What is ISO/IEC 27035-1 - Principles of incident management in information technology about?
ISO/IEC 27035 is an international standard on security techniques that discusses information security incident management for information technology. ISO/IEC 27035-1 provides the best industry guidance on the principles of incident management to take appropriate decisions for information security incidents.
ISO/IEC 27035-1 is the first part of a multi-part series that presents basic concepts and phases of information security incident management and combines these concepts with principles in a structured approach to detecting, reporting, assessing, and responding to incidents, and applying lessons learnt.
The principles given in ISO/IEC 27035-1 are generic and intended to be applied to all organizations, regardless of type, size, or nature.
Organizations can adjust the guidance given in ISO/IEC 27035-1 according to their type, size and nature of business to the information security risk situation.
ISO/IEC 27035-1 also applies to external organizations providing information security incident management services.
Who is ISO/IEC 27035-1 - Principles of incident management in information technology for?
ISO/IEC 27035-1 on the principles of incident management in information technology is relevant to:
- IT organisations and institutions
- Personal or technical team
- Engineers and developers
Why should you use ISO/IEC 27035-1 - Principles of incident management in information technology?
Information security policies or controls alone will not guarantee total protection of information, information systems, services, or networks. After controls have been implemented, residual vulnerabilities are likely to remain that can reduce the effectiveness of information security and facilitate the occurrence of information security incidents.
ISO/IEC 27035-1 guideline assists you with basic concepts, principles, objectives of incident management, benefits of a structured approach, adaptability, planning, preparation, detection, reporting, assessment, and decision for principles of incident management.
With compliance and obedience to ISO/IEC 27035-1, you can detect, report, assess and take appropriate decisions for information security incidents.