Skip to content
compliancebase
ISO 27001A.5 — Assessment and decision on information security events

A.5.25

Assessment and decision on information security events

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Assess information security events and decide whether they should be categorized as incidents.

Points of focus

  • Event vs incident criteria defined
  • Triage roles and SLAs
  • Decision records retained
  • Escalation to IR when criteria met

Implementation notes

Publish clear criteria separating noisy alerts, security events, and incidents. Train on-call to capture who decided and why. Automate enrichment (user, IP, asset) but keep human disposition for ambiguous cases. Hand off to A.5.26 when incident criteria hit. Align clocks with privacy breach assessment when personal data may be involved.

Audit tip: Provide three alert tickets: one false positive, one event, one promoted incident — with decision notes.

Evidence auditors typically request:

  • Severity / triage matrix
  • On-call runbook for security alerts
  • Sample tickets showing event disposition
  • Metrics of time-to-triage

Common gaps

  • Everything paged as SEV1
  • Alerts closed with 'looks fine' and no notes
  • No link from detection (A.8.16) to IR

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.25This control
SOC 2CC7.3Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.
GDPRArticle 33Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

Name on-call security/engineering roles with escalation to IR lead for borderline or high-impact cases.

No. Tickets with a triage matrix beat an unused SOAR playbook.

Maps to CC7.3-style evaluation of security events — reuse the same triage evidence.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above