ISO 27001:2022 Annex A Control 5.24: Information Security Incident Management Planning and Preparation
Annex A control 5.24 of the 2022 version of the ISO 27001 standard can be mapped to ISO 27001:2013 Annex A 16.1.1

Control 5.24 describes how information security incidents, events and weaknesses should be managed, highlighting the importance of preparation and planning. It outlines the need for efficient processes, describing how staff should respond to incidents based on their roles.
Constructive communication and professionalism are key to an effective incident response. Annex A 5.24 acts as a corrective control that maintains risk by setting out a common list of Incident Management procedures to mitigate any damage caused by information security events.
{{snapshot}}
Control 5.24 in brief
- Corrective control that maintains risk by setting a common list of incident management procedures
- Covers information security incidents, events and weaknesses, stressing preparation and planning
- Staff respond according to their roles, with communication and professionalism central to an effective response
- Replaces ISO 27001:2013 Annex A 16.1.1 with a more comprehensive breakdown of roles, management and reporting
{{/snapshot}}
Roles and responsibilities
Staff are expected to work together to resolve incidents, and Annex 5.24 offers five core guidance points to help teams do just that. In order to create an efficient and cohesive incident management operation, organisations should:
- Establish and document a clear method for reporting information security events, outlining a main point of contact for all such events.
- Create a series of IM processes to manage information security incidents, focusing on administration, documentation, detection, triage, prioritisation, analysis and communication.
- Develop an incident response procedure that allows the organisation to respond to incidents effectively. This should encourage learning from incidents once they have been resolved to mitigate recurrence.
- Limit responsibility to trained and competent personnel. They should have full access to procedural documentation and undertake refresher training regularly.
- Identify the training needs of all staff involved in incident response. This should include any vendor-specific or professional certifications.
{{snapshot}}
Five foundations for incident response
- Document a clear reporting method with a single point of contact for all security events
- Define IM processes for administration, documentation, detection, triage, prioritisation, analysis and communication
- Build an incident response procedure that captures lessons learned to prevent recurrence
- Limit responsibility to trained, competent staff with full access to procedures and regular refresher training
- Identify training needs, including vendor-specific or professional certifications
{{/snapshot}}
Incident management
The key objective of any incident management process within an organisation is to ensure that those responsible for resolving information security incidents have all the information and training they need to navigate the event. Staff should have a firm understanding of three main areas, which are the time it takes to resolve an incident, the severity of the incident and any potential consequences.
Processes should work harmoniously to ensure that these priorities are met. Control 5.24 highlights 8 activities that should be addressed when trying to resolve incidents. These are:
- IS events should be assessed in accordance with strict criteria to validate their severity.
- IS events should be managed in line with 5 key criteria: monitoring, detection, classification, analysis and reporting.
- Organisations should implement procedures to ensure IS incidents are concluded successfully. These procedures are:
a. Response and escalation
b. Activation of business continuity plans
c. Managed recovery that mitigates operational and financial damage
d. Internal and external parties receive thorough communication of incident-related events - Working collaboratively with internal and external personnel.
- Logging all incident activities in a thorough, accessible and transparent way.
- Evidence should be handled responsibly in line with external and internal guidelines and regulations.
- Once the incident has been resolved, a thorough review procedure and root cause analysis should take place.
- Recording required improvements to prevent an incident from occurring.
{{snapshot}}
Resolving an incident
- Assess and validate severity against strict criteria before acting
- Manage events through monitoring, detection, classification, analysis and reporting
- Follow set procedures: response and escalation, business continuity activation, managed recovery and clear communication
- Log every activity in a transparent, accessible record and handle evidence responsibly
- After resolution, run a review and root cause analysis and record improvements
{{/snapshot}}
Reporting
An essential element of incident management is reporting. This ensures that information is accurately disseminated throughout an organisation. Reporting should focus on 4 main areas:
| Reporting focus | What it covers |
|---|---|
| Response actions | What must be done once an information security event occurs |
| Incident forms | Clear, concise recording of information to support personnel in their duties |
| Feedback processes | Ensuring personnel are made aware of IS event outcomes once resolved |
| Incident reports | Documenting all relevant information on an incident |
{{snapshot}}
What Hicomply recommends
Incident response only works if the plan is live before the incident is. We recommend rehearsing your escalation path and evidence handling now, so the eight activities in Control 5.24 become muscle memory rather than a document you dust off under pressure.
Wiring incident logging into your ISO 27001 ISMS keeps the audit trail complete without extra admin, and our free compliance tools are a practical place to start.
{{/snapshot}}
How has it changed since ISO 27001:2013?
Replacing ISO 27001:2013 Annex A control 16.1.1, the new control 5.24 acknowledges that organisations must undergo stringent preparations to be resilient and compliant against incidents.
The newer control includes a comprehensive breakdown of the steps organisations should take to delegate roles, manage incidents, and report outcomes.
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.




