nerdexam
Isaca

CISM · Question #985

While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the…

The correct answer is C. During post-incident review. The post-incident review (also called 'lessons learned') is the correct and standard time to formally update the incident response plan. During active incident phases - containment (A) and recovery (B) - the team's full attention must remain on resolving the incident; stopping…

Submitted by rania.sa· Apr 18, 2026Information Security Incident Management

Question

While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the plan?

Options

  • AWhile containing the incident
  • BBefore the recovery phase
  • CDuring post-incident review
  • DAfter a risk re-evaluation

How the community answered

(57 responses)
  • A
    14% (8)
  • B
    4% (2)
  • C
    75% (43)
  • D
    7% (4)

Explanation

The post-incident review (also called 'lessons learned') is the correct and standard time to formally update the incident response plan. During active incident phases - containment (A) and recovery (B) - the team's full attention must remain on resolving the incident; stopping to rewrite documentation introduces distraction and delay. Waiting for a full risk re-evaluation (D) is unnecessarily delayed and decouples the update from the fresh, concrete observations made during the incident. The post-incident review allows the team to systematically analyze what went wrong, why deficiencies existed, and how the plan should be improved, while the experience is still recent and well-documented.

Topics

#Incident Response Plan#Post-incident Review#Lessons Learned#Incident Management Lifecycle

Community Discussion

No community discussion yet for this question.

Full CISM Practice