5.3 Post-Incident Learning & Prevention
-
The Post-Incident Review (PIR): After an incident, the team meets to analyze what happened. This is not about blame; it is about process improvement.
-
Questions asked: What worked? What failed? Was the response time fast enough?
-
-
Root Cause Analysis (RCA) – The “5 Whys”: To find the true source of the problem, we ask “Why” five times.
-
Example: Data was leaked. -> Why? -> An employee uploaded it to Dropbox. -> Why? -> They couldn’t send it via email (too large). -> Why? -> The corporate secure transfer tool was broken. -> Why? -> Lack of maintenance.
-
Root Cause: The failure of the supported tool forced the user to use Shadow IT.
-
-
Feedback Loop: The results of the PIR and RCA are used to update the Threat Model and Security Policies to prevent recurrence.