Book an Appointment
GRC · Incident Management

ISO/IEC 27035 master security incidents with structure

The international standard for Information Security Incident Management provides the process backbone behind incident response and forensics – from preparation all the way to the lessons-learned loop.

27035-1:2023Current edition (Part 1, 2nd edition)
Multi-partParts 1–4 (process, planning, ICT response, coordination)
Not certifiableGuidance, not a certification standard
NIS2 & DORANormative basis for reporting and response duties

What ISO/IEC 27035 covers

ISO/IEC 27035 describes a structured, repeatable lifecycle for handling information security incidents. Instead of reacting ad hoc to attacks, outages or data leaks, the standard establishes an end-to-end process: detect, report, assess, decide, contain, recover and learn from every incident.

The standard is multi-part: Part 1 (27035-1:2023) defines principles and the process, Part 2 (27035-2:2023) planning and preparation, Part 3 (27035-3:2020) operational ICT incident response and Part 4 (27035-4:2024) cross-organisation coordination. ISO/IEC 27035 is guidance and not certifiable on its own – but it is the operational backbone for incident handling within an ISO/IEC 27001-certified ISMS.

The five-phase lifecycle

ISO/IEC 27035 breaks incident handling into five phases that build on one another.

01

Plan and Prepare

Incident response policy, roles, an Incident Response Team (IRT), reporting channels, playbooks, tooling and awareness are set up before the first incident – the foundation of any resilient response.

02

Detection and Reporting

Events are captured through monitoring, SIEM, reports and detection, recognised as security-relevant and reported promptly through defined channels.

03

Assessment and Decision

Reported events are triaged, classified and prioritised. A decision is made on whether a security incident exists and what escalation is required.

04

Responses

Containment, eradication, recovery and – where needed – forensic evidence preservation, plus internal and external communication including regulatory notifications.

05

Lessons Learned

Post-incident review, root-cause analysis, updates to controls and playbooks, and metrics – each incident demonstrably improves the security posture.

Bridge to NIS2, DORA and ISO 27001

ISO/IEC 27035 is the normative underpinning for regulatory reporting and response duties.

NIS2 (Art. 23 reporting duties)

NIS2's staged deadlines – early warning within 24 hours, notification within 72 hours, final report within one month – presuppose exactly the process that ISO/IEC 27035 provides through detection, assessment and reporting.

DORA (incident reporting)

For financial entities the lifecycle covers the classification and reporting of major ICT-related incidents under DORA from a normative standpoint – from initial notification to final report.

ISO/IEC 27001 (A.5.24–A.5.28)

Controls A.5.24 to A.5.28 of Annex A of ISO/IEC 27001:2022 (planning, assessment, response, learning, evidence collection) are directly operationalised and made audit-ready by ISO/IEC 27035.

CRA & vulnerability handling

The Cyber Resilience Act (CRA) requires active vulnerability handling and reporting of exploited vulnerabilities – the response and reporting processes from 27035 map directly onto it.

How we work with you

From baseline assessment to an operational incident-response capability.

01

1 · Maturity & gap analysis

We assess your existing incident handling against the five phases of ISO/IEC 27035 and against your regulatory duties (NIS2, DORA, ISO 27001).

02

2 · Process & playbooks

We design incident response policy, roles, reporting chains and scenario-based playbooks – including the 24h/72h/1-month reporting logic.

03

3 · Enablement & exercising

We enable your Incident Response Team through tabletop exercises and simulated incidents and integrate detection, SIEM and escalation.

04

4 · Operate & improve

We embed lessons-learned loops, metrics and regular reviews – keeping the process effective and audit-ready.

Frequently asked questions

Answers on ISO/IEC 27035 in practice.

Can you get certified against ISO/IEC 27035?

No. ISO/IEC 27035 is guidance and not certifiable on its own. The overarching ISMS is certifiable under ISO/IEC 27001; ISO/IEC 27035 supplies the operational incident-management process for it, especially for controls A.5.24–A.5.28.

How does ISO/IEC 27035 help with NIS2 reporting duties?

The standard establishes exactly the process steps – detection, assessment, decision, reporting – needed to reliably meet NIS2's staged deadlines (24-hour early warning, 72-hour notification, one-month final report).

What is the difference between an event and an incident?

An event is an identifiable change of state that may be security-relevant. An incident is one or more events that actually threaten information security. The Assessment and Decision phase makes exactly this distinction.

What parts make up the standard?

Four parts: 27035-1:2023 (principles and process), 27035-2:2023 (planning and preparation), 27035-3:2020 (ICT incident response operations) and 27035-4:2024 (coordination across organisational boundaries).

Do we need 27035 if we already have ISO 27001?

ISO/IEC 27001 requires an incident-management process but describes it only briefly. ISO/IEC 27035 details and hardens that process – closing the gap between the requirement and an audit-proof implementation.

Make your incident handling operational

We raise your incident response to ISO/IEC 27035 level – aligned with NIS2, DORA and your ISO 27001 ISMS.