ISO/IEC 27035
Prepare for, detect, respond to and learn from information security incidents.
ISO/IEC 27035: what it is and why it matters
The ISO/IEC 27035 series gives guidance on managing information security incidents in a structured way: planning and preparation, detection and reporting, assessment and decision, response, and lessons learned.
It suits organisations that want incident handling to be a rehearsed process with defined roles rather than an improvised reaction.
Built for the people who carry the work
- Security operations and incident response team members
- Incident managers and service desk leads
- Risk and compliance staff who own incident procedures
- Managers who must make decisions during an incident
What you will be able to do
- Describe the phases of an incident management process
- Design incident categories, severity levels and escalation paths
- Define roles, communication and evidence handling
- Run post-incident reviews that change controls
- Test the plan with exercises
Subject outline
- 01
Principles and phases of incident management
- 02
Planning and preparation
- 03
Detection, reporting and triage
- 04
Assessment, decision and response
- 05
Lessons learned and improvement
- 06
Incident response planning guidance
- 07
Tabletop exercises and testing
How it supports real work
Writing a runbook that a night-shift analyst can follow
Deciding when to escalate to legal, communications and regulators
Closing the loop so incidents improve controls
Training, examination and certification are different steps
ISO/IEC 27035 is guidance and has no organisational certificate of its own. Personal credentials built on it come from third-party bodies, with their own exam and eligibility rules.
- Training does not by itself award a credential.
- Credentials depend on the issuing body and normally involve an exam.
- Ask us which credential, if any, matches your goal.
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Is ISO/IEC 27035 a single document?
No. It is a multi-part series covering principles, incident response planning and operations.
Is it the same as a SOC procedure?
No. It is guidance on the management process around incidents. A SOC procedure is one way to operate part of it.
Can we practise with our own scenarios?
Scenario-based exercises can be discussed on enquiry. See our incident readiness services too.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for ISO/IEC 27035.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


