Skip to main content

TNV Inspection Division

ISO/IEC 27035-1:2023 – Information Security Incident Management: Principles and Process


Every organisation will face a security incident eventually. The ones that come through it well are not the ones that hoped it would not happen, but the ones that were ready: a plan in place, clear roles, fast detection, and a habit of learning afterwards. ISO/IEC 27035-1:2023 is the standard that lays out how to build that readiness.

This page explains what ISO/IEC 27035-1:2023 is, the incident management process it defines, and how TNV Inspection Division assesses an organisation against it. TNV is a UAF accredited inspection body operating under ISO/IEC 17020:2012.

What Is ISO/IEC 27035-1:2023?

ISO/IEC 27035-1:2023 is the international standard for the principles and process of information security incident management. Its full title is Information technology — Information security incident management — Part 1: Principles and process, and it is the foundation of the wider ISO/IEC 27035 series.

It sets out the basic concepts, principles, and key activities for managing incidents in a structured way. The guidance is deliberately generic, so it applies to any organisation regardless of type, size, or nature, and it also covers external organisations that provide incident management services. It is a process and principles standard, used to build and assess incident management, rather than a certifiable requirements standard on its own.

The Information Security Incident Management Process

The heart of the standard is a clear, repeatable lifecycle. Its key phases are:

  • Plan and prepare. Put the policy, team, roles, tools, and procedures in place before anything happens.
  • Detect and report. Spot events and incidents and get them reported quickly through the right channels.
  • Assess and decide. Judge what is actually happening and decide the right course of action.
  • Contain, resolve, and recover from the incident.
  • Learn lessons. Review what happened and feed it back so the next response is better.

The aim across all of it is a systematic approach that limits the damage of an incident, keeps communication working under pressure, and turns every incident into an improvement.

How TNV Uses ISO/IEC 27035-1 as the Reference Standard

A readiness check is only meaningful against a recognised benchmark. ISO/IEC 27035-1 is that benchmark. As a UAF accredited inspection body under ISO/IEC 17020, we take the principles and process defined in the standard as the criteria and assess an organisation’s incident management against them, phase by phase.

Because the standard is guidance on principles and process, what we provide is an independent assessment and gap review against it, not a certificate. The value is an outside, evidence-based view of how ready your organisation actually is, measured against an international reference rather than a feeling.

How We Assess Incident Management Against ISO/IEC 27035-1

Our assessment follows the lifecycle in the standard, so the whole picture is covered. In practice, an ISO/IEC 27035-1 assessment by TNV looks at the following.

  • Plan and prepare. We review the incident management policy, the team and roles, escalation paths, tooling, and procedures.
  • Detection and reporting. We check how events are detected, classified, and reported, and how quickly.
  • Assessment and decision-making. We review how incidents are triaged and how decisions on response are made and recorded.
  • We examine containment, resolution, recovery, and communication during an incident, including past incident records.
  • Lessons learned. We check whether reviews happen and whether findings actually feed back into improvements.

Our team works through these using document review, record and log checks, and interviews with the people who would run a real response. We record observations with evidence and keep you informed. The deliverable is a detailed assessment report: where your incident management aligns with ISO/IEC 27035-1, the gaps, and practical recommendations to close them.

Our UAF Accreditation Explained

TNV Global Limited (TNV) is accredited by the United Accreditation Foundation (UAF) for inspection, under ISO/IEC 17020:2012 – Conformity assessment – Requirements for bodies providing various types of inspection. We hold that accreditation now, and we keep it through regular surveillance and witnessed inspections.

UAF is a signatory of the IAF MLA and the APAC MRA, the international recognition arrangements that let a report carry weight outside the country it was written in, and our accreditation covers work across most of Europe, the Americas, the Middle East, Africa, and Asia.

What Our Accreditation Means for You

Your report carries weight, because it comes from an independent body with recognised accreditation rather than from an internal review. ISO/IEC 17020 keeps us impartial and clear of any tie to the organisation we assess, so what we report is simply what we found. And the scope, method, and reference standard for the assessment are all set out before we start.

Why Does ISO/IEC 27035-1 Matter for Your Business?

The cost of an incident is rarely the breach itself; it is the chaos that follows when no one knows who does what. A tested, structured incident management process limits damage, keeps regulators and customers informed, and shortens recovery. ISO/IEC 27035-1 gives that process a recognised shape, and an independent assessment against it shows partners, insurers, and regulators that your readiness is real, not assumed.

Who Should Use ISO/IEC 27035-1?

  • Organisations of any size building or improving incident response.
  • Security and IT teams responsible for detecting and handling incidents.
  • Managed security and incident-response service providers.
  • Risk, compliance, and business-continuity teams that need confidence in readiness.

How to Arrange an ISO/IEC 27035-1 Assessment with TNV

  1. Share your requirement. Reach us by website, email, phone, or WhatsApp and tell us what you want assessed. We review the scope against ISO/IEC 27035-1 and send a clear proposal covering method, timeline, and cost.
  2. We plan the assessment. We agree the scope, build the plan around the lifecycle, and assign assessors with the right experience.
  3. We assess. We review your incident management against the standard, working from documents, records, and interviews, and recording findings with evidence.
  4. We report. You receive the detailed assessment report within the agreed timeframe.
  5. We follow up. We answer questions, help you act on the findings, and run follow-up reviews where useful.

Why Choose TNV Inspection Division?

TNV Inspection Division is an independent, UAF accredited inspection body working under ISO/IEC 17020:2012. Independence and impartiality are built into how we operate, which is exactly what a credible readiness assessment needs. You get an outside party with recognised accreditation, qualified assessors, and a report your leadership, insurers, and partners can rely on.

Frequently Asked Questions(FAQ)

What is ISO/IEC 27035-1:2023 in simple terms?
It is the international standard that sets out the principles and process for managing information security incidents, from preparing for them to learning lessons afterwards.
What are the phases of the incident management process?
Plan and prepare, detect and report, assess and decide, respond, and learn lessons.
Can you get certified to ISO/IEC 27035-1?
It is a principles and process standard. TNV provides an independent assessment and gap review against it rather than a certificate.
Who is ISO/IEC 27035-1 for?
Any organisation that wants reliable incident response, including managed security and incident-response service providers.
How do I arrange an assessment with TNV?
Send us the details by website, email, phone, or WhatsApp. We review the scope, share a proposal, plan the work, assess, and deliver a clear report with follow-up support.

Talk to TNV Inspection Division

Want an independent, accredited assessment of your incident management against ISO/IEC 27035-1? Contact TNV Inspection Division for a clear scope and a free quote.

© 2026 All Rights Reserved. TNV Certification