Back to all 93 controls
    Annex A 5.24
    Organizational

    A.5.24 Information security incident management planning and preparation

    You are prepared for incidents before they happen.

    What good looks like

    Incident response plan, defined roles, severities, escalation paths and runbooks.

    Evidence an auditor will ask for

    IRP, on-call rota, runbooks, tabletop exercise records.

    Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer

    Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.

    Certified Lead Implementer
    2022 Standard Aligned
    Audit-Ready Materials

    Document template for this control

    The Incident Management Policy template gives you auditor-ready wording that fulfils Annex A 5.24. Preview the full document before you download the editable version.