ISO/IEC 27001:2022 Annex A · Control 5.26
Response to Information Security Incidents: A Practical Implementation Guide
Contain harm, restore trusted operations and coordinate decisions through a disciplined response process.
This control addresses responding to information security incidents according to established procedures.
What should the control achieve?
- Incidents have accountable command and objectives.
- Containment and eradication actions are authorized.
- Evidence and decisions are preserved.
- Recovery is verified before closure.
Step-by-step implementation
Activate command
Confirm severity, Incident Manager, objectives and communication channel.
Analyze scope
Build timeline, affected assets, identities, data and business impact.
Contain safely
Select immediate and longer-term measures with owners and rollback plans.
Eradicate causes
Remove persistence, vulnerabilities, compromised credentials and unsafe configurations.
Recover and monitor
Restore from trusted state, validate controls and watch for recurrence.
Communicate and close
Meet stakeholder duties, document decisions and approve closure.
What this could look like in practice
During ransomware, the Incident Manager isolates affected segments, preserves forensic images, invokes continuity plans and coordinates Legal, Communications and external responders. Systems return only after clean rebuild and validation.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Command | Named manager sets priorities and records decisions. | Incident log |
| Containment | Technical actions are approved and timestamped. | Action timeline |
| Recovery | Business and technical owners verify trusted operation. | Recovery acceptance |
| Communication | Notifications use approved facts and channels. | Communication record |
Implementation evidence
- Incident records
- Decision timeline
- Containment approvals
- Forensic evidence
- Communication logs
- Recovery validation
- Risk acceptance
- Closure approval
Useful metrics
- Time to contain
- Time to recover critical service
- Repeated containment failures
- Incidents with complete timelines
Common mistakes
- Allowing multiple uncoordinated commanders.
- Rebuilding before preserving evidence.
- Communicating speculation.
- Restoring without removing root cause.
- Closing when service returns but actions remain.
Questions an auditor may ask
- Who commanded the last incident?
- How were containment decisions authorized?
- Show evidence of trusted recovery.
- How were stakeholders informed?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.