Back to Frameworks

ISO/IEC 27035-1:2023

International
v2023 (second edition)
2 domains
19 controls

ISO/IEC 27035-1:2023 is the foundation of the ISO/IEC 27035 series: the concepts, principles and process of information security incident management. Clause 4 sets out why events and incidents occur, the objectives (detect and decide on events, assess and respond within a predetermined time frame, minimize impact, escalate to crisis management and back, deal with the vulnerabilities involved, learn quickly, document consistently for metrics), the nine benefits of a structured approach, proportionality to the organization's size, scope, risk and goals, the capability (policies, plan and process; an incident management team under an incident manager and incident response teams under an incident coordinator, with authority, trust and external relationships), communication across phases and organizations, and the documentation set (event report, incident management log, incident report, incident register). Clause 5 gives the five-phase process with its key activities: plan and prepare, detect and report, assess and decide, respond, learn lessons. Annexes relate the series to the investigative standards, give example incidents, cross-reference ISO/IEC 27001 and cover situations discovered during an investigation. Guidance, not certifiable; the process reference behind the incident controls of ISO/IEC 27002 and of most security frameworks.

Verified

ISO/IEC 27035-1:2023 is a compliance framework from International with 2 domains and 19 controls. The largest domains are Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023 (13 controls), Clause 5: Process – ISO/IEC 27035-1:2023 (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (2)

Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023

13 controls
Controls in the Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023 domain of ISO/IEC 27035-1:202313 controls
CodeTitle
iso-iec-27035-1-2023::4.1Basic concepts
iso-iec-27035-1-2023::4.2Objectives of incident management
iso-iec-27035-1-2023::4.3Benefits of a structured approach
iso-iec-27035-1-2023::4.4Adaptability
iso-iec-27035-1-2023::4.5.1General: an incident management capability proportionate to crises as well as incidents
iso-iec-27035-1-2023::4.5.2Policies, plan and process
iso-iec-27035-1-2023::4.5.3Incident management structure
iso-iec-27035-1-2023::4.6Communication
iso-iec-27035-1-2023::4.7.1General: documenting events, incidents and vulnerabilities throughout
iso-iec-27035-1-2023::4.7.2Event report
iso-iec-27035-1-2023::4.7.3Incident management log
iso-iec-27035-1-2023::4.7.4Incident report
iso-iec-27035-1-2023::4.7.5Incident register

Clause 5: Process – ISO/IEC 27035-1:2023

6 controls
Controls in the Clause 5: Process – ISO/IEC 27035-1:2023 domain of ISO/IEC 27035-1:20236 controls
CodeTitle
iso-iec-27035-1-2023::5.1Overview of the process
iso-iec-27035-1-2023::5.2Plan and prepare
iso-iec-27035-1-2023::5.3Detect and report
iso-iec-27035-1-2023::5.4Assess and decide
iso-iec-27035-1-2023::5.5Respond
iso-iec-27035-1-2023::5.6Learn lessons

What is ISO/IEC 27035-1:2023 and who does it apply to?

ISO/IEC 27035-1:2023 is a compliance framework from International with 2 domains and 19 controls. ISO/IEC 27035-1:2023 is the foundation of the ISO/IEC 27035 series: the concepts, principles and process of information security incident management. Clause 4 sets out why events and incidents occur, the objectives (detect and decide on events, assess and respond within a predetermined time frame, minimize impact, escalate to crisis management and back, deal with the vulnerabilities involved, learn quickly, document consistently for metrics), the nine benefits of a structured approach, proportionality to the organization's size, scope, risk and goals, the capability (policies, plan and process; an incident management team under an incident manager and incident response teams under an incident coordinator, with authority, trust and external relationships), communication across phases and organizations, and the documentation set (event report, incident management log, incident report, incident register). Clause 5 gives the five-phase process with its key activities: plan and prepare, detect and report, assess and decide, respond, learn lessons. Annexes relate the series to the investigative standards, give example incidents, cross-reference ISO/IEC 27001 and cover situations discovered during an investigation. Guidance, not certifiable; the process reference behind the incident controls of ISO/IEC 27002 and of most security frameworks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 27035-1:2023 actually require?

ISO/IEC 27035-1:2023 has 19 controls organised across 2 domains. The largest domains are Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023 (13 controls), Clause 5: Process – ISO/IEC 27035-1:2023 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 27035-1:2023 do I already cover?

ISO/IEC 27035-1:2023 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO/IEC 27035-1:2023?

Start your ISO/IEC 27035-1:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27035-1:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 19 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required