CISM - Incident Management (30% of the exam) - Section 4.12

Conduct post-incident reviews to identify lessons learned, root causes and corrective actions for continuous improvement.

Conduct a post-incident review to identify lessons learned, perform root cause analysis, and define corrective actions that prevent recurrence and improve incident response capability. Ensure findings are documented, assigned to owners, and tracked to closure so that each incident drives measurable improvement to the programme.

Post-incident reviewLessons learnedRoot cause analysisCorrective actions

Practice question for this objective

Free sampleIncident Managementmedium

A new governance committee asks the information security manager what the post-incident review is fundamentally intended to deliver to the organisation, as distinct from the incident report that closed the case. Which outcome best describes the primary purpose of a post-incident review?

  • AIt identifies the responder whose error allowed the incident to succeed so that individual accountability can be enforced fairly.
  • BIt produces validated lessons and corrective actions that feed continuous improvement of the security programme and its controls. Correct
  • CIt confirms that the incident has been fully eradicated and that all affected systems were restored from clean backups.
  • DIt satisfies the regulator that a mandatory breach notification was filed inside the required reporting window for the jurisdiction.
A post-incident review exists to convert an incident into validated lessons and corrective actions that continuously improve the security programme. The review is the bridge between a single event and lasting improvement: it surfaces root causes, agrees corrective actions and feeds them back into controls and processes, which is governance value distinct from closing the case or proving compliance.

Why A is wrong: Tempting because accountability matters in governance, but a review focused on attributing individual blame discourages honest disclosure and yields fewer durable lessons, so this is not its purpose.

Why B is correct: Correct because the review exists to convert the incident into learning, identifying root causes and assigning corrective actions that measurably strengthen controls and prevent recurrence over time.

Why C is wrong: Tempting because closure relies on eradication and recovery, but those are completed before the review begins, so confirming them is not what the review is fundamentally meant to deliver.

Why D is wrong: Tempting because regulators do scrutinise incident handling, but notification is a separate response-phase obligation, and the review's purpose is organisational learning rather than compliance evidencing.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • The review documented the incident timeline in insufficient detail for the final report.

    Why it is wrong: A thin timeline weakens reporting and may be worth noting, but documentation detail does not by itself explain why an agreed fix was never applied and the issue recurred.

  • Distribute each review report to executives so they are aware that incidents have been handled and closed.

    Why it is wrong: Informing executives supports accountability, but awareness alone does not feed the findings back into controls, policies, or training, so the programme does not actually improve.

  • Defer the review until the next quarterly governance meeting so that it can be combined with other incident reports for efficiency.

    Why it is wrong: Batching reviews into a quarterly cycle is tempting for governance efficiency, but the long delay erodes responder recall and weakens the accuracy of the lessons captured.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.