CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
A security auditor is reviewing an organization's incident response plan. The auditor notes that while the plan includes detailed steps for containment and eradication, it lacks clear guidelines for post-incident activities aimed at preventing recurrence. Which phase of the incident response lifecycle is inadequately addressed?
- APost-Incident Activity (Lessons Learned)
- BRecovery
- CPreparation
- DDetection and Analysis
Show answer & explanationAnswer & explanation
Correct answer: A. Post-Incident Activity (Lessons Learned)
Post-incident activity, often referred to as 'Lessons Learned,' is the phase where an organization reviews the incident, identifies root causes, and implements measures to prevent similar incidents from recurring. This directly addresses the missing guidelines for preventing recurrence.
Why the other options are wrong
- B. Recovery focuses on restoring systems and data to normal operations after an incident.
- C. Preparation involves proactive measures before an incident, not post-incident prevention.
- D. Detection and Analysis focuses on identifying and understanding an ongoing incident.
Post-Incident Activity (Lessons Learned)
The final phase of the incident response lifecycle, focused on reviewing the incident, identifying root causes, documenting lessons learned, and implementing changes to prevent recurrence and improve future response.
- Occurs after recovery.
- Aims for continuous improvement.
- Involves root cause analysis and policy updates.
Memory trick: Plan, Spot, Stop, Fix, Learn.