Back to all 93 controls
    Annex A 5.25
    Organizational

    A.5.25 Assessment and decision on information security events

    Events are triaged into incidents consistently.

    What good looks like

    Criteria to assess whether an event is a security incident, with severity scoring.

    Evidence an auditor will ask for

    Triage criteria, sample tickets, severity matrix.

    Document template for this control

    The Incident Management Policy template gives you auditor-ready wording that fulfils Annex A 5.25. Preview the full document before you download the editable version.