Home›Courses›Cognicert ISO/IEC 27035 Information Security Incident Manager Course
PROFESSIONAL COURSE · Courses, Continuity, Resilience and Recovery

Cognicert ISO/IEC 27035 Information Security Incident Manager Course

Training Overview: ISO/IEC 27035 Information Security Incident Management training equips professionals with the skills to manage and respond to security incidents effectively.

  • Practical, standards-based professional learning
  • Assessment and verifiable Cognicert certification
  • Flexible online, self-study and organisational delivery

Entry, exam and access at a glance

Prerequisites

Three years of professional experience, including two years at management level.

Exam and resits

100 questions in one hour. Pass mark: 70%. Your payment includes two exam attempts. A third or later attempt costs £100 per resit.

Cognicert reports an 87% pass rate.

Self-study access

Lifetime access for the enrolled learner. Access is personal and cannot be shared.

Overview
ISO/IEC 27035 Information Security Incident Management training is designed to equip professionals with the knowledge and skills necessary to effectively manage and respond to information security incidents within an organization. This training program covers incident management principles, processes, and best practices outlined in ISO/IEC 27035 to ensure that organizations can identify, assess, and mitigate security incidents while minimizing potential damage.
Audience
The target audience for ISO/IEC 27035 Information Security Incident Management training includes:
  1. Information Security Professionals: Security managers, officers, and analysts responsible for incident response and management.
  2. IT Managers and Administrators: IT personnel who play a role in responding to and mitigating security incidents.
  3. Compliance Officers: Professionals tasked with ensuring that the organization adheres to security standards and regulations.
  4. Business Continuity and Disaster Recovery Teams: Those responsible for maintaining business continuity in the event of security incidents.
  5. Risk Managers: Professionals focused on assessing and managing information security risks.
  6. Incident Responders: Individuals involved in the technical aspects of incident handling, such as forensics and incident analysis.
Standards
The primary reference standard for ISO/IEC 27035 Information Security Incident Management training is ISO/IEC 27035 itself, titled "Information technology — Security techniques — Information security incident management." This standard provides guidelines and best practices for establishing and operating an incident management process. Training Objectives:
  1. Comprehensive Understanding: Ensure participants have a deep understanding of ISO/IEC 27035 and its relevance to information security incident management.
  2. Incident Identification: Teach participants how to recognize and classify various types of information security incidents.
  3. Incident Response Planning: Enable participants to develop and implement incident response plans and procedures aligned with ISO/IEC 27035.
  4. Effective Incident Handling: Equip participants with the skills to respond promptly and effectively to security incidents, including containment, eradication, and recovery.
  5. Evidence Preservation: Provide knowledge on preserving digital evidence during incident response for potential legal and forensic purposes.
  6. Reporting and Communication: Teach participants how to communicate and report incidents internally and externally, as required.
  7. Continuous Improvement: Encourage participants to continuously improve their incident management processes through lessons learned and post-incident analysis.
Training Content: The training content should cover a range of topics to meet the specified objectives. Here's a breakdown of the content: Module 1: Introduction to ISO/IEC 27035
  • Overview of ISO/IEC 27035 and its importance
  • Role of incident management in information security
  • Relation to other ISO/IEC standards (e.g., ISO/IEC 27001)
Module 2: Incident Classification and Identification
  • Identifying and classifying information security incidents
  • Incident categorization and severity assessment
  • Early warning signs and indicators
Module 3: Incident Response Planning
  • Developing an incident response plan
  • Establishing an incident management team
  • Legal and regulatory considerations
Module 4: Incident Handling and Response
  • Incident handling phases (preparation, detection, containment, eradication, recovery, lessons learned)
  • Escalation procedures and decision-making during an incident
  • Coordinating response efforts
Module 5: Digital Evidence Preservation
  • Preserving digital evidence during incident response
  • Chain of custody and forensic considerations
  • Legal admissibility of evidence
Module 6: Incident Reporting and Communication
  • Internal and external incident reporting requirements
  • Communicating with stakeholders, including regulatory bodies and law enforcement
  • Managing public relations during incidents
Module 7: Post-Incident Analysis and Lessons Learned
  • Conducting post-incident analysis and root cause analysis
  • Lessons learned and continuous improvement
  • Updating incident response plans based on findings
Module 8: Case Studies and Best Practices
  • Real-world examples of effective incident management
  • Best practices from organizations with mature incident response programs
Module 9: Action Plan and Implementation
  • Developing an action plan for implementing ISO/IEC 27035 practices within participants' organizations
  • Steps to initiate and sustain effective incident management practices
Module 10: Q&A and Course Evaluation
  • Opportunity for participants to ask questions and seek clarification
  • Course evaluation and feedback collection
Delivery
  • Case Study
  • Individual Exercises
  • Role Play
  • Group Exercises
  • Group Presentation
  • Examination
Duration
5 Days Delivery Options:  Frequently Asked Questions: https://cognicert.com/faqs/   Enroll Now
BOOK WITH CLARITY

Refunds, cancellations and transfers

Refund and transfer choices depend on the course format, how much notice you give and whether digital content has been accessed. Contact learner care early and we will help you identify the best available option.

Read the complete refund, cancellation and transfer policy →
UPCOMING COURSE CALENDAR

Training, exam and application dates

Prices are per learner before any applicable UK VAT. A live-online intake costs more after its standard deadline because the published late fee is added. Self-study is priced separately and has no late-intake fee.

TRAINING DATESEXAMDEADLINE & STATUSLIVE ONLINESELF-STUDY
9–13 November 202613 November 2026Standard booking period
Standard deadline: 12 October 2026. No late fee yet.
Places are confirmed at booking, not guaranteed by this calendar.
£1,500
Choose this intake
£600
On-demand study; next exam shown at checkout.
VERIFIABLE ACHIEVEMENT

Check your Cognicert certificate

Successful candidates receive a uniquely numbered Cognicert certificate that another person can check through our public certificate-verification service. This confirms the authenticity of a Cognicert-issued award; acceptance by an employer, regulator or external professional scheme depends on their requirements.

View certificate verification →
YOUR COURSE ADVISER

Need help before enrolling?

Lisa Williams
Course and Business Development Adviser
Monday–Friday, 09:00–17:00 UK time

+44 20 3432 2505
info@cognicert.com
Self-study from £600Choose option & enrol

Related Cognicert resources

ISO 27031 ICT Disaster Recovery ManagerRead more →Cognicert Crisis Management Professional CourseRead more →Cognicert Emergency Response Manager CourseRead more →
Ready to enrol?

Choose online or self-study and continue securely to Stripe.