Certified Information Security Manager (CISM)Information Security Risk ManagementEasy

A global e-commerce company recently experienced a significant data breach. Following the incident containment and eradication, the CISO initiates a 'lessons learned' review. What is the PRIMARY objective of this post-incident activity?

  1. ATo publicly disclose all technical details of the breach to demonstrate transparency.
  2. BTo assign blame and penalize individuals responsible for the breach.
  3. CTo update cyber insurance policies based on the financial impact of the breach.
  4. DTo identify root causes, improve incident response procedures, and enhance security controls.
Show answer & explanation

Correct answer: D. To identify root causes, improve incident response procedures, and enhance security controls.

The primary objective of a 'lessons learned' review is to analyze the incident thoroughly to understand its root causes, identify what went well and what didn't, and use this information to improve future incident response capabilities and overall security posture.

Why the other options are wrong

  • A. Public disclosure is a legal/PR requirement, not the primary internal objective of learning and improving from the incident.
  • B. Blame assignment is counterproductive to learning and improvement; the focus should be on process and system enhancement.
  • C. While insurance policies might be reviewed, this is a financial consequence, not the primary objective of a 'lessons learned' review.

Post-Incident Review (Lessons Learned)

A critical phase in the incident response lifecycle where the entire incident is analyzed to identify areas for improvement in processes, controls, and strategies.

  • Focuses on continuous improvement, not blame.
  • Identifies root causes and control deficiencies.
  • Enhances future incident response and security posture.

Memory trick: Lessons Learned: Reflect, Improve, Prevent Repeat.

More Information Security Risk Management questions