Side-by-sideGlobalISO/IEC 27035

ISO/IEC 27035 ISO/IEC 27035 vs NIST SP 800-61 Rev. 3

Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Validate legal, contractual, regulatory, and certification claims against the controlling source.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use ISO/IEC 27035 when you want a defined five-phase information security incident-management process with separate preparation and ICT operations guidance. Use NIST SP 800-61 Rev. 3 when you want incident response integrated across Cybersecurity Framework 2.0 risk management through a . Both are adaptable guidance, and neither creates a universal reporting deadline or certifies an organization.

Side-by-side comparison

ISO/IEC 27035 vs NIST SP 800-61 Rev. 3: scope, duties, evidence, and decision rule

This comparison maps the ISO/IEC 27035 series to NIST SP 800-61 Rev. 3's without treating either voluntary guide as law or certification.

Review all sources
First framework
ISO/IEC 27035

ISO/IEC 27035 provides a five-phase process in Part 1, preparation and learning guidance in Part 2, ICT response operations in Part 3, and multi-organization coordination guidance in Part 4.

Second framework
NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 is an April 2025 that integrates incident response across Govern, Identify, Protect, Detect, Respond, and Recover.

Comparison row 1

Scope and covered activity

ISO/IEC 27035

ISO/IEC 27035 structures information security incident management from preparation and detection through response and lessons learned.

NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 is incident response guidance focused on cybersecurity incident preparation, coordination, analysis, and improvement.

Operational implication

Choose the lifecycle vocabulary that fits the organization, then map equivalent roles, decisions, records, and improvement actions. NIST explicitly allows organizations to use the incident-response lifecycle model that suits them best.

Comparison row 2

Who must act

ISO/IEC 27035

ISO/IEC 27035 uses management, an incident coordinator, an Incident Management Team, Incident Response Teams, points of contact, monitoring teams, business roles, and external responders according to the organization's design.

NIST SP 800-61 Rev. 3

NIST identifies leadership, incident handlers, technology professionals, legal, public affairs and media relations, human resources, physical security, asset owners, third parties, and other internal or external participants.

Operational implication

Create one role map that names decision authority, deputies, contact paths, evidence duties, and communication limits for each incident type.

Comparison row 3

Trigger or threshold

ISO/IEC 27035

Readiness precedes an incident; reported events are assessed against organization-defined criteria and then closed or handled through the five-phase process.

NIST SP 800-61 Rev. 3

Preparation and lessons learned sit across Govern, Identify, and Protect. Potentially adverse events are analyzed through Detect to determine whether they meet defined incident criteria; once an incident is declared, the response plan is executed and applicable Respond and Recover outcomes follow.

Operational implication

Align event criteria, incident declaration, escalation, and closure states explicitly; neither publication supplies a legal notification threshold.

Comparison row 4

Core obligations

ISO/IEC 27035

ISO/IEC 27035 guides incident policy, plan, capability, relationships, detection, notification, triage, analysis, response, reporting, and lessons learned.

NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 provides prioritized CSF 2.0 outcomes plus recommendations and considerations for preparation, detection, response, recovery, and improvement; they are not comprehensive or universally applicable.

Operational implication

Map the ISO process to the relevant CSF outcomes, retaining each publication's status as adaptable guidance and documenting organization-specific choices.

Comparison row 5

Evidence and records

ISO/IEC 27035

ISO/IEC 27035 records include policy and plan, team authority, event and incident reports, the incident register, assessment and priority decisions, response logs, evidence, communications, closure, and lessons.

NIST SP 800-61 Rev. 3

NIST-aligned records connect governance, assets, suppliers, risk, safeguards, monitoring, adverse-event analysis, incident declaration, investigation, response, recovery, communications, and improvements to CSF outcomes.

Operational implication

Keep one chronology and evidence store where possible. Tag the ISO phase and CSF outcome, preserve provenance, and identify the owner and acceptance criteria for each decision.

Comparison row 6

Timing and cadence

ISO/IEC 27035

ISO/IEC 27035 timing follows implementation, exercise, review, supplier, incident, or change cycles rather than a single universal deadline.

NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 recommends timely coordination and response but does not create universal response or regulatory-notification deadlines.

Operational implication

Set operational targets from risk and service needs, and maintain separate clocks for any applicable law, contract, insurer, or authority requirement.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27035

ISO/IEC 27035 adoption can be evaluated through exercises, internal audits, customer assurance, management review, and governance review; the guidance itself is not a standalone certification scheme.

NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 is guidance, not a certification scheme or statute. Other laws, government policies, contracts, or customer requirements may separately require its use or particular incident practices.

Operational implication

Evaluate implementation against the chosen profile and operating evidence. Test legal and contractual compliance against the controlling sources rather than inferring it from NIST alignment.

Comparison row 8

Overlap and reuse

ISO/IEC 27035

ISO/IEC 27035 can supply the incident plan, criteria, chronology, assessment, response actions, communications, evidence handling, closure, and lessons.

NIST SP 800-61 Rev. 3

Rev. 3 can map the same records to governance, asset and supplier context, detection, analysis, response, recovery, communications, and improvement outcomes.

Operational implication

Reuse the record when it represents the same event and decision. Add the missing CSF context or ISO process detail instead of duplicating the incident.

Comparison row 9

Practical decision rule

ISO/IEC 27035

Use ISO/IEC 27035 when the organization wants the ISO series' incident-management phases, readiness detail, and ICT operational process.

NIST SP 800-61 Rev. 3

Use NIST SP 800-61 Rev. 3 when the organization wants incident response expressed as a within broader cybersecurity risk management.

Operational implication

Using both is reasonable: select one operational vocabulary, maintain a crosswalk, and avoid duplicating records or treating either guide as law.

Practical decision rule

How should teams decide between ISO/IEC 27035 and NIST SP 800-61 Rev. 3 for compliance planning?

  • Choose ISO/IEC 27035 for its defined incident-management phases, preparation detail, and ICT response operations.
  • Choose Rev. 3 for a that connects incident response to organization-wide cybersecurity risk management.
  • Use both with one operational vocabulary, a maintained crosswalk, and shared records; keep legal and contractual requirements as separate overlays.
Section 1

Should an organization use ISO/IEC 27035 or NIST SP 800-61 Rev. 3?

Many organizations can use both. ISO/IEC 27035-1 defines plan and prepare; detect and report; assess and decide; respond; and learn lessons. Part 2 expands preparation and learning, while Part 3 covers ICT detection, notification, triage, analysis, evidence storage, containment, eradication, recovery, and reporting operations.

NIST SP 800-61 Rev. 3 is an April 2025 . Govern, Identify, and Protect support prevention, preparation, impact reduction, and improvement; Detect, Respond, and Recover cover discovery, management, containment, eradication, recovery, reporting, and communications. NIST says organizations may use the incident-response lifecycle model that suits them best, so a one-to-one phase conversion is unnecessary.

  • Use Rev. 3 for current NIST alignment; it superseded Rev. 2 and has a materially different scope and structure.
  • Select one vocabulary for live response, then map roles, decision states, records, communications, and improvement actions to the other publication.
  • Add laws, regulations, contracts, insurer terms, and sector requirements as separate overlays with their own thresholds, recipients, content, and clocks.
Section 2

Which records should prove ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 is implemented correctly?

Use operating records, not a crosswalk alone. ISO/IEC 27035 evidence should show the incident policy and plan, Incident Management Team and Incident Response Team authority, reporting channels, tested assessment criteria, event and incident registers, response actions, evidence handling, closure, and lessons learned.

NIST-aligned evidence should connect the same incident to CSF outcomes: governance decisions, asset and supplier context, risk and vulnerability information, monitoring and adverse-event analysis, incident declaration and prioritization, investigation records, containment and eradication, recovery validation, communications, and improvement actions. Preserve integrity and provenance for incident data, metadata, and investigation records.

