ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsMedium
After a successful recovery from a major cybersecurity incident, an organization's incident response team holds a meeting to review what happened, what was done well, what could be improved, and to update documentation. Which phase of the incident response process is this activity part of?
- AEradication
- BPreparation
- CRecovery
- DPost-Incident Activity
Show answer & explanationAnswer & explanation
Correct answer: D. Post-Incident Activity
Post-Incident Activity (also known as Lessons Learned) involves reviewing the incident, documenting findings, identifying areas for improvement, and updating plans and procedures to prevent similar incidents or improve future responses.
Why the other options are wrong
- A. Eradication involves removing the cause of the incident, not reviewing the process.
- B. Preparation involves setting up policies and tools before an incident occurs.
- C. Recovery involves restoring systems to normal operations, which occurs before the review.
Incident Response: Post-Incident Activity
The final phase of incident response, focused on learning from the incident, documenting findings, and improving policies, procedures, and tools for future incidents.
- Also known as 'Lessons Learned'
- Includes documentation and reporting
- Aims for continuous improvement of IR capabilities
Memory trick: P D C E R P: Prepare, Detect, Contain, Eradicate, Recover, Post-Incident.