CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A security analyst is preparing an incident report for an unauthorized access event. The report needs to include a 'lessons learned' section to prevent similar incidents in the future. Which of the following elements is MOST crucial to thoroughly document in this section?
- AThe total financial cost incurred due to the unauthorized access.
- BSpecific recommendations for improving security controls and processes.
- CA detailed timeline of all system changes made by the unauthorized actor.
- DNames and contact information of all personnel involved in the incident response.
Show answer & explanationAnswer & explanation
Correct answer: B. Specific recommendations for improving security controls and processes.
The 'lessons learned' section of an incident report is designed to drive improvement. Specific recommendations for security control and process enhancements directly address this goal by outlining actionable steps to prevent recurrence.
Why the other options are wrong
- A. This is part of the business impact assessment, not the 'lessons learned' for prevention.
- C. While important for the incident analysis, this is part of 'what happened,' not 'what we learned to improve.'
- D. This is for internal coordination and audit trails, not for identifying preventive measures.
Lessons Learned Report Purpose
A section or standalone report following an incident to identify contributing factors, evaluate response effectiveness, and recommend improvements.
- Aims to prevent recurrence of similar incidents.
- Focuses on actionable recommendations.
- Part of continuous security improvement.
Memory trick: Lessons Learned mean 'What's NEXT to make it BETTER?'