The organization shall conduct post-incident evaluations to analyse lessons learned from
incident response and recovery, and consequently improve processes/procedures/technologies to enhance its cyber resilience.
Guidance
Consider bringing involved people together after each incident and reflect together on ways to improve what happened, how it happened, how we reacted, how it could have gone better, what should be done to prevent it from happening again, etc.
Lessons learned from incident handling shall be translated into updated or new incident
handling procedures that shall be tested, approved and trained.
The knowledge gained from analyzing and resolving security incidents should be used to reduce the likelihood of future incidents and their impact.
The organization regularly analyzes incidents as a whole. This process examines the type, amount and cost of incidents with the aim of identifying recurrent and significant incidents that need more action.
If recurrent incidents requiring response are identified, based on them:
If it is difficult to identify the source of a security incident based on the primary treatment, a separate follow-up analysis is performed for the incident, in which the root cause is sought to be identified.
The organization regularly develops its continuity plans by analyzing the testing of the plans, training and their actual use in real situations.