isms.coach
← All controls

A.5.25 · Organizational

Assessment and decision on information security events

Why it matters

Not every alert is an incident — you need a clear, fast way to decide what actually warrants response.

How a self-led small team implements it

A simple severity triage (e.g. low/medium/high with example criteria) is sufficient at small scale.

What auditors expect to see

Event triage criteria, example logged decisions.

Track A.5.25 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls