ISO 27035: A Practical Guide to Information Security Incident Management
Back to InsightsInformation Security

ISO 27035: A Practical Guide to Information Security Incident Management

MaxStandards Editorial Team 31 August 2026 5 min read

What Is ISO 27035?

ISO/IEC 27035 is the international standard for Information Security Incident Management. Published in three parts, it provides organisations with a structured, repeatable approach to planning for, detecting, reporting, assessing, and responding to information security incidents — and learning from them to prevent recurrence.

Unlike ISO 27001, which governs the broader Information Security Management System (ISMS), ISO 27035 focuses specifically on the incident lifecycle: from the moment an anomaly is detected to the point where lessons learned are fed back into security controls. For organisations that have already achieved ISO 27001 certification, ISO 27035 is the natural next step toward operational security maturity.

The Three-Part Structure of ISO 27035

ISO 27035 is organised into three complementary parts, each addressing a distinct aspect of incident management:

  • ISO 27035-1: Principles of incident management — Establishes the foundational concepts, objectives, and high-level process model for managing information security incidents and events.
  • ISO 27035-2: Guidelines to plan and prepare for incident response — Covers the development of an Incident Response Plan (IRP), team structures, communication protocols, and readiness testing.
  • ISO 27035-3: Guidelines for ICT incident response operations — Provides detailed operational guidance for handling incidents in ICT environments, including triage, containment, eradication, and recovery.

Together, these three parts give security teams a complete operational playbook — from strategic planning through to hands-on response and post-incident review.

Key Requirements and Process Phases

ISO 27035 defines a five-phase incident management lifecycle that organisations must implement:

1. Plan and Prepare

Before any incident occurs, organisations must establish an Incident Response Policy, define roles and responsibilities within a dedicated Information Security Incident Response Team (ISIRT), and develop documented procedures for detection, escalation, and communication. Tabletop exercises and simulations are strongly recommended to validate readiness.

2. Detection and Reporting

Effective incident management depends on reliable detection mechanisms — SIEM tools, intrusion detection systems, endpoint monitoring, and user reporting channels. ISO 27035 requires clear criteria for distinguishing security events (observable occurrences) from security incidents (events that compromise confidentiality, integrity, or availability). All potential incidents must be logged and reported through defined channels without delay.

3. Assessment and Decision

Once reported, incidents must be assessed for severity, scope, and business impact. ISO 27035 recommends a structured triage process using predefined classification criteria — for example, categorising incidents by type (malware, unauthorised access, data breach) and by impact level (low, medium, high, critical). This assessment drives the escalation and response decisions that follow.

4. Responses

The response phase covers containment, eradication, and recovery. Containment limits the spread of the incident; eradication removes the root cause; recovery restores affected systems and services to normal operation. ISO 27035 emphasises that response actions must be documented in real time to support forensic analysis and regulatory reporting obligations — particularly relevant under GDPR's 72-hour breach notification requirement.

5. Lessons Learned

Post-incident reviews are a mandatory element of ISO 27035. Organisations must analyse what happened, why existing controls failed or were bypassed, and what improvements are needed. Findings feed directly into the ISMS risk register and control set, creating a continuous improvement loop that strengthens security posture over time.

How ISO 27035 Integrates with Other Standards

ISO 27035 is designed to complement, not replace, other management system standards:

  • ISO 27001: Annex A control A.16 (Information Security Incident Management) maps directly to ISO 27035. Organisations certified to ISO 27001 can use ISO 27035 to operationalise their incident management controls.
  • ISO 22301: Business continuity plans and incident response plans must be aligned. A major security incident may trigger business continuity procedures, so the two frameworks should be tested together.
  • ISO 27701: Privacy incident management — including personal data breaches — requires the same structured response approach, with additional obligations around data subject notification.

Benefits of Implementing ISO 27035

Organisations that implement ISO 27035 gain measurable advantages across operational, regulatory, and reputational dimensions:

  • Faster, more consistent incident response: Documented procedures and trained teams reduce mean time to detect (MTTD) and mean time to respond (MTTR), limiting the business impact of incidents.
  • Regulatory compliance support: Structured incident logging and breach notification procedures directly support compliance with GDPR, NIS2, and sector-specific regulations such as DORA (Digital Operational Resilience Act) for financial services.
  • Reduced financial exposure: Faster containment limits data loss, system downtime, and the associated costs of remediation, legal liability, and regulatory fines.
  • Improved stakeholder confidence: Demonstrating a certified, auditable incident management capability reassures customers, partners, and regulators that your organisation takes security seriously.
  • Continuous security improvement: The lessons-learned phase ensures that each incident makes the organisation more resilient, rather than simply returning to the pre-incident state.

Who Should Implement ISO 27035?

ISO 27035 is applicable to any organisation that processes, stores, or transmits sensitive information — regardless of size or sector. It is particularly valuable for:

  • Financial services firms subject to DORA or PCI DSS
  • Healthcare organisations handling patient data under HIPAA or NHS data security standards
  • Technology companies and managed service providers (MSPs) with contractual security obligations
  • Public sector bodies subject to NIS2 or national cybersecurity regulations
  • Any organisation that has achieved ISO 27001 and wants to strengthen its operational security capabilities

Getting Started with ISO 27035 Certification

Implementing ISO 27035 typically involves a gap analysis against your current incident response capabilities, development or enhancement of your Incident Response Plan, team training and simulation exercises, and integration with your existing ISMS documentation. Certification is achieved through a third-party audit conducted by an accredited certification body.

At MaxStandards Certification, our consultants have deep expertise in ISO 27035 implementation and audit readiness. We work with your security and compliance teams to build an incident management framework that is both standards-compliant and operationally practical — so your organisation is prepared to respond effectively when incidents occur, not just on paper.

Contact MaxStandards Certification today to discuss your ISO 27035 readiness assessment and take the next step toward a more resilient security posture.