  • Preparation: approved policy and plan, roles and alternates, contacts, supplier responsibilities, asset and service priorities, playbooks, training, exercises, tools, and protected communication channels.
  • Response: event source, assessment, incident declaration, scope, impact, priority, decisions, evidence provenance, actions, communications, handoffs, recovery validation, and closure.
  • Improvement: exercise findings, incident follow-up report, root cause, assigned corrective actions, risk updates, plan changes, verification, and closure approval.
Section 3

How should teams run one workflow against both publications?

Before incidents, assign leadership, incident handlers, technology owners, legal, communications, human resources, physical security, business continuity, asset owners, and relevant third parties. Define event sources, reporting routes, declaration criteria, response authority, evidence rules, external notification overlays, service priorities, and secure out-of-band communications. Exercise the people and decisions, not only the technical playbook.

During an event, detect and report it, preserve the original facts, assess whether it is an incident, assign priority, and activate the needed responders. Analyze scope and root cause, record actions and evidence provenance, contain and eradicate the cause, restore affected assets and operations, validate recovery, communicate with authorized parties, and revise the assessment as facts change.

  • Keep ISO phase and CSF outcome tags on the same incident record instead of creating duplicate tickets.
  • Track external legal and contractual reporting separately because neither guide supplies the controlling threshold or deadline.
  • Feed lessons into risk assessment, safeguards, monitoring, plans, exercises, supplier requirements, and response procedures as soon as the lesson is reliable.
Section 4

What mistakes make ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 weak or hard to audit?

Do not map the superseded Rev. 2 phases as if they were Rev. 3. Rev. 3 still shows the old model for context, but its recommendations are organized as a and place continuous improvement across the lifecycle.

Do not reduce either publication to a security operations center checklist. Both depend on leadership, business and asset owners, legal and communications roles, suppliers, continuity planning, risk decisions, and recovery priorities.

  • Do not force every event into an incident record; preserve the assessment and close false positives or non-incidents under defined criteria.
  • Do not treat a CSF mapping or ISO procedure as proof that responders followed it.
  • Do not overwrite early facts, decisions, or evidence when the scope and priority change; preserve the chronology and provenance.
Section 5

How should teams review and improve ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 over time?

ISO/IEC 27035 treats learning as a defined phase and calls for improvements to incident management, risk work, controls, and response-team performance. NIST Rev. 3 uses the CSF Identify Improvement category across all Functions, so lessons can be recorded and acted on during preparation, detection, response, and recovery rather than waiting for final closure.

For each finding, record the evidence, affected policy or control, risk, owner, due date, planned change, acceptance test, and verification result. Re-run the failed scenario or control. Update the crosswalk only after the operating process changes.

  • Review plans periodically and after material incidents, exercises, supplier changes, architecture changes, and new reporting obligations.
  • Measure response outcomes that support decisions, such as time to assess, containment effectiveness, recovery validation, repeat causes, and overdue actions.
  • Escalate unresolved authority, staffing, tooling, supplier, evidence, and recovery risks to leadership.
Primary sources

References and citations

iso.org
Referenced sections
  • Primary ISO listing for incident management principles and process.
"preparing for, detecting, reporting, assessing, and responding to incidents"
iso.org
Referenced sections
  • Primary ISO listing for planning, preparing, and lessons-learned guidance.
"plan and prepare for incident response and to learn lessons"
iso.org
Referenced sections
  • Primary ISO listing for ICT incident response operations guidance.
"information security incident response in ICT security operations"
nvlpubs.nist.gov
Referenced sections
  • NIST source for cybersecurity incident response roles, CSF 2.0 alignment, preparation, detection, response, and recovery recommendations.
"Incident Response Recommendations and Considerations for Cybersecurity Risk Management"
csrc.nist.gov
Referenced sections
  • NIST's final publication page identifies Rev. 3 as an April 2025 CSF 2.0 Community Profile that supersedes Rev. 2.
Related guides

Explore more topics

ISO/IEC 27035 Compliance Guide
Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Evidence FAQ
Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Retained Logs FAQ
Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs ISO 22301 Comparison
Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
ISO/IEC 27035 vs NIS2 Comparison
Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 vs NIST SP 800-61 Comparison
Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.