Side-by-sideGlobalISO/IEC 27035

ISO/IEC 27035 ISO/IEC 27035 vs NIST SP 800-61

Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Validate legal, contractual, regulatory, and certification claims against the controlling source.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

NIST SP 800-61 Rev. 3 superseded Rev. 2 in April 2025 and expresses its recommendations as a . This legacy route therefore compares ISO/IEC 27035 with Rev. 3, not with the older four-phase NIST model. Use Rev. 2 only for historical records or migration. Neither publication creates a universal reporting deadline or standalone certification.

Side-by-side comparison

ISO/IEC 27035 vs NIST SP 800-61: scope, duties, evidence, and decision rule

This comparison maps the ISO/IEC 27035 series to the current NIST SP 800-61 Rev. 3 ; Rev. 3 supersedes the older Rev. 2 lifecycle guidance.

Review all sources
First framework
ISO/IEC 27035

ISO/IEC 27035 provides a five-phase process in Part 1, preparation and learning guidance in Part 2, ICT response operations in Part 3, and multi-organization coordination guidance in Part 4.

Second framework
NIST SP 800-61

This route describes the current NIST SP 800-61 Rev. 3, an April 2025 that supersedes Rev. 2.

Comparison row 1

Scope and covered activity

ISO/IEC 27035

ISO/IEC 27035 structures information security incident management from preparation and detection through response and lessons learned.

NIST SP 800-61

NIST SP 800-61 Rev. 3 is incident response guidance focused on cybersecurity incident preparation, coordination, analysis, and improvement.

Operational implication

Choose ISO/IEC 27035 when the question is how to build and run an information security incident management process. Choose NIST SP 800-61 when the question is how to apply cybersecurity incident response recommendations inside a CSF 2.0 risk-management program.

Comparison row 2

Who must act

ISO/IEC 27035

ISO/IEC 27035 ownership should sit with incident management leadership, the Incident Management Team, Incident Response Team, security operations, risk owners, and managers who can approve lessons learned.

NIST SP 800-61

NIST SP 800-61 ownership should map to incident response leadership, incident handlers, technology professionals, legal, public affairs, asset owners, and contracted response providers where they support the response.

Operational implication

Assign the people who operate and authorize the process. Use ISO/IEC 27035 to define incident-management roles and NIST SP 800-61 Rev. 3 to map broader internal and third-party participation.

Comparison row 3

Trigger or threshold

ISO/IEC 27035

Readiness precedes an incident; reported events are assessed against organization-defined criteria and then closed or handled through the five-phase process.

NIST SP 800-61

Preparation and lessons learned sit across Govern, Identify, and Protect. Potentially adverse events are analyzed through Detect to determine whether they meet defined incident criteria; once an incident is declared, the response plan is executed and applicable Respond and Recover outcomes follow.

Operational implication

Align event criteria, incident declaration, escalation, and closure states explicitly; neither publication supplies a legal notification threshold.

Comparison row 4

Core obligations

ISO/IEC 27035

ISO/IEC 27035 guides incident policy, plan, capability, relationships, detection, notification, triage, analysis, response, reporting, and lessons learned.

NIST SP 800-61

NIST SP 800-61 organizes incident response as cybersecurity risk management guidance within the , including preparation, detection, response, recovery, and lessons learned.

Operational implication

Use ISO/IEC 27035 for the management-system backbone: policy, roles, process, records, and review. Use NIST SP 800-61 for incident-response recommendations that fit a CSF 2.0 based risk-management model.

Comparison row 5

Evidence and records

ISO/IEC 27035

ISO/IEC 27035 records include policy and plan, team authority, event and incident reports, the incident register, assessment and priority decisions, response logs, evidence, communications, closure, and lessons.

NIST SP 800-61

Current NIST records connect governance, assets, suppliers, risk, safeguards, monitoring, adverse-event analysis, incident declaration, investigation, response, recovery, communications, and improvements to CSF outcomes.

Operational implication

Keep one chronology and evidence store where possible. Preserve the NIST revision used by historical records, then tag current ISO phases and Rev. 3 CSF outcomes without rewriting history.

