ISO 27001A.5 — Information security incident management planning and preparation
A.5.24
Information security incident management planning and preparation
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Plan and prepare information security incident management so the organization can respond effectively.
Points of focus
- Define scope and requirements for information security incident management planning and preparation
- Assign ownership and operating cadence
- Integrate with risk treatment and SoA status
- Retain dated records proving operation
Implementation notes
Maintain an IR plan with roles, severity definitions, comms paths, and tabletop cadence. Align with GDPR Art. 33 clocks when personal data is involved. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.
Audit tip: Present the SoA line for A.5.24, the current procedure, and one recent dated operating sample with a named owner.
Evidence auditors typically request:
- Approved information security policy set with version and owner
- Statement of Applicability entry with applicability rationale
- Management review minutes referencing the control theme
- Ticket or register samples showing the process operated
Common gaps
- SoA marks information security incident management planning and preparation applicable without dated operating samples
- Procedure exists but interviews describe a different tribal process
- Owner unclear or last review older than the stated cadence
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.24 | This control |
| SOC 2 | CC7.3, CC7.4 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
| GDPR | Article 33 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
| HIPAA | 164.308(a)(6) | Related HIPAA Security Rule citations when PHI is in scope — SoA does not replace BAAs. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.24)
Frequently Asked Questions
Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.
Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.
Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.