Skip to main content
Cybersecurity ops

ISO 27035 Lead Incident Manager

ISO 27035 Lead Incident Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants seeking to expand their knowledge of information security incident management
  • Professionals responsible for establishing and leading incident response teams
  • IT professionals and information security risk managers aiming to strengthen their incident management capabilities
  • Current members of incident response teams who want formal grounding in ISO/IEC 27035
  • Incident response coordinators and others with direct responsibilities for incident handling and response

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no background in information security or incident management who would find the pace and depth of this course challenging
  • Those seeking only an awareness-level introduction to incident management, who should consider the ISO/IEC 27035 Foundation course instead
  • Professionals whose primary focus is application security or infrastructure security rather than incident management processes

What you'll be able to do

  • 1Explain the fundamental principles of information security incident management as defined in ISO/IEC 27035
  • 2Develop and implement an incident response plan tailored to an organisation's specific needs
  • 3Select and structure an effective incident response team appropriate to the organisational context
  • 4Conduct risk assessments to identify threats and vulnerabilities relevant to incident scenarios
  • 5Apply good practices drawn from international standards to improve incident response efficiency
  • 6Manage the detection, reporting, and response phases of information security incidents
  • 7Evaluate and improve incident management processes through post-incident analysis and lessons learned
  • 8Monitor incident management activities and drive continual improvement cycles

Day by day

Day 1Introduction to Information Security Incident Management Concepts and ISO/IEC 27035
  • Incident Management Principles and Terminology

    Participants examine the core vocabulary and theoretical foundations of information security incident management as established in ISO/IEC 27035.

  • Structure and Scope of ISO/IEC 27035

    The session reviews the architecture of the ISO/IEC 27035 standard series and its intended application across different organisational contexts.

  • Alignment with the ISO/IEC 27000 Family

    Participants explore how ISO/IEC 27035 interoperates with ISO/IEC 27001 and other related standards to form a coherent information security governance structure.

By end of day

  • Describe the purpose and structure of ISO/IEC 27035 in your own words
  • Identify where incident management sits within a broader information security management system
Day 2Designing and Preparing an Information Security Incident Management Plan
  • Scoping and Structuring the Incident Management Function

    This module guides participants through defining the scope, policies, and governance structure needed for a formally documented incident management plan.

  • Building and Organising an Incident Response Team

    Participants learn criteria for selecting team members, defining roles and responsibilities, and establishing escalation and communication protocols.

  • Risk Assessment in an Incident Management Context

    The session applies risk assessment methods to identify potential threat scenarios and prioritise preparedness activities accordingly.

By end of day

  • Draft the key components of an organisational incident management plan
  • Define role assignments and escalation paths within an incident response team structure
Day 3Detecting and Reporting Information Security Incidents
  • Incident Detection Mechanisms

    Participants study technical and procedural approaches for identifying information security events and determining which warrant escalation to incident status.

  • Incident Reporting and Classification

    This module covers the processes for documenting, classifying, and communicating incidents to the appropriate stakeholders in a timely manner.

  • Evidence Handling and Initial Response

    Participants examine best practices for preserving evidence and executing initial containment actions when an incident is confirmed.

By end of day

  • Apply classification criteria to categorise security events and incidents consistently
  • Outline a reporting workflow that ensures timely communication to relevant stakeholders
Day 4Monitoring and Continual Improvement of the Information Security Incident Management Process
  • Monitoring Incident Management Performance

    Participants identify key performance indicators and review techniques for assessing whether the incident management process meets defined objectives.

  • Post-Incident Analysis and Lessons Learned

    The module introduces structured approaches to conducting post-incident reviews and translating findings into actionable process improvements.

  • Embedding Continual Improvement

    Participants practise incorporating improvement actions into the incident management lifecycle to sustain and enhance organisational resilience over time.

By end of day

  • Select appropriate metrics to monitor incident management effectiveness
  • Conduct a structured post-incident review and document improvement recommendations
Day 5Competency Consolidation and Exam Preparation
  • Review of PECB Exam Competency Domains

    Facilitators guide participants through all six competency domains assessed in the PECB ISO/IEC 27035 Lead Incident Manager examination to consolidate learning.

  • Scenario-Based Practice

    Participants work through realistic incident management scenarios to apply course knowledge and identify remaining areas for self-study.

By end of day

  • Map personal knowledge against the six exam competency domains
  • Apply integrated incident management reasoning to complex organisational scenarios

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of information security incident management
  • Domain 2: Information security incident management process based on ISO/IEC 27035
  • Domain 3: Designing and developing an organizational incident management process based on ISO/IEC 27035
  • Domain 4: Preparing and executing the incident response plan for information security incidents
  • Domain 5: Implementing incident management processes and managing information security incidents
  • Domain 6: Improving the incident management processes and activities
  1. Defining an incident management approach
  2. Determining the incident management objectives and scope
  3. Performing risk assessment
  4. Developing an incident management program
  5. Defining risk evaluation and risk acceptance criteria
  6. Evaluating risk treatment options
  7. Monitoring and reviewing the incident management program

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational Approach

  • This training course combines theoretical concepts with best practices for implementing an information security incident management process.
  • The training course contains essay-type exercises and multiple-choice quizzes, some of which are scenario-based.
  • The participants are encouraged to collaborate and engage in meaningful discussions with fellow learners while tackling quizzes and exercises.
  • The quiz format closely mirrors that of the certification exam, ensuring participants are well-prepared for their exam.

Buyers always ask

What distinguishes training completion from passing the exam and earning a certification?+

Completing the five-day training programme means you have attended the course and may receive an attestation of participation. Passing the PECB ISO/IEC 27035 Lead Incident Manager exam is a separate achievement that demonstrates competency across the defined domains.

Earning a PECB certification credential requires passing the exam and satisfying any additional requirements, such as professional experience criteria, as set out in PECB's Certification Rules and Policies. Cyber Academy provides the training; examination and certification are administered by PECB.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Which competency domains are assessed in the PECB ISO/IEC 27035 Lead Incident Manager exam?+

According to PECB, the exam covers: fundamental principles and concepts of information security incident management, the incident management process based on ISO/IEC 27035, designing and developing an organisational incident management process, preparing and executing an incident response plan, implementing incident management processes and managing incidents, and improving incident management processes and activities.

For details on exam format, duration, and available languages, refer to the List of PECB Exams and the Examination Rules and Policies on the PECB website.

How does this course differ from the ISO/IEC 27035 Foundation course?+

The Foundation course provides an overview of incident management principles and the ISO/IEC 27035 framework, suitable for those building awareness or starting their learning journey. The Lead Incident Manager course goes significantly further, addressing how to design, implement, lead, and continuously improve a complete incident management function.

Participants in the Lead course are expected to arrive with existing knowledge of incident management processes and the ISO/IEC 27000 family, whereas the Foundation course requires no such prior background.

What types of organisations benefit most from having staff trained at this level?+

Organisations that handle sensitive data, operate critical infrastructure, or face regulatory requirements related to breach notification typically gain the most from having trained Lead Incident Managers. The course prepares practitioners to build proportionate, repeatable, and auditable incident management capabilities rather than relying on ad hoc responses.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.