ISO/IEC 27000 Information Security Incident Management Planning and Preparation, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information security incident management planning and preparation.

Assessment Step

1
Information Security Incident Management Planning and Preparation (InformationSecurityIncidentManagementPlanningandPreparation)
Does the organization plan and prepare for managing information security incidents by defining, establishing, and communicating incident management processes, roles, and responsibilities?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Information Security Incident Management Planning and Preparation
The organization shall plan and prepare for managing information security incidents by defining, establishing and communicating information security incident management processes, roles and responsibilities.
Citations
27001
Annex A, Control 5.24
27002
Section 5.24