A new governance committee asks the information security manager what the post-incident review is fundamentally intended to deliver to the organisation, as distinct from the incident report that closed the case. Which outcome best describes the primary purpose of a post-incident review?
- AIt identifies the responder whose error allowed the incident to succeed so that individual accountability can be enforced fairly.
- BIt produces validated lessons and corrective actions that feed continuous improvement of the security programme and its controls. Correct
- CIt confirms that the incident has been fully eradicated and that all affected systems were restored from clean backups.
- DIt satisfies the regulator that a mandatory breach notification was filed inside the required reporting window for the jurisdiction.
Why A is wrong: Tempting because accountability matters in governance, but a review focused on attributing individual blame discourages honest disclosure and yields fewer durable lessons, so this is not its purpose.
Why B is correct: Correct because the review exists to convert the incident into learning, identifying root causes and assigning corrective actions that measurably strengthen controls and prevent recurrence over time.
Why C is wrong: Tempting because closure relies on eradication and recovery, but those are completed before the review begins, so confirming them is not what the review is fundamentally meant to deliver.
Why D is wrong: Tempting because regulators do scrutinise incident handling, but notification is a separate response-phase obligation, and the review's purpose is organisational learning rather than compliance evidencing.