CAS-003 · Question #901
Following a major security modem that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root cause…
The correct answer is A. Capture recommendations from a lessons-learned session with key management. After completing a root cause analysis, the next logical step in the post-incident process is a lessons-learned session. This session, attended by key stakeholders and management, transforms root cause findings into actionable recommendations - procedural changes, control…
Question
Following a major security modem that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root cause analysis. Which of the following additional steps should the CISO take to mitigate the chance of a recurrence?
Options
- ACapture recommendations from a lessons-learned session with key management
- BInstall additional detective controls to facilitate a better root cause analysts in future incidents
- CPurchase cyber-incident insurance specifically covering the root cause
- DCompile a report containing all help desk tickets received during the incident
How the community answered
(60 responses)- A78% (47)
- B12% (7)
- C3% (2)
- D7% (4)
Explanation
After completing a root cause analysis, the next logical step in the post-incident process is a lessons-learned session. This session, attended by key stakeholders and management, transforms root cause findings into actionable recommendations - procedural changes, control improvements, training updates - that directly reduce recurrence risk. Option B (more detective controls) improves future detection but doesn't prevent the same root cause from recurring. Option C (cyber insurance) covers financial losses after an incident but provides no preventive value. Option D (compiling help desk tickets) is purely historical documentation and produces no actionable mitigations. The lessons-learned process is a cornerstone of incident response maturity frameworks such as NIST SP 800-61.
Topics
Community Discussion
No community discussion yet for this question.