Post-Incident Review
What is Post-Incident Review?
A structured evaluation conducted after a security incident to identify lessons learned and improvement opportunities for future prevention and response.
Terms that appear alongside post-incident review
Each of these is named in at least one of the same controls as post-incident review. The number is how many controls name both.
- incident response 19 shared controls
- lessons learned 15 shared controls
- business continuity 12 shared controls
- breach notification 10 shared controls
- nist 9 shared controls
- cybersecurity 8 shared controls
- incident management 8 shared controls
- audit 7 shared controls
Frameworks that govern post-incident review
What the standards actually require on post-incident review
Requirements naming post-incident review across 6 standards, quoted from the control text.
The Board may cause reviews of significant cyber security incidents to be conducted on a no-fault basis to identify lessons learned, without attributing liability.
AUCSA-CIRB-REVIEW · Conduct of no-fault post-incident reviews →Maintain recordkeeping + communications strategy + post-incident review + board reporting per OAIC guidance and Privacy Act section 26WL recordkeeping expectations.
AUNDB-A7 · Recordkeeping, Communications Strategy, Post-Incident Review, Board Reporting →Analyze incident from start to finish to identify successes and shortcomings in the response
PICERL-L1 · Post-Incident Review →Conduct post-incident reviews. Post-incident reviews help prevent incident recurrence through identifying lessons learned and follow-up action.
CIS-17.8 · Conduct Post-Incident Reviews →Post-incident review and improvement. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.
FFIEC-25 · Post-incident review and improvement →Conduct structured post incident reviews to identify lessons, validate effectiveness, and drive improvement.
ISO22320-10.1 · Post Incident Review and Lessons Learned →Questions people ask about post-incident review
What is Post-Incident Review?
Why is Post-Incident Review important for compliance?
Which compliance frameworks address Post-Incident Review?
Where can I learn more about Post-