An IS auditor is reviewing an organization's overall incident response capability following recovery from a cybersecurity incident. Which of the following findings should be of MOST concern to the auditor?
A.
Risk analysis errors were identified as part of the post-incident review.
B.
Logs were only collected as part of the post-incident review.
C.
The incident was caused by a known vulnerability with a documented risk acceptance.
D.
Lessons learned were not documented after the incident.
I vote D. If there are no lessons learned then they will not improve and what happened could ultimately happen again. To build a robust and growing security team you have to learn from mistakes and document so you can identify the deficiencies and grow.
Logs are crucial for incident detection, investigation, and response. Collecting logs only after an incident has occurred, as part of the post-incident review, suggests that the organization lacks the necessary monitoring and logging capabilities to proactively detect and respond to incidents.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
blehbleh
3 weeks, 5 days agoPurpleParrot
2 months, 1 week ago