1 Scope
This document is the foundation of the ISO/IEC 27035 series. It presents basic concepts, principles and process with key activities of information security incident management, which provide a structured approach to preparing for, detecting, reporting,
assessing, and responding to incidents, and applying lessons learned.
The guidance on the information security incident management process and its key activities given in this document are generic and
intended to be applicable to all organizations, regardless of type, size or nature.
Organizations can adjust the guidance according to their type, size and nature of
business in relation to the information security risk situation. This document is
also applicable to external organizations providing information security incident management services.
BS ISO/IEC 27035-1:2023 history
2023BS ISO/IEC 27035-1:2023 Information technology. Information security incident management. Principles and process
2016BS ISO/IEC 27035-1:2016 Information technology. Security techniques. Information security incident management. Principles of incident management
2011BS ISO/IEC 27035:2011 Information technology. Security techniques. Information security incident management