Certified Information Security Manager (CISM)Incident ManagementMedium
A retail company experiences a data breach involving customer credit card information. The incident response team has identified the root cause and implemented corrective actions. Before declaring the incident closed, what critical step should the CISO ensure is completed to prevent recurrence and improve future response?
- AUpdate the incident response plan based on lessons learned.
- BVerify that all compromised accounts have been reset.
- CPublicly announce the breach and notify affected customers.
- DConduct a comprehensive forensic analysis of all affected systems.
Show answer & explanationAnswer & explanation
Correct answer: A. Update the incident response plan based on lessons learned.
After an incident is contained, eradicated, and recovered from, a crucial 'post-incident activity' is to conduct a lessons learned review. This review identifies areas for improvement in the incident response plan, processes, and security controls, directly aiming to prevent recurrence and enhance future responses.
Why the other options are wrong
- B. Verifying account resets is part of eradication and recovery, ensuring the immediate threat is mitigated, but not the final improvement step.
- C. Public announcement and customer notification are part of the incident communication plan, often carried out during or immediately after containment, but not the final step for internal improvement.
- D. Forensic analysis is typically performed during identification and containment to understand the incident, not as the last step before closing.
Post-Incident Review
A formal process after an incident to analyze what happened, how it was handled, and what can be improved.
- Identifies lessons learned.
- Leads to updates in incident response plans and policies.
- Aims for continuous improvement in security posture.
Memory trick: Learn from the past to secure the future.