// Information Security
ISO/IEC 27035 Incident Management Compliance Software
Principles and processes for information security incident management.
Framework at a glance
Short name
ISO 27035
Version
—
Category
Information Security
Controls
25
What ISO 27035 covers
25 controls across 22 domains — every one tracked, owned and evidenced in Cyber Horizon.
Policy
1 controls- 5.1 Incident management policy
Objectives
1 controls- 5.2 Incident management objectives
Governance
2 controls- 5.3 Incident management roles
- 10.3 CSIRT establishment
Procedures
1 controls- 5.4 Incident management procedure
Detection
1 controls- 6.1 Event detection
Reporting
2 controls- 6.2 Event reporting
- 10.1 Incident metrics
Triage
1 controls- 6.3 Incident assessment
Response
1 controls- 6.4 Initial response
Classification
1 controls- 7.1 Incident classification
Prioritisation
1 controls- 7.2 Incident prioritisation
Escalation
1 controls- 7.3 Incident escalation
Containment
1 controls- 8.1 Containment
Eradication
1 controls- 8.2 Eradication
Recovery
1 controls- 8.3 Recovery
Forensics
1 controls- 8.4 Evidence collection
Notifications
1 controls- 8.5 Notifications
Communication
1 controls- 8.6 Communication
Review
1 controls- 9.1 Post-incident review
Analysis
2 controls- 9.2 Root cause analysis
- 10.2 Trend analysis
Improvement
1 controls- 9.3 Improvement actions
Documentation
1 controls- 9.4 Incident closure
Training
1 controls- 10.4 CSIRT capabilities
How Cyber Horizon automates ISO 27035
Every ISO 27035 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO/IEC 27035 Incident Management?
Principles and processes for information security incident management.
How many controls does ISO/IEC 27035 Incident Management have?
ISO/IEC 27035 Incident Management has 25 controls in Cyber Horizon's catalogue, organised across 22 domains.
How does Cyber Horizon help with ISO/IEC 27035 Incident Management?
Cyber Horizon maps ISO/IEC 27035 Incident Management into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27035 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Information Security frameworks
See ISO 27035 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27035 in Cyber Horizon.