GSO ISO/IEC 27035-2:2026

ISO/IEC 27035-2:2023
Gulf Standard   Current Edition · Approved on 17 September 2026

Information technology — Information security incident management — Part 2: Guidelines to plan and prepare for incident response

GSO ISO/IEC 27035-2:2026 Files

English 53 Pages
Current Edition Reference Language
USD 245.59

GSO ISO/IEC 27035-2:2026 Scope

This document provides guidelines to plan and prepare for incident response and to learn lessons from incident response. The guidelines are based on the “plan and prepare” and “learn lessons” phases of the information security incident management phases model presented in ISO/IEC 27035-1:2023, 5.2 and 5.6.

The major points within the “plan and prepare” phase include:

—    information security incident management policy and commitment of top management;

—    information security policies, including those relating to risk management, updated at both organizational level and system, service and network levels;

—    information security incident management plan;

—    Incident Management Team (IMT) establishment;

—    establishing relationships and connections with internal and external organizations;

—    technical and other support (including organizational and operational support);

—    information security incident management awareness briefings and training.

The “learn lessons” phase includes:

—    identifying areas for improvement;

—    identifying and making necessary improvements;

—    Incident Response Team (IRT) evaluation.

The guidance given in this document is generic and intended to be applicable to all organizations, regardless of type, size or nature. Organizations can adjust the guidance given in this document according to their type, size and nature of business in relation to the information security risk situation. This document is also applicable to external organizations providing information security incident management services.

Best Sellers From Information Sector

GSO ISO/TR 18492:2017
ISO/TR 18492:2005 
Gulf Standard
Long-term preservation of electronic document-based information
GSO ISO/TS 23635:2024
ISO/TS 23635:2022 
Gulf Standard
Blockchain and distributed ledger technologies — Guidelines for governance
GSO ISO/IEC 15773:2013
ISO/IEC 15773:1998 
Gulf Standard
Information technology -- Telecommunications and information exchange between systems -- Broadband Private Integrated Services Network -- Inter-exchange signalling protocol -- Transit counter additional network feature
GSO ISO 11238:2017
ISO 11238:2012 
Gulf Standard
Health informatics -- Identification of medicinal products -- Data elements and structures for the unique identification and exchange of regulated information on substances

Recently Published from Information Sector

GSO ISO/IEC 23773-1:2026
ISO/IEC 23773-1:2024 
Gulf Standard
Information technology — User interfaces for automatic simultaneous interpretation systems — Part 1: General
GSO ISO/IEC TS 19770-10:2026
ISO/IEC TS 19770-10:2025 
Gulf Standard
Information technology — IT asset management — Part 10: Guidance for implementing ITAM
GSO ISO 19168-1:2026
ISO 19168-1:2025 
Gulf Standard
Geographic information — Geospatial API for features — Part 1: Core
GSO ISO/IEC TS 33062:2026
ISO/IEC TS 33062:2025 
Gulf Standard
Information technology — Process assessment — Process assessment model for quantitative processes to support higher levels of process capability in ISO/IEC 33020