Skip to main content
Cybersecurity ops

ISO 27035 Foundation

ISO 27035 Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Individuals interested in understanding how information security incident management processes work
  • People seeking foundational knowledge of the main principles covered by ISO/IEC 27035
  • Those considering a career path in information security incident management
  • IT and security team members who participate in or support incident handling activities

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced incident managers seeking advanced implementation or leadership techniques, who would be better served by the Lead Incident Manager course
  • Professionals requiring deep technical forensics or malware analysis skills rather than a process-level overview
  • Those who already hold a solid working knowledge of ISO/IEC 27035 and want only practical implementation guidance

What you'll be able to do

  • 1Describe the basic concepts and terminology underpinning information security incident management
  • 2Recognise how ISO/IEC 27035 relates to other information security standards and regulatory frameworks
  • 3Explain the process approaches used to manage information security incidents effectively
  • 4Distinguish between the phases of an information security incident management lifecycle
  • 5Identify the roles and responsibilities involved in incident management processes

Day by day

Day 1Fundamental Principles and Concepts of Information Security Incident Management
  • Introduction to ISO/IEC 27035

    Participants are introduced to the scope, structure, and purpose of ISO/IEC 27035 and its role within the broader information security standards ecosystem.

  • Core Concepts of Incident Management

    This module defines key terminology and foundational concepts such as events, incidents, and the incident management lifecycle as described in ISO/IEC 27035.

  • Relationship with Other Standards and Frameworks

    The session explores how ISO/IEC 27035 aligns with and complements other information security standards and applicable regulatory requirements.

By end of day

  • Explain what constitutes an information security incident and why structured management matters
  • Map ISO/IEC 27035 concepts to familiar security frameworks encountered in your organisation
Day 2Information Security Incident Management Process Approaches and Exam Preparation
  • Process Approaches for Managing Incidents

    Participants examine the structured process approaches defined in ISO/IEC 27035 for planning, detecting, assessing, responding to, and learning from information security incidents.

  • Practical Application and Case Discussion

    Scenarios and examples are used to consolidate understanding of how the ISO/IEC 27035 processes apply in real organisational contexts.

  • Exam Competency Review

    Facilitators review the two competency domains assessed in the PECB ISO/IEC 27035 Foundation exam to help participants gauge their readiness.

By end of day

  • Apply the ISO/IEC 27035 process model to a sample incident scenario
  • Identify which competency domain each topic belongs to for examination purposes

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of Information Security Incident Management
  • Domain 2: Information Security Incident Management

The certificate requirements for the ISO/IEC 27035 Foundation are:

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational approach

  • Lecture sessions are illustrated with practical questions and examples
  • Practical exercises include examples and discussions
  • Practice tests are similar to the Certificate Exam

Prerequisites

What is the PECB ISO/IEC 27035 Foundation course?

The PECB ISO/IEC 27035 Foundation course is an introductory training program designed to provide participants with a solid understanding of the fundamental concepts and principles of information security incident management. Based on the ISO/IEC 27035 standard, this course focuses on the processes and best practices for effectively managing information security incidents. Participants will learn how to establish an incident management plan, identify and assess incidents, and implement appropriate responses to mitigate risks and minimize impact on the organization.

Who should attend the ISO/IEC 27035 Foundation course?

This course is ideal for individuals who are new to information security incident management or those seeking to enhance their knowledge in this area. It is particularly beneficial for IT professionals, security officers, risk managers, and consultants who are involved in the development, implementation, or management of an incident management process within their organization. Additionally, individuals aspiring to pursue a career in information security incident management will find this course valuable.

What will I learn in the ISO/IEC 27035 Foundation course?

Participants will gain insights into the key concepts and principles of information security incident management, including the identification, assessment, and response to security incidents. The course covers the structure and components of an effective incident management plan, the roles and responsibilities of an incident response team, and the correlation between ISO/IEC 27035 and other standards and regulatory frameworks. Through practical examples and discussions, participants will learn how to apply process approaches to manage information security incidents effectively.

How long is the ISO/IEC 27035 Foundation course?

The ISO/IEC 27035 Foundation course is a two-day training program. The first day introduces participants to the fundamental principles and concepts of information security incident management, while the second day focuses on the process approaches used to manage incidents effectively. The course concludes with a certification exam.

Is there a certification exam included in the course?

Yes, the course includes a certification exam that assesses participants' understanding of the fundamental concepts and principles of information security incident management. Upon successful completion of the exam, participants will receive the "PECB Certified ISO/IEC 27035 Foundation" credential, demonstrating their knowledge and competence in this area.

Buyers always ask

What is the difference between completing the training, passing the exam, and earning a certificate?+

Attending and completing the two-day training results in an attestation of course completion. Passing the PECB examination is a separate step that assesses your knowledge against defined competency domains.

Earning the ISO/IEC 27035 Foundation certificate requires satisfying the credential requirements set out in PECB's Certification Rules and Policies, which go beyond simply attending the training. Cyber Academy delivers the training programme; the examination and certification are managed by PECB.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Which competency domains does the ISO/IEC 27035 Foundation exam cover?+

According to PECB, the exam covers two domains: fundamental principles and concepts of information security incident management, and information security incident management processes. For details on exam format and available languages, consult the List of PECB Exams on the PECB website.

Is this course suitable for someone with no prior experience in incident management?+

The course is designed as an entry point into the subject. While basic familiarity with security incident concepts is preferred, the programme starts with foundational terminology and principles, making it accessible to motivated learners who are new to the field.

However, individuals who already work in incident management roles and are looking for advanced implementation or leadership skills would gain more value from the ISO/IEC 27035 Lead Incident Manager course.

How does ISO/IEC 27035 Foundation relate to more advanced ISO/IEC 27035 qualifications?+

The Foundation course provides conceptual grounding in incident management principles and the ISO/IEC 27035 framework. It is a natural precursor for those who later wish to pursue the Lead Incident Manager programme, which focuses on designing, implementing, and leading full incident management functions within an organisation.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.