Comparison row 6

Timing and cadence

ISO/IEC 27035

ISO/IEC 27035 timing follows implementation, exercise, review, supplier, incident, or change cycles rather than a single universal deadline.

NIST SP 800-61

NIST SP 800-61 Rev. 3 recommends timely coordination and response but does not create universal response or regulatory-notification deadlines.

Operational implication

Set operational targets from risk and service needs, and maintain separate clocks for any applicable law, contract, insurer, or authority requirement.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27035

ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme.

NIST SP 800-61

NIST SP 800-61 Rev. 3 is guidance, not a certification scheme or statute. Other laws, government policies, contracts, or customer requirements may separately require its use or particular incident practices.

Operational implication

Evaluate implementation against the chosen profile and operating evidence. Test legal and contractual compliance against the controlling sources rather than inferring it from NIST alignment.

Comparison row 8

Overlap and reuse

ISO/IEC 27035

ISO/IEC 27035 can supply the incident plan, criteria, chronology, assessment, response actions, communications, evidence handling, closure, and lessons.

NIST SP 800-61

Rev. 3 can map the same records to governance, asset and supplier context, detection, analysis, response, recovery, communications, and improvement outcomes.

Operational implication

Reuse the record when it represents the same event and decision. Preserve its original NIST revision and add missing current mappings instead of duplicating the incident.

Comparison row 9

Practical decision rule

ISO/IEC 27035

Use ISO/IEC 27035 when the organization wants the ISO series' incident-management phases, readiness detail, and ICT operational process.

NIST SP 800-61

Use the current NIST SP 800-61 Rev. 3 when the organization wants incident response expressed as a within broader cybersecurity risk management.

Operational implication

Using both is reasonable: select one operational vocabulary, maintain a crosswalk, and avoid duplicating records or treating either guide as law.

Practical decision rule

How should teams decide between ISO/IEC 27035 and NIST SP 800-61 for compliance planning?

  • Choose ISO/IEC 27035 when you need a management-system style incident process with documented scope, roles, records, review, and improvement.
  • Choose NIST SP 800-61 when you need CSF 2.0-based incident response recommendations for cybersecurity risk management, including preparation, detection, response, recovery, and lessons learned.
  • Use both when one source supports the governance model and the other helps operationalize incident response; do not merge them into one undifferentiated requirement set.
Section 1

What changed in the ISO/IEC 27035 versus NIST SP 800-61 comparison?

Rev. 2 used preparation; detection and analysis; containment, eradication and recovery; and post-incident activity. Rev. 3 reproduces that model only as the previous lifecycle, then organizes current recommendations as a . Govern, Identify, and Protect support preparation and impact reduction; Detect, Respond, and Recover cover active incident response; Identify Improvement carries lessons across all Functions.

ISO/IEC 27035-1 uses five phases: plan and prepare; detect and report; assess and decide; respond; and learn lessons. Part 2 expands preparation and learning, while Part 3 covers ICT detection, notification, triage, analysis, evidence storage, containment, eradication, recovery, and reporting. Compare these current outcomes and decisions instead of forcing the Rev. 2 diagram onto either publication.

  • Use the dedicated Rev. 3 route when documenting a new crosswalk or current framework alignment.
  • Label records and diagrams with the NIST revision so responders can tell whether a phase name is historical or current.
  • Keep legal, regulatory, contractual, insurer, and customer notifications as separate overlays with their own tests, recipients, content, and clocks.
Section 2

Which records should prove ISO/IEC 27035 vs NIST SP 800-61 is implemented correctly?

First identify which NIST revision each record implements. A Rev. 2 phase label can remain in historical tickets, procedures, and metrics, but a current alignment should also identify the relevant Rev. 3 CSF outcome. Do not silently relabel old evidence as if the operating process had changed.

ISO/IEC 27035 evidence should show policy, plan, team authority, tested assessment criteria, event and incident registers, response actions, evidence handling, closure, and lessons. Rev. 3 evidence should connect governance, asset and supplier context, adverse-event analysis, investigation, containment, eradication, recovery validation, communications, and improvement to the applicable CSF outcomes.

