ISO - 27035 Lead Incident Manager



Only 3 Days



Classroom / Online / Hybrid

Next date

Next date:

3/5/2023 (Wednesday)


Accelerated ISO training, ISO course and ISO certification

Master a model for implementing an incident management process throughout your organisation - using the ISO/IEC 2735 standard - in just 3 days.

You’ll study practical exercises as you get the knowledge you need to manage information security incidents quickly. You’ll also learn:

  • Incident management standards and best practices
  • Effective security incident management using ISO/IEC 27035
  • Change management and incident analysis processes
  • How to establish an Information Security Incident Response Team

Get immersed in ISO/IEC 27035 in a distraction-free environment and learn faster with Firebrand’s Lecture | Lab | Review methodology.

You’ll sit the PECB Certified ISO/IEC 27035 Lead Incident Manager exam as part of your accelerated course. This exam is covered by your Certification Guarantee.

As of March 2023, PECB have partnered with Credly to offer you the chance of earning a digital badge upon completing your certification.

If you’re responsible for information and security or conformity in your organisation, this 3-day course is ideal for you. This course is also beneficial for:

  • Incident managers
  • Business Process Owners
  • Information Security Risk Managers
  • Regulatory Compliance Managers
  • Members of Incident Response Team
  • Persons responsible for information security or conformity within an organisation

This accelerated training is fully compatible with ISO/IEC 27035 which supports ISO 27001 by providing guidance for incident management.


Seven reasons why you should sit your course with Firebrand Training

  1. Two options of training. Choose between residential classroom-based, or online courses
  2. You'll be certified fast. With us, you’ll be trained in record time
  3. Our course is all-inclusive. A one-off fee covers all course materials, exams**, accommodation* and meals*. No hidden extras.
  4. Pass first time or train again for free. This is our guarantee. We’re confident you’ll pass your course first time. But if not, come back within a year and only pay for accommodation, exams and incidental costs
  5. You’ll learn more. A day with a traditional training provider generally runs from 9am – 5pm, with a nice long break for lunch. With Firebrand Training you’ll get at least 12 hours/day quality learning time, with your instructor
  6. You’ll learn faster. Chances are, you’ll have a different learning style to those around you. We combine visual, auditory and tactile styles to deliver the material in a way that ensures you will learn faster and more easily
  7. You’ll be studying with the best. We’ve been named in Training Industry’s “Top 20 IT Training Companies of the Year” every year since 2010. As well as winning many more awards, we’ve trained and certified over 100,000 professionals
  • * For residential training only. Doesn't apply for online courses
  • ** Some exceptions apply. Please refer to the Exam Track or speak with our experts


Introduction, incident management framework according to ISO/IEC 27035

  • Concepts and definitions related to information security and incident management
  • Incident management standards, and best practices
  • Choosing an incident management framework
  • Understanding an organisation and its context

Planning the implementation of an Organisational Incident Management Process based on ISO/IEC 27035

  • Incident management strategy and project management
  • Planning the implementation of an effective incident management process
  • Preliminary analysis and selection of an approach and methodology
  • Design and document an incident detection, reporting and management process
  • Defining roles and responsibilities in the context of the implementation and management of an Incident Management Process

Implementing an Incident Management Process

  • Define the document and record management processes
  • Incident Management policies & procedures
  • Implementation of security processes and controls related to incident management
  • Change management process
  • Incident analysis processes
  • Effective communication and the communication strategies
  • Establish the Information Security Incident Response Team

Monitoring, measuring and improving an Incident Management Process

  • Monitoring and evaluating the effectiveness of incident management process in operations
  • Development of metrics, performance indicators and dashboards
  • Management reviews
  • Implementation of a continual improvement program
  • Develop and propose the best corrective and preventive action plans

Exam Track

As part of your accelerated course, you'll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:

PECB Certified ISO/IEC 27035 Lead Incident Manager exam

  • Format: Open book
  • Duration: 3 hours
  • Passing score: 70%
  • Domains:
    • Domain 1: Fundamental principles and concepts of Information Security Incident Management
    • Domain 2: Information Security Incident Management best practices based on ISO/IEC 27035
    • Domain 3: Designing and developing an Organizational Incident Management process based on ISO/IEC 27035
    • Domain 4: Preparing for Information Security incidents and implementing an Incident Management Plan
    • Domain 5: Enacting the Incident Management Process and handling Information Security Incidents
    • Domain 6: Performance measurement and monitoring 
    • Domain 7: Improving the Incident Management processes and activities

What's Included

Your accelerated course includes:

  • Accommodation *
  • Meals, unlimited snacks, beverages, tea and coffee *
  • On-site exams **
  • Exam vouchers **
  • Practice tests **
  • Certification Guarantee ***
  • Courseware
  • Up-to 12 hours of instructor-led training each day
  • 24-hour lab access
  • Digital courseware **
  • * For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
  • ** Some exceptions apply. Please refer to the Exam Track or speak with our experts
  • *** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.


Before attending this accelerated course, you should have:

  • An understanding of ISO/IEC 27035
  • Comprehensive knowledge of Information Security

Unsure whether you meet the prerequisites? Don’t worry. Your training consultant will discuss your background with you to understand if this course is right for you.


Here's the Firebrand Training review section. Since 2001 we've trained exactly 134,561 students and asked them all to review our Accelerated Learning. Currently, 96.50% have said Firebrand exceeded their expectations.

Read reviews from recent accelerated courses below or visit Firebrand Stories for written and video interviews from our alumni.

"Always good facilities and staff."
Nicholas Daniels, Bridewell. (23/11/2022 (Wednesday) to 25/11/2022 (Friday))

"Always good facilities and staff."
Nicholas Daniels, Bridewell. (23/11/2022 (Wednesday) to 25/11/2022 (Friday))

"Very good layout, that allows you to concentrate on learning"
JO, HSBC. (10/8/2022 (Wednesday) to 12/8/2022 (Friday))

"Very good layout, that allows you to concentrate on learning"
JO, HSBC. (10/8/2022 (Wednesday) to 12/8/2022 (Friday))

"This is my first experience with Firebrand and I can only speak for this experience and educator. Based on the past 3 days, I would highly recommend firebrand for the quality of education I got."
Marcel Janssen. (17/3/2021 (Wednesday) to 19/3/2021 (Friday))

Course Dates

ISO - 27035 Lead Incident Manager - Incident Management




Book now

3/5/2023 (Wednesday)

5/5/2023 (Friday)


Book now

14/8/2023 (Monday)

16/8/2023 (Wednesday)


Book now

23/10/2023 (Monday)

25/10/2023 (Wednesday)


Book now

Latest Reviews from our students