CAS-003 · Question #826
Following a major security incident that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root-cause…
The correct answer is A. Capture recommendations from a lessons-learned session with key management. After a major incident, a CISO must translate root-cause findings into actionable improvements, which requires a structured lessons-learned session with stakeholders who can drive change.
Question
Following a major security incident that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root-cause analysis. Which of the following additional steps should the CISO take to mitigate the chance of a recurrence?
Options
- ACapture recommendations from a lessons-learned session with key management.
- BInstall additional detective controls to facilitate a better root cause analysis in future incidents.
- CPurchase cyber-incident insurance, specifically covering the root cause.
- DCompile a report containing all help desk tickets received during the incident.
How the community answered
(35 responses)- A71% (25)
- B17% (6)
- C9% (3)
- D3% (1)
Why each option
After a major incident, a CISO must translate root-cause findings into actionable improvements, which requires a structured lessons-learned session with stakeholders who can drive change.
A lessons-learned session with key management captures institutional knowledge about what failed, why it failed, and what controls must be added or changed. This directly converts root-cause findings into formal recommendations that leadership can fund and prioritize, closing the gap that allowed the incident to occur.
Installing additional detective controls improves future detection but does not address the root cause or prevent the same incident from recurring - it only helps identify the next one faster.
Cyber-incident insurance transfers financial risk but does nothing to reduce the likelihood or severity of a recurrence; it is a risk transfer mechanism, not a risk mitigation strategy.
Compiling help desk tickets is a data-gathering activity that may support analysis, but it does not constitute a step toward preventing recurrence and lacks the actionable output of a lessons-learned session.
Concept tested: Post-incident lessons-learned process for risk reduction
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.