  • Migration evidence: inventory of Rev. 2 documents and metrics, approved Rev. 3 crosswalk, changed roles or procedures, training, exercise results, exceptions, and retirement dates.
  • Incident evidence: event source, assessment, declaration, priority, scope, decisions, actions, evidence provenance, communications, recovery validation, and closure.
  • Improvement evidence: incident follow-up report, root cause, assigned corrective actions, risk and control updates, verification, and closure approval.
Section 3

How should teams migrate from Rev. 2 without disrupting response?

Inventory every policy, plan, playbook, role description, ticket state, metric, exercise, customer commitment, and control mapping that cites SP 800-61 Rev. 2. Decide whether each item remains valid operationally, needs only a citation update, or must change because Rev. 3 broadens incident response across cybersecurity risk management.

Choose one vocabulary for live response. Map ISO/IEC 27035 event reporting, incident assessment, response, and learning to the applicable Rev. 3 outcomes. Keep aliases for old ticket states only where responders need them during transition, and train the people who declare incidents, authorize disruptive actions, communicate externally, or validate recovery.

  • Test migrated playbooks through a scenario that crosses detection, legal review, supplier coordination, containment, recovery, and lessons learned.
  • Preserve historical revision labels so old metrics and audit samples are not misrepresented.
  • Retire Rev. 2-only diagrams and training after the replacement process has been exercised and approved.
Section 4

What mistakes make ISO/IEC 27035 vs NIST SP 800-61 weak or hard to audit?

Do not call the Rev. 2 four-phase model the current NIST lifecycle. Rev. 3 discusses it as the previous model and explicitly allows organizations to use the lifecycle framework that suits them.

Do not perform a citation-only migration where roles, supplier participation, asset context, recovery priorities, continuous improvement, or broader risk-management integration are missing. Conversely, do not rewrite a working procedure merely to imitate the order of CSF Functions.

  • Do not erase Rev. 2 labels from historical evidence or claim that old incidents were handled under Rev. 3.
  • Do not force a one-to-one mapping between ISO phases, Rev. 2 phases, and CSF Functions.
  • Do not treat either guide as the source of a statutory or contractual notification deadline.
Section 5

How should teams review and improve ISO/IEC 27035 vs NIST SP 800-61 over time?

Review the migration after exercises and real incidents. Look for terminology that delayed declaration, unclear authority, broken automation, metrics that no longer measure the same state, missing third parties, duplicated records, and improvements that never reached risk, protection, detection, or recovery work.

For each finding, record the evidence, owner, due date, change, acceptance test, and verification result. Update the crosswalk only after the operating process changes, and keep unresolved legacy dependencies visible until they are retired.

  • Review plans after material incidents, exercises, supplier changes, architecture changes, and new reporting obligations.
  • Re-run failed scenarios before closing migration actions.
  • Escalate unresolved authority, staffing, tooling, supplier, evidence, and recovery risks to leadership.
Primary sources

References and citations

iso.org
Referenced sections
  • Primary ISO listing for incident management principles and process.
"preparing for, detecting, reporting, assessing, and responding to incidents"
iso.org
Referenced sections
  • Primary ISO listing for planning, preparing, and lessons-learned guidance.
"plan and prepare for incident response and to learn lessons"
iso.org
Referenced sections
  • Primary ISO listing for ICT incident response operations guidance.
"information security incident response in ICT security operations"
nvlpubs.nist.gov
Referenced sections
  • Sections 1-3 establish Rev. 3's April 2025 CSF 2.0 scope, lifecycle model, roles, policy and procedure guidance, prioritized outcomes, and supersession of Rev. 2.
"Incident Response Recommendations and Considerations for Cybersecurity Risk Management"
csrc.nist.gov
Referenced sections
  • NIST's final publication page dates Rev. 3 to April 2025, identifies it as a CSF 2.0 Community Profile, and states that it supersedes Rev. 2.
Related guides

Explore more topics

ISO/IEC 27035 Compliance Guide
Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Evidence FAQ
Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Retained Logs FAQ
Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs ISO 22301 Comparison
Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
ISO/IEC 27035 vs NIS2 Comparison
Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison
Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.