Reading time: ~ 3 min.

The information security incident management process according to the ISO/IEC 27035-2
Please be aware that these guidelines are related to on the «plan and prepare» and the «lessons learned» steps of the information security incident management model based on the ISO/IEC 27035-1:2023 standard.
The ISO/IEC 27035-2:2023 main aspects on the «plan & prepare» steps
If we consider the «plan & prepare» steps of the ISO/IEC 27035-2:2023, we can notice that the standard includes in particular these principal aspects:
✅ information security policies, including those relating to risk management, updated at both organizational level and system, service and network levels;
✅ information security incident management plan;
✅ Incident Management Team (IMT) establishment;
✅ establishing relationships and connections with internal and external organizations;
✅ technical and other support (including organizational and operational support);
✅ information security incident management awareness briefings and training.
The ISO/IEC 27035-2:2023 main aspects on the «lessons learned» phase
If we take a look at the «lessons learned» phase as considered by the ISO/IEC 27035-2:2023, we can notice that the standard includes in particular these main aspects:
✅ identifying and making necessary improvements;
✅ incident Response Team (IRT) evaluation.
ISO/IEC 27035-2:2023 Information security incident management and the correlation with others standards
If we reflect on the others ISO standards we can put in relation with this ISO/IEC 27035-2, we can easily find out these ones:
- ISO 27001 Information Security Standards (in particular Appendix A);
- ISO 20000-1 Services (clause 8.6.1 incident management)
- ISO 22301 Business continuity.
The ISO/IEC27035-2:2023 standard on information security incident management
