Post-incident activities and investigation
The objective of a post-incident review is to learn from each incident and improve the organization's response and recovery procedure. Lessons learned during incident management can be best used to improve the security posture of the organization, as well as the incident management process.
During a post-incident review, the overall cost of the incident is determined. This cost includes loss or damage to infrastructure, loss of business, cost of recovery, and cost of resources used to handle the incident. This cost provides useful metrics to justify the existence of the incident management team.
Identifying the root cause and corrective action
The information security manager should appoint an event review team. This team should be responsible for determining the root cause of the incident and suggest the appropriate action to prevent the reoccurrence of the incident.
Sometimes, the security manager obtains the services...