While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the plan?
During post-incident review is the best time to update the incident response plan after observing several deficiencies in the current plan while responding to a high-profile security incident. A post-incident review is a process of analyzing and evaluating the incident response activities, identifying the lessons learned, and documenting the recommendations and action items for improvement. Updating the incident response plan during post-incident review helps to ensure that the plan reflects the current best practices, addresses the gaps and weaknesses, and incorporates the feedback and suggestions from the incident response team and other stakeholders. Therefore, during post-incident review is the correct answer.
https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf
https://www.techtarget.com/searchsecurity/feature/5-critical-steps-to-creating-an-effective-incident-response-plan
https://www.integrify.com/blog/posts/incident-response-plan-need-an-update/
Abel
6 months agoLeonie
6 months agoRoselle
6 months agoRosann
5 months agoLeigha
6 months agoFletcher
6 months agoVallie
7 months agoLucille
7 months agoNida
7 months agoCorrinne
6 months agoDelila
6 months agoCoral
7 months agoJohana
7 months agoCarma
7 months ago