ISO/IEC standards related to information security incident management
ISO/IEC 27035 is the guideline standard for information security incident management. There are also six other standards that relate to information security incident management in one way or the other. Let’s explore all seven standards as follows:
- ISO/IEC 27035 (Information technology – Security techniques – Information security incident management) (https://www.iso.org/): Information security incident management is explained, focusing on detection, reporting, evaluation, response, and lessons learned, which comprises three parts (https://www.iso.org/):
- Part 1: The principles of incident management
- Part 2: Guidelines for planning and preparing for incident response
- Part 3: Guidelines for ICT incident response operations
- ISO/IEC 27037 (Information technology – Security techniques – Guidelines for identification, collection, acquisition, and preservation of digital evidence...