ISO/IEC 27000 Assessment And Decision on Information Security Events, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to assessment and decision on information security events.
Assessment Step
1
Assessment And Decision on Information Security Events (AssessmentAndDecisiononInformationSecurityEvents)
Does the organization assess information security events and determine whether they should be categorized as information security incidents?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Assessment And Decision on Information Security Events
The organization shall assess information security events and decide if they are to be categorized as information security incidents.
Citations
27001
Annex A, Control 5.25
27002
Section 5.25
|