What is the purpose of a lessons learned review after a security incident?
- A.To analyze the incident response effectiveness, identify improvements for the IR plan, address root causes, and prevent similar incidents from occurring in the future
- B.To write a report for management, governed by Requirement 1.2.5, which requires every allowed service, protocol, and port to be identified, approved, and supported by a defined business need
- C.To update the employee handbook, since a post-incident review may substitute for the required plan testing for backup and archive media since the retirement of v3.2.1
- D.To discipline employees, as the standard requires lessons learned to be recorded only after a confirmed breach for telephone order channels between annual assessments
Why A is correct
Lessons learned reviews improve the IR plan, address root causes, and implement preventive measures to reduce the likelihood of similar future incidents.
Know someone studying for PCI DSS? Send them this one.