You are on page 1of 1

ISO/IEC WD 27035-1.

Crisis handling
User/ Point of contact Internal ISIRT function,
Source (24h x 7d) (on call) including External
ISIRTs

Information Detection and Reporting


Alarm Report of
security
of information
event
abnormality security
or anomaly incident

Detection

Reporting

Contact NO
point
exists?

YES

Assessment and Decision

Information Information
Collection Collection

Assessment Assessment

YES
Possible
information
security
incident?

Confirmed
NO NO information
security
incident?

YES

Response
Immediate
Response

Incident categolization and


severity classification

Incident under NO
control?

YES
Response to
Later Response
Crisis situation

Digital evidence
Collection

Communication

Reduction
of
false alarm
Review

Improve

Figure 3 Information security event and incident flow diagram

NOTE False alarm is an indication of a reported event that is found not to be real or of any consequence.

16 © ISO/IEC 2013 All rights reserved

You might also like