ExamGecko
Question list
Search
Search

Related questions

Question 1061 - CISA discussion

Report
Export

Which of the following is the MOST important reason for an IS auditor to examine the results of a post-incident review performed after a security incident?

A.
To evaluate the effectiveness of continuous improvement efforts
Answers
A.
To evaluate the effectiveness of continuous improvement efforts
B.
To compare incident response metrics with industry benchmarks
Answers
B.
To compare incident response metrics with industry benchmarks
C.
To re-analyze the incident to identify any hidden backdoors planted by the attacker
Answers
C.
To re-analyze the incident to identify any hidden backdoors planted by the attacker
D.
To evaluate the effectiveness of the network firewall against future security breaches
Answers
D.
To evaluate the effectiveness of the network firewall against future security breaches
Suggested answer: A

Explanation:

A post-incident review (PIR) is a process to review the incident information from occurrence to closure and to identify potential findings and recommendations for improvement1.The most important reason for an IS auditor to examine the results of a PIR is to evaluate the effectiveness of continuous improvement efforts and to ensure that the lessons learned from the incident are implemented and followed up2.A PIR can help an organization to eliminate or reduce the risk of the incident to re-occur, improve the initial incident detection time, identify improvements needed to diagnose and repair the incident, and update the incident management best practices1. Therefore, a PIR is a valuable source of information for an IS auditor to assess the maturity and performance of the organization's incident management process.

asked 18/09/2024
Styliani Simoiridou
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first