Certified Information Security Manager (CISM)Incident ManagementMedium

A financial institution is updating its incident response plan. The CISO wants to ensure that the organization continuously learns from past incidents and improves its incident response capabilities over time. Which of the following processes should the CISO emphasize to achieve this objective?

  1. AEstablishing a formal 'lessons learned' process after every major incident.
  2. BIncreasing the budget for external incident response consultants.
  3. CImplementing automated incident detection and response tools.
  4. DConducting regular tabletop exercises with senior management.
Show answer & explanation

Correct answer: A. Establishing a formal 'lessons learned' process after every major incident.

A formal 'lessons learned' process specifically focuses on reviewing past incidents to identify what went well, what could be improved, and how to update plans and procedures, directly supporting continuous learning and improvement.

Why the other options are wrong

  • B. External consultants can provide expertise, but relying on them doesn't inherently build an internal continuous learning capability for the organization.
  • C. Automated tools improve efficiency and speed but do not inherently facilitate learning from past incidents or improving the *process* itself.
  • D. Tabletop exercises test the plan and train personnel but are not primarily designed for retrospective analysis and continuous improvement based on *actual* incidents.

Lessons Learned Process

A structured review conducted after an incident or exercise to identify strengths, weaknesses, opportunities for improvement, and to update plans, policies, and procedures accordingly.

  • Crucial for continuous improvement of incident response.
  • Involves detailed analysis of incident handling.
  • Leads to actionable recommendations for change.

Memory trick: Learn from the past to make the future IR better, always have 'lessons learned'.

More Incident Management questions