit, management review, and corrective action.

A shared exercise can support both standards only if it tests both sets of objectives. A ransomware exercise, for example, may test detection, analysis, containment, and evidence preservation under ISO/IEC 27035 while separately testing minimum service capacity, recovery time objectives, alternate resources, stakeholder warnings, and return from temporary measures under ISO 22301.

  • Incident evidence: event and incident registers, assessment criteria, incident declaration, response log, communications, containment and recovery actions, preserved evidence, closure decision, and lessons learned.
  • Continuity evidence: scoped products and services, business impact analysis, prioritized activities and resources, continuity strategies, plans and procedures, activation records, exercise results, and restoration records.
  • Link the records with a stable incident identifier, timestamps, decision owners, affected services, assumptions, approvals, exceptions, and corrective actions.
Section 3

What is the joint incident and continuity workflow?

Start with the ISO/IEC 27035 event assessment. If the event is declared an incident, assign the incident coordinator and response team, record the affected assets and services, and begin the response log. At the same time, compare the predicted service disruption with the BCMS activation criteria and the business impact analysis.

If continuity is activated, run two linked workstreams. The incident team investigates, contains, eradicates, and supports technical recovery. The continuity structure manages service priorities, workarounds, resources, warnings, communications, recovery at the required capacity, and return from temporary measures. Each team should exchange updated impact and timing information without surrendering its decision authority.

  • Before an incident: cross-reference contacts, dependencies, decision rights, activation criteria, recovery priorities, communication procedures, and exercise scenarios.
  • During an incident: maintain a common operating picture, but record incident-response and continuity decisions separately.
  • After recovery: reconcile the incident review with the BCMS post-incident evaluation, assign corrective actions, and update both plans where the evidence supports a change.
Section 4

What mistakes make ISO/IEC 27035 vs ISO 22301 weak or hard to audit?

Do not treat technical recovery as proof that business continuity objectives were met. A system may be restored while a prioritized activity remains below its required capacity, or a workaround may sustain the service while eradication continues.

Do not copy one set of severity labels into the other without a mapping. Incident severity may reflect threat, scope, confidentiality, integrity, and technical impact; continuity activation depends on disruption impacts, time, capacity, dependencies, and approved continuity requirements.

  • Do not let the same person approve incompatible actions without recording the tradeoff and authority used.
  • Do not assume an ISO 22301 certificate proves that a particular incident was handled in line with ISO/IEC 27035.
  • Do not let legal, regulatory, contractual, insurer, or customer notification clocks disappear inside either standards workflow.
Section 5

How should teams review and improve ISO/IEC 27035 vs ISO 22301 over time?

ISO/IEC 27035 calls for lessons to be identified, documented, communicated, and used to improve the incident-management policy, plan, controls, risk work, and response teams. ISO 22301 requires evaluation through reviews, analysis, exercises, tests, post-incident reports, and performance evaluation, with internal audit and management review at planned intervals.

Use one corrective-action register where practical, but identify which process failed, the evidence, the owner, the due date, and the acceptance test. Update the business impact analysis when the event changes impact assumptions or dependencies; update incident criteria and playbooks when detection, escalation, authority, or response decisions failed.

  • Re-exercise the changed handoff, not only the document.
  • Verify that corrective actions work before closing them.
  • Send unresolved scope, resource, risk, or authority issues to the relevant management review.
Primary sources

References and citations

iso.org
Referenced sections
  • Primary ISO listing for the current ISO 22301 business continuity management system requirements standard.
"Business continuity management systems"
iso.org
Referenced sections
  • Primary ISO listing for incident management principles and process.
"preparing for, detecting, reporting, assessing, and responding to incidents"
iso.org
Referenced sections
  • Primary ISO listing for planning, preparing, and lessons-learned guidance.
"plan and prepare for incident response and to learn lessons"
iso.org
Referenced sections
  • Primary ISO listing for ICT incident response operations guidance.
"information security incident response in ICT security operations"
Related guides

Explore more topics

ISO/IEC 27035 Compliance Guide
Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Evidence FAQ
Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Retained Logs FAQ
Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs NIS2 Comparison
Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 vs NIST SP 800-61 Comparison
Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.
ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison
Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.