Overview
ISO/IEC 27035-1:2023 - Information technology - Information security incident management - Part 1: Principles and process - is the foundational part of the ISO/IEC 27035 series. It defines basic concepts, principles and a generic incident management process that organizations of any size or sector can adapt. The standard covers preparing for, detecting, reporting, assessing, responding to, and learning from information security incidents and related vulnerabilities. It is applicable to in‑house teams and external service providers offering incident management services.
Key Topics
- Incident management principles: terminology (events, incidents, incident handling, incident response), roles (incident coordinator, incident management team, incident response team), and objectives.
- Structured process: lifecycle stages - Plan & Prepare; Detect & Report; Assess & Decide; Respond; Learn Lessons.
- Capabilities and governance: policies, plans, defined processes, organizational structure and assigned responsibilities to ensure consistent incident handling.
- Communication and documentation: guidance on points of contact, communication during incidents, and required records such as event reports, incident logs, incident reports and incident registers.
- Adaptability and applicability: generic guidance intended for all organizations, including external CSIRT/CERT providers, with advice on tailoring to type, size and risk profile.
- Supporting material: informative annexes with examples of incidents, relationship to investigative standards, cross‑references to ISO/IEC 27001, and considerations for investigations.
Applications
Who uses ISO/IEC 27035-1:2023 and how it’s applied:
- Security and incident response teams (IRT, CSIRT, CERT) - to design or refine incident response workflows, assign roles (incident coordinator, IMT) and document handling procedures.
- Information security managers and ISMS owners - to align incident management with broader information security management systems and business continuity planning.
- Executives and risk owners - to understand incident response objectives, decision points and assurance that incidents are handled consistently.
- External service providers - to deliver incident management services that follow internationally recognized principles and process models.
Practical uses include establishing playbooks, defining escalation paths, evidence handling awareness, and continuous improvement from post‑incident lessons learned.
Related Standards
- ISO/IEC 27000 (vocabulary and ISMS overview) - normative reference.
- ISO/IEC 27002 - complementary guidance on incident management controls.
- ISO/IEC 27042 - investigative guidance referenced in definitions.
- ISO/IEC 29147 and ISO/IEC 30111 - guidance on vulnerability disclosure and handling, referenced for related practices.
Keywords: ISO/IEC 27035-1:2023, information security incident management, incident response, incident handling, CSIRT, CERT, incident management process, ISMS.