ISO27001:2022 – A5.26 Response to Information Security Incidents

Introduction to ISO 27001 – A5.26

ISO 27001 – A5.26 is just one of a series in ISO27001, related to incident management, each building upon the last to form a comprehensive approach. You should also review:

What does ISO 27001 – A5.26 require?

“Information security incidents shall be responded to in accordance with the documented procedures.”

(ISO 27001 – A5.26 – Response to Information Security Incidents)

Why is this required?

People respond differently in a crisis. Having a documented incident response procedure ensures that responses are effective, consistent, and repeatable. A documented approach also reduces stress and confusion, improves communication, and helps people act faster.

What the auditor is looking for

The auditor will look for:

  • A documented Incident Response Plan (IRP)
  • Clear roles and responsibilities
  • References to related plans such as BCP and DRP
  • Assessment criteria (see A5.25)
  • Collection of evidence procedures (A5.28)

What do you need to do?

Create an Incident Response Plan that is:

  • Short – aim for 1–2 pages
  • Simple – focused on critical information and actions
  • Practical – usable in a crisis

WARNING:

Some Consultants will try and sell you a 10. 20, 60 and even a 100 page Plan(!). THIS WILL NOT HELP YOU IN A CRISIS!  There are many psychological reasons we can go into on this, but some consultants (NOT Consultants Like Us!) give you lengthy documents to justify their existence. But believe me, it’s incredibly hard, and takes some effort to get your plans as short as these.  When it comes to Incident Response Plans… Size matters!

 The plan should include:

  • Who is responsible for what?
  • Who should be informed?
  • What are the immediate actions to take?
  • How to communicate internally and externally
  • Key contacts (internal, supplier, legal, etc.)

Once this is in place, build out separate Business Continuity Plans (BCPs) that provide functional-level recovery actions (e.g. what HR, IT, or Finance should do).

Instead of focusing on the cause of the incident, BCPs should focus on the impact: loss of people, systems, or premises — regardless of how it occurred.

Q & A

Do I have to document the IRP and BCP separately?

No, but it’s recommended. Keep the IRP short and strategic (for leadership), and the BCP more detailed and operational (for departments).

Do we need to test our plans?

Yes. You can start with a walkthrough, then move on to tabletop exercises. For example, simulate a ransomware attack and ask: What do we do Day 1? Day 2?

Difficulty Rating

3 out of 5 – While technical skills are not required, writing a useful and usable plan is harder than it seems. Avoid overly complex or lengthy plans; aim for clarity and usability under pressure.

More Questions?

Incident management ties in with many other controls – don’t treat it in isolation. If you have more questions please don’t hesitate to contact us and we would be happy to help.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… The Real Easy Guide to ISO27001” available on Amazon.

ISO 27001 – A5.26
ISO 27001 – A5.26