ISO 27001A.5 — Assessment and decision on information security events
A.5.25
Assessment and decision on information security events
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Assess information security events and decide whether they should be categorized as incidents.
Points of focus
- Event vs incident criteria defined
- Triage roles and SLAs
- Decision records retained
- Escalation to IR when criteria met
Implementation notes
Publish clear criteria separating noisy alerts, security events, and incidents. Train on-call to capture who decided and why. Automate enrichment (user, IP, asset) but keep human disposition for ambiguous cases. Hand off to A.5.26 when incident criteria hit. Align clocks with privacy breach assessment when personal data may be involved.
Audit tip: Provide three alert tickets: one false positive, one event, one promoted incident — with decision notes.
Evidence auditors typically request:
- Severity / triage matrix
- On-call runbook for security alerts
- Sample tickets showing event disposition
- Metrics of time-to-triage
Common gaps
- Everything paged as SEV1
- Alerts closed with 'looks fine' and no notes
- No link from detection (A.8.16) to IR
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.25 | This control |
| SOC 2 | CC7.3 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
| GDPR | Article 33 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.25)
Frequently Asked Questions
Name on-call security/engineering roles with escalation to IR lead for borderline or high-impact cases.
No. Tickets with a triage matrix beat an unused SOAR playbook.
Maps to CC7.3-style evaluation of security events — reuse the same triage evidence.