ISO/IEC 27035-1:2023
ISO/IEC 27035-1:2023 is the foundation of the ISO/IEC 27035 series: the concepts, principles and process of information security incident management. Clause 4 sets out why events and incidents occur, the objectives (detect and decide on events, assess and respond within a predetermined time frame, minimize impact, escalate to crisis management and back, deal with the vulnerabilities involved, learn quickly, document consistently for metrics), the nine benefits of a structured approach, proportionality to the organization's size, scope, risk and goals, the capability (policies, plan and process; an incident management team under an incident manager and incident response teams under an incident coordinator, with authority, trust and external relationships), communication across phases and organizations, and the documentation set (event report, incident management log, incident report, incident register). Clause 5 gives the five-phase process with its key activities: plan and prepare, detect and report, assess and decide, respond, learn lessons. Annexes relate the series to the investigative standards, give example incidents, cross-reference ISO/IEC 27001 and cover situations discovered during an investigation. Guidance, not certifiable; the process reference behind the incident controls of ISO/IEC 27002 and of most security frameworks.
ISO/IEC 27035-1:2023 is a compliance framework from International with 2 domains and 19 controls. The largest domains are Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023 (13 controls), Clause 5: Process – ISO/IEC 27035-1:2023 (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023
| Code | Title |
|---|---|
| iso-iec-27035-1-2023::4.1 | Basic concepts |
| iso-iec-27035-1-2023::4.2 | Objectives of incident management |
| iso-iec-27035-1-2023::4.3 | Benefits of a structured approach |
| iso-iec-27035-1-2023::4.4 | Adaptability |
| iso-iec-27035-1-2023::4.5.1 | General: an incident management capability proportionate to crises as well as incidents |
| iso-iec-27035-1-2023::4.5.2 | Policies, plan and process |
| iso-iec-27035-1-2023::4.5.3 | Incident management structure |
| iso-iec-27035-1-2023::4.6 | Communication |
| iso-iec-27035-1-2023::4.7.1 | General: documenting events, incidents and vulnerabilities throughout |
| iso-iec-27035-1-2023::4.7.2 | Event report |
| iso-iec-27035-1-2023::4.7.3 | Incident management log |
| iso-iec-27035-1-2023::4.7.4 | Incident report |
| iso-iec-27035-1-2023::4.7.5 | Incident register |
Clause 5: Process – ISO/IEC 27035-1:2023
| Code | Title |
|---|---|
| iso-iec-27035-1-2023::5.1 | Overview of the process |
| iso-iec-27035-1-2023::5.2 | Plan and prepare |
| iso-iec-27035-1-2023::5.3 | Detect and report |
| iso-iec-27035-1-2023::5.4 | Assess and decide |
| iso-iec-27035-1-2023::5.5 | Respond |
| iso-iec-27035-1-2023::5.6 | Learn lessons |
What is ISO/IEC 27035-1:2023 and who does it apply to?
ISO/IEC 27035-1:2023 is a compliance framework from International with 2 domains and 19 controls. ISO/IEC 27035-1:2023 is the foundation of the ISO/IEC 27035 series: the concepts, principles and process of information security incident management. Clause 4 sets out why events and incidents occur, the objectives (detect and decide on events, assess and respond within a predetermined time frame, minimize impact, escalate to crisis management and back, deal with the vulnerabilities involved, learn quickly, document consistently for metrics), the nine benefits of a structured approach, proportionality to the organization's size, scope, risk and goals, the capability (policies, plan and process; an incident management team under an incident manager and incident response teams under an incident coordinator, with authority, trust and external relationships), communication across phases and organizations, and the documentation set (event report, incident management log, incident report, incident register). Clause 5 gives the five-phase process with its key activities: plan and prepare, detect and report, assess and decide, respond, learn lessons. Annexes relate the series to the investigative standards, give example incidents, cross-reference ISO/IEC 27001 and cover situations discovered during an investigation. Guidance, not certifiable; the process reference behind the incident controls of ISO/IEC 27002 and of most security frameworks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27035-1:2023 actually require?
ISO/IEC 27035-1:2023 has 19 controls organised across 2 domains. The largest domains are Clause 4: Overview, capability, communication and documentation – ISO/IEC 27035-1:2023 (13 controls), Clause 5: Process – ISO/IEC 27035-1:2023 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27035-1:2023 do I already cover?
ISO/IEC 27035-1:2023 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 27035-1:2023?
Start your ISO/IEC 27035-1:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27035-1:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 19 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required