Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
ISO/IEC 27035: Information Security Incident Management
Rating: 4.6 out of 5(857 ratings)
2,574 students

ISO/IEC 27035: Information Security Incident Management

Master the 5-phase incident response process of ISO/IEC 27035: plan, detect, assess, respond and learn from incidents
Last updated 7/2026
English
Arabic [Auto],English

What you'll learn

  • The process for managing information security incidents
  • Best practices recommended by standards for handling incidents
  • How to plan and prepare for managing incidents
  • How to detect and assess information security events
  • How to analyze and classify information security incidents
  • What involves the response to information security incidents
  • What standards are available for information security management

Course content

7 sections35 lectures3h 25m total length
  • Introduction4:02

    About the subject and the structure of the course

  • Information security management4:51

    About the concept of information security and what is information security management

  • The ISO/IEC 27000 series of standards5:08

    About the most popular standards in the ISO/IEC 27000 series and what they refer to

  • About ISO/IEC 270356:30

    About the purpose of ISO/IEC 27035 and the different documents that make up the ISO/IEC 27035 standard. What is the subject for each of those documents and how they are intended to be used

Requirements

  • Familiarity with the ISO standards on information security management is helpful, but not mandatory

Description

Every organization, regardless of size or industry, can become the target of a cyber attack — and security controls alone cannot guarantee total protection. Residual vulnerabilities will always exist, new threats emerge constantly, and information security incidents are a matter of when, not if. What separates a minor disruption from a business-ending crisis is how well the organization prepares for and responds to incidents.

This course teaches information security incident management according to ISO/IEC 27035, the international standard for incident management. You will learn the complete process for planning, detecting, assessing, responding to and learning from security incidents — the foundation of any incident response capability, and a natural complement to an ISO/IEC 27001 information security management system.

The five phases of incident management under ISO/IEC 27035

A section of the course is dedicated to each phase, with examples and case studies throughout:

  • Plan and prepare — developing incident management plans and policies, training and awareness, identifying resources, establishing forms and templates, and setting up organizational structures such as the incident management team and the incident response team (IRT/CSIRT)

  • Detect and report — identifying and reporting information security events, and the monitoring and detection capabilities that make this possible

  • Assess and decide — triaging events, categorizing incidents by their impact on the organization, and deciding on the appropriate response

  • Respond — containing the incident, eradicating the cause, and recovering affected systems and services

  • Learn lessons — using the information collected during incident handling to improve security controls, the incident management process and the wider organization

What you will gain

  • A complete understanding of the concepts, roles and tools of information security incident management

  • The ability to categorize and analyse security incidents and select appropriate responses

  • Practical knowledge for designing or improving your organization's incident response process — including plans, policies and team structures

  • A foundation for incident manager or incident responder certification paths, and for consulting or auditing engagements covering incident management

Who this course is for

  • IT and information security professionals building or joining an incident response team

  • SOC analysts and incident responders who want the management-system view of incident handling

  • CISOs, security managers and IT managers responsible for incident preparedness

  • ISO/IEC 27001 implementers and auditors — incident management is a required control area of every ISMS

  • Consultants supporting clients with incident management processes

Use this course to design or improve your company's incident management process, to support your consulting or audit work, or to advance your career in information security.

Who this course is for:

  • Information security incident managers
  • Information security managers
  • Information security auditors
  • Members of incident response teams (IRTs)
  • IT managers
  • ISO consultants and auditors
  • Information security risk managers
  • IT system administrators
  • Individuals interested in information security management