Plan and Prepare
Incident response policy, roles, an Incident Response Team (IRT), reporting channels, playbooks, tooling and awareness are set up before the first incident – the foundation of any resilient response.
The international standard for Information Security Incident Management provides the process backbone behind incident response and forensics – from preparation all the way to the lessons-learned loop.
ISO/IEC 27035 describes a structured, repeatable lifecycle for handling information security incidents. Instead of reacting ad hoc to attacks, outages or data leaks, the standard establishes an end-to-end process: detect, report, assess, decide, contain, recover and learn from every incident.
The standard is multi-part: Part 1 (27035-1:2023) defines principles and the process, Part 2 (27035-2:2023) planning and preparation, Part 3 (27035-3:2020) operational ICT incident response and Part 4 (27035-4:2024) cross-organisation coordination. ISO/IEC 27035 is guidance and not certifiable on its own – but it is the operational backbone for incident handling within an ISO/IEC 27001-certified ISMS.
ISO/IEC 27035 breaks incident handling into five phases that build on one another.
Incident response policy, roles, an Incident Response Team (IRT), reporting channels, playbooks, tooling and awareness are set up before the first incident – the foundation of any resilient response.
Events are captured through monitoring, SIEM, reports and detection, recognised as security-relevant and reported promptly through defined channels.
Reported events are triaged, classified and prioritised. A decision is made on whether a security incident exists and what escalation is required.
Containment, eradication, recovery and – where needed – forensic evidence preservation, plus internal and external communication including regulatory notifications.
Post-incident review, root-cause analysis, updates to controls and playbooks, and metrics – each incident demonstrably improves the security posture.
ISO/IEC 27035 is the normative underpinning for regulatory reporting and response duties.
NIS2's staged deadlines – early warning within 24 hours, notification within 72 hours, final report within one month – presuppose exactly the process that ISO/IEC 27035 provides through detection, assessment and reporting.
For financial entities the lifecycle covers the classification and reporting of major ICT-related incidents under DORA from a normative standpoint – from initial notification to final report.
Controls A.5.24 to A.5.28 of Annex A of ISO/IEC 27001:2022 (planning, assessment, response, learning, evidence collection) are directly operationalised and made audit-ready by ISO/IEC 27035.
The Cyber Resilience Act (CRA) requires active vulnerability handling and reporting of exploited vulnerabilities – the response and reporting processes from 27035 map directly onto it.
From baseline assessment to an operational incident-response capability.
We assess your existing incident handling against the five phases of ISO/IEC 27035 and against your regulatory duties (NIS2, DORA, ISO 27001).
We design incident response policy, roles, reporting chains and scenario-based playbooks – including the 24h/72h/1-month reporting logic.
We enable your Incident Response Team through tabletop exercises and simulated incidents and integrate detection, SIEM and escalation.
We embed lessons-learned loops, metrics and regular reviews – keeping the process effective and audit-ready.
Primary sources for the standard and matching VamiSec services.
Answers on ISO/IEC 27035 in practice.
No. ISO/IEC 27035 is guidance and not certifiable on its own. The overarching ISMS is certifiable under ISO/IEC 27001; ISO/IEC 27035 supplies the operational incident-management process for it, especially for controls A.5.24–A.5.28.
The standard establishes exactly the process steps – detection, assessment, decision, reporting – needed to reliably meet NIS2's staged deadlines (24-hour early warning, 72-hour notification, one-month final report).
An event is an identifiable change of state that may be security-relevant. An incident is one or more events that actually threaten information security. The Assessment and Decision phase makes exactly this distinction.
Four parts: 27035-1:2023 (principles and process), 27035-2:2023 (planning and preparation), 27035-3:2020 (ICT incident response operations) and 27035-4:2024 (coordination across organisational boundaries).
ISO/IEC 27001 requires an incident-management process but describes it only briefly. ISO/IEC 27035 details and hardens that process – closing the gap between the requirement and an audit-proof implementation.
We raise your incident response to ISO/IEC 27035 level – aligned with NIS2, DORA and your ISO 27001 ISMS.