CISM · Question #985
While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the…
The correct answer is C. During post-incident review. The post-incident review (also called 'lessons learned') is the correct and standard time to formally update the incident response plan. During active incident phases - containment (A) and recovery (B) - the team's full attention must remain on resolving the incident; stopping…
Question
While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the plan?
Options
- AWhile containing the incident
- BBefore the recovery phase
- CDuring post-incident review
- DAfter a risk re-evaluation
How the community answered
(57 responses)- A14% (8)
- B4% (2)
- C75% (43)
- D7% (4)
Explanation
The post-incident review (also called 'lessons learned') is the correct and standard time to formally update the incident response plan. During active incident phases - containment (A) and recovery (B) - the team's full attention must remain on resolving the incident; stopping to rewrite documentation introduces distraction and delay. Waiting for a full risk re-evaluation (D) is unnecessarily delayed and decouples the update from the fresh, concrete observations made during the incident. The post-incident review allows the team to systematically analyze what went wrong, why deficiencies existed, and how the plan should be improved, while the experience is still recent and well-documented.
Topics
Community Discussion
No community discussion yet for this question.