What is the role of lessons learned in continual improvement?
- A.They provide insights from past experiences (incidents, audits, exercises) that inform improvements to prevent recurrence and enhance practices
- B.Only for incident response
- C.Lessons learned are optional. Clause 4.3 requires the information security committee to document this during the initial certification audit, then present the outcome again during the Check phase as part of the evidence reviewed by the certification body.
- D.Only documented after major events
Why A is correct
Lessons learned from incidents, audits, and exercises provide valuable insights that inform ISMS improvements and prevent recurrence of issues.
Know someone studying for ISO 27001? Send them this one.