🚨

ISO/IEC 27035

Information security incident management

Organization: ISO/IEC Category: Incident Management
2
Related Articles
19
Articles with Obligations
7
Key Sections
8
Coverage Areas

Overview

Provides guidelines for information security incident management, including preparation, detection, assessment, response, and lessons learned. Covers the complete incident lifecycle from planning to post-incident activities.

Applicability

Cybersecurity incident detection, response, and recovery

Relevance to Network and Information Security Directive (NIS2)

Essential for NIS2 incident detection, reporting, and response obligations

Key Coverage Areas

1
Incident management policy and planning
2
Incident detection and reporting
3
Incident assessment and classification
4
Incident response procedures
5
Communication during incidents
6
Evidence collection and preservation
7
Post-incident analysis
8
Lessons learned and improvement

Standard Sections & Chapters

5

Incident management planning

6

Detection and reporting

7

Assessment and decision

8

Responses

Part-1

Principles of incident management

Part-2

Guidelines to plan and prepare

Part-3

Guidelines for ICT incident response operations

Related Network and Information Security Directive (NIS2) Articles

Article 21: Cybersecurity risk-management measures

View Article →
Sections: 5, 6, 7, 8

Incident management integration

Implementation Guidance:

Integrate incident management into risk management framework

Mapped Obligations:

  • Set up incident handling procedures

Article 23: Reporting obligations

View Article →
Sections: 6, 7, 8

Incident detection, assessment, and reporting

Implementation Guidance:

Establish 24-hour early warning, incident assessment, and formal reporting procedures

Mapped Obligations:

  • Report significant incidents to CSIRT or competent authority without undue delay
  • Submit early warning within 24 hours of becoming aware of incident
  • Submit incident notification within 72 hours with initial assessment
  • Submit final report within one month after incident notification
  • Notify recipients/customers of services about significant incidents that may affect them
  • Cooperate with authorities on cross-border incident information sharing

Quick Information

Organization
ISO/IEC
Category
Incident Management
Certification
Not available

🤝 Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.