06. Post-Incident Review Practices (492) Flashcards

1
Q

Post Incident Review

Key personnel begin discussions about lessons learned and hopefully generate ideas to improve defenses and responses. Should include;

  1. Incident awareness
  2. internal communications
  3. external communications
  4. Response procedures
  5. Knowledge and training
  6. resilience

492

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Closure

Activities required as part of security incident closure;

  1. Archival of forensic evidence
  2. Archival of communications records
  3. Notifcation to internal personnel and outside authorities
  4. Report issuance

492

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly