Skip to content
arrow_back
search
Annex A 5.25 verified ISO/IEC 27001:2022

Assessment and decision on information security events

Evaluate security events to determine which are serious enough to be called incidents.

record_voice_over

Plain language

This control is about figuring out if a security problem is just a minor hiccup or a real incident that needs immediate attention. If it's not done, small issues might be ignored until they grow into big, costly problems like data breaches.

Framework

ISO/IEC 27001:2022

Control effect

Detective

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The organization shall assess information security events and decide if they are to be categorized as information security incidents.
verified ISO/IEC 27001:2022 Annex A 5.25
priority_high

Why it matters

If security events are not assessed and categorised promptly, true incidents may be missed, delaying containment and increasing business impact.

settings

Operational notes

Define event triage criteria and decision thresholds for incident categorisation; train responders and review samples to ensure consistent classification.

Mapping detail

Mapping

Direction

Controls