06. Post-Incident Review Practices (492) Flashcards
1
Q
Post Incident Review
Key personnel begin discussions about lessons learned and hopefully generate ideas to improve defenses and responses. Should include;
- Incident awareness
- internal communications
- external communications
- Response procedures
- Knowledge and training
- resilience
492
A
2
Q
Closure
Activities required as part of security incident closure;
- Archival of forensic evidence
- Archival of communications records
- Notifcation to internal personnel and outside authorities
- Report issuance
492
A