Certified Information Security Manager (CISM)Incident ManagementMedium

A financial institution is updating its incident response plan. The CISO wants to ensure that the plan effectively addresses emerging threats while remaining agile. Which of the following approaches BEST supports continuous improvement and adaptation of the incident response plan?

  1. AIntegrating lessons learned from post-incident reviews into plan updates.
  2. BBenchmarking the plan against industry best practices every five years.
  3. CConducting annual, full-scale simulation exercises with external auditors.
  4. DImplementing a strict change control process that limits plan modifications.
Show answer & explanation

Correct answer: A. Integrating lessons learned from post-incident reviews into plan updates.

Integrating lessons learned from post-incident reviews is the most direct and effective way to ensure continuous improvement and adaptation of the incident response plan, as it directly incorporates real-world experiences and identified deficiencies.

Why the other options are wrong

  • B. Benchmarking every five years is too infrequent to support continuous improvement and agile adaptation to emerging threats.
  • C. While valuable, annual exercises are periodic and may not capture continuous, agile adaptation.
  • D. Strict change control can hinder agility and adaptation by making necessary updates difficult or slow.

Lessons Learned Process

A systematic process of identifying, documenting, and disseminating knowledge gained from incident response activities to improve future performance.

  • Occurs during post-incident review.
  • Identifies what went well, what went wrong, and what could be improved.
  • Drives updates to policies, procedures, and training.

Memory trick: Learn from the past to secure the future.

More Incident Management questions