Assessment and decision on information security events
Summary
The organisation shall assess information security events and decide if they are to be categorised as information security incidents.
incident management
Read the full official text: https://www.iso.org/standard/27001
← Clause 5.24
Information security incident management planning and preparation
Clause 5.26 →
Response to information security incidents
Track ISO 27001 clause 5.25 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial