ISO27001:2022 – A5.24 Information security incident management planning and preparation
Introduction to ISO 27001 – A5.24
The purpose of ISO 27001 – A5.24 is to ensure that we respond swiftly, effectively, and consistently to information security incidents, and carry out any actions in an orderly manner.
The Related Controls
This control should not be taken in isolation. It is linked closely with the following Annex A controls:
- A5.25 – Assessment and decision on information security events
- A5.26 – Response to information security incidents
- A5.27 – Learning from information security incidents
- A5.28 – Collection of evidence
- A5.29 – Information security during disruption
- A5.30 – ICT Readiness for Business Continuity
What does ISO 27001 – A5.24 require?
“The organisation shall plan and prepare for managing information security incidents by defining, establishing, and communicating information security incident management processes, roles and responsibilities.” (ISO 27001 – A5.24)
This control requires that you plan and prepare by:
- Defining required resources
- Establishing a process and assigning responsibilities
- Communicating this process across the organisation
Why is this required?
Security incidents are inevitable. These don’t always mean a hack — they can include:
- Sending personal data to the wrong recipient
- Losing a laptop or sensitive document
- System outages
If it affects confidentiality, integrity, or availability — it’s a security incident. This control ensures you’ve planned for such events in advance.
What the auditor is looking for
The auditor will expect you to have:
- A documented Incident Response Plan
- Business Continuity Processes
- A Post-Incident Review Process
They will also expect:
- Clearly defined roles and responsibilities (linked to A5.2)
- A completed Business Impact Analysis (BIA)
- Evidence that the plan has been tested or exercised
What do you need to do?
To meet this control, conduct a Business Impact Analysis (BIA). Use a simple spreadsheet to capture:
- Your most critical functions
- Key resources (human and technical)
- Maximum tolerable downtime for each function
- Assigned roles during incident scenarios
Test or exercise your plans annually. A test involves technical recovery, while an exercise involves decision-making and team response (e.g., role-playing scenarios).
Q & A
We already have a BC Plan — is that sufficient?
If your Business Continuity Plan includes:
- Defined resources
- Roles and responsibilities
- Communication strategy
- Testing records
…then yes, it can satisfy A5.24.
How detailed should the BIA be?
Start simple. Identify critical operations, required resources, and tolerable downtime. Avoid complex jargon unless you’re building a full ISO22301 BCP system. Consider terms like RTO (Recovery Time Objective) or RPO (Recovery Point Objective) later as your maturity grows.
How often should we test our plans?
We recommend:
- Annually: Run an exercise with key team members
- Annually: Test a technical recovery scenario
These exercises also support awareness training (see A6.3).
Difficulty Rating
2 out of 5 – Requires cross-departmental coordination and planning. The technical difficulty is low, but effort is needed to bring stakeholders together and create a usable plan.
More questions?
As with all ISO27001 controls, A5.24 does not stand alone. Review related controls for a full understanding of incident and continuity planning. If you’re unsure how to begin or want help mapping your process, just get in touch.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available now on Amazon.
