Post-Incident Activities and Investigations
The objective of a post-incident review is to learn from each incident and improve the organization's response and recovery procedures. Lessons learned during incident management can best be used to inform the overall improvement of the security posture of the organization as well as the incident management process.
During a post-incident review, the overall cost of the incident is determineCost includes loss or damage to infrastructure, loss of business, cost of recovery, and the cost of the resources used to handle the incident. This cost provides useful metrics to justify the existence of the incident management team.
Identifying the Root Cause and Taking Corrective Action
An information security manager should appoint an event review team. This team should be responsible for determining the root cause of the incident and suggesting the appropriate actions that should be taken to prevent any reoccurrence of the incident.
...