nerdexam
Isaca

CISM · Question #424

Which of the following actions is MOST important to perform following a post-incident review to ensure similar incidents are not repeated?

The correct answer is C. Redesign of controls. The most important action after a post-incident review is to redesign controls to address the root cause of the incident and prevent recurrence. This may involve strengthening security measures, updating policies, or improving monitoring and response processes. While regression t

Submitted by khalil_dz· Apr 18, 2026Information Security Incident Management

Question

Which of the following actions is MOST important to perform following a post-incident review to ensure similar incidents are not repeated?

Options

  • ARegression test of remediation
  • BRecalculation of residual risk
  • CRedesign of controls
  • DReturn to the normal state

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    85% (29)
  • D
    9% (3)

Explanation

The most important action after a post-incident review is to redesign controls to address the root cause of the incident and prevent recurrence. This may involve strengthening security measures, updating policies, or improving monitoring and response processes. While regression testing, recalculating residual risk, and returning to normal operations are important, they do not directly prevent similar incidents from happening again.

Topics

#Post-incident review#Incident prevention#Control redesign#Continuous improvement

Community Discussion

No community discussion yet for this question.

Full CISM Practice