CISM - Incident Management - Section 4.12

Conduct post-incident reviews to identify lessons learned, root causes and corrective actions for continuous improvement.

Conduct a post-incident review to identify lessons learned, perform root cause analysis, and define corrective actions that prevent recurrence and improve incident response capability. Ensure findings are documented, assigned to owners, and tracked to closure so that each incident drives measurable improvement to the programme.

Post-incident reviewLessons learnedRoot cause analysisCorrective actions

Practice question for this objective

Free sampleIncident Managementmedium

A new governance committee asks the information security manager what the post-incident review is fundamentally intended to deliver to the organisation, as distinct from the incident report that closed the case. Which outcome best describes the primary purpose of a post-incident review?

  • AIt identifies the responder whose error allowed the incident to succeed so that individual accountability can be enforced fairly.
  • BIt produces validated lessons and corrective actions that feed continuous improvement of the security programme and its controls. Correct
  • CIt confirms that the incident has been fully eradicated and that all affected systems were restored from clean backups.
  • DIt satisfies the regulator that a mandatory breach notification was filed inside the required reporting window for the jurisdiction.
A post-incident review exists to convert an incident into validated lessons and corrective actions that continuously improve the security programme. The review is the bridge between a single event and lasting improvement: it surfaces root causes, agrees corrective actions and feeds them back into controls and processes, which is governance value distinct from closing the case or proving compliance.

Why A is wrong: Tempting because accountability matters in governance, but a review focused on attributing individual blame discourages honest disclosure and yields fewer durable lessons, so this is not its purpose.

Why B is correct: Correct because the review exists to convert the incident into learning, identifying root causes and assigning corrective actions that measurably strengthen controls and prevent recurrence over time.

Why C is wrong: Tempting because closure relies on eradication and recovery, but those are completed before the review begins, so confirming them is not what the review is fundamentally meant to deliver.

Why D is wrong: Tempting because regulators do scrutinise incident handling, but notification is a separate response-phase obligation, and the review's purpose is organisational learning rather than compliance evidencing.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.