| Scope and covered activity | ISO/IEC 27035 structures information security incident management from preparation and detection through response and lessons learned. | ISO 22301:2019 specifies BCMS requirements for scope, leadership, business impact analysis, disruption risk assessment, continuity strategies and solutions, response procedures, exercises, evaluation, audit, management review, and improvement. | A cyber incident may invoke both. ISO/IEC 27035 guides handling the security incident; the BCMS decides how prioritized activities continue or recover at the required capacity and within approved time frames. |
|---|
| Who must act | ISO/IEC 27035 uses management, an incident coordinator, an Incident Management Team, Incident Response Teams, points of contact, monitoring teams, business roles, and external responders according to the organization's design. | ISO 22301 requires top-management leadership and assigned BCMS responsibilities. Response structures need personnel and alternates with authority and competence, while activity, plan, communication, audit, and management-review owners support the system. | Name who declares the security incident, who activates continuity arrangements, who can authorize disruptive containment, and who accepts temporary service capacity. These decisions may belong to different roles. |
|---|
| Trigger or threshold | Preparation is continuous. A reported event is assessed under organization-defined criteria and is either closed or declared and prioritized as an information security incident. | The BCMS is maintained before disruption. During an incident, organization-defined warning, escalation, and activation procedures trigger continuity solutions when products, services, or prioritized activities are at risk of unacceptable disruption. | Map incident declaration, crisis escalation, continuity-plan activation, and return-to-normal as separate states with named authorities and evidence. |
|---|
| Core obligations | The series guides an incident-management policy, plan, classification and escalation arrangements, response capability, communications, documentation, operational handling, and learning. | ISO 22301 requires context and scope, leadership, objectives, resources, competence, communications, controlled information, business impact analysis, disruption risk assessment, continuity solutions, response procedures, exercises, evaluation, audit, management review, and improvement. | Cross-reference incident and continuity plans, but keep the incident coordinator's assessment and response authority distinct from continuity activation, service-priority, and temporary-capacity decisions. |
|---|
| Evidence and records | ISO/IEC 27035 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions. | ISO 22301 evidence includes BCMS scope and exclusions, legal and interested-party requirements, policy and objectives, business impact analysis, disruption risk assessment, continuity solutions and plans, activation and recovery records, exercises, evaluations, audits, management reviews, and corrective actions. | Use one incident identifier across both evidence sets, then label each decision, authority, objective, timestamp, exception, and corrective action by the process it supports. |
|---|
| Timing and cadence | ISO/IEC 27035 timing follows implementation, exercise, review, supplier, incident, or change cycles rather than a single universal deadline. | The business impact analysis identifies when disruption impacts become unacceptable and sets prioritized time frames for resuming activities at a specified minimum acceptable capacity. The organization also sets exercise and evaluation schedules. | Connect incident escalation to continuity activation criteria, capacity targets, and recovery priorities. Neither standard supplies a universal statutory notification clock; applicable law and contracts can. |
|---|
| Enforcement or assurance route | ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme. | ISO 22301 contains requirements for conformity assessment. An organization may self-declare, seek interested-party or external confirmation, or seek third-party certification of its BCMS; certification does not prove every incident decision or legal duty was satisfied. | Keep ISO/IEC 27035 adoption evidence distinct from ISO 22301 conformity and certification evidence, even where the same exercise or incident record supports both. |
|---|
| Overlap and reuse | ISO/IEC 27035 can supply the incident chronology, affected assets and services, assessment, response actions, communications, recovery status, and lessons. | The BCMS can reuse those facts while adding continuity requirements, activity and dependency impacts, activation decisions, workarounds, capacity, recovery time, and return from temporary measures. | Share facts but preserve separate decisions. Technical containment, service continuity, investigation, and return-to-normal can require different authorities and acceptance criteria. |
|---|
| Practical decision rule | Use ISO/IEC 27035 when the decision concerns recognizing, assessing, coordinating, containing, eradicating, recovering from, documenting, or learning from an information security incident. | Use ISO 22301 when the decision concerns continuity priorities, acceptable disruption, continuity solutions, plan activation, recovery of prioritized activities, or BCMS conformity. | If both apply, record two linked decisions: how the security incident is handled and whether continuity or crisis arrangements are activated. |
|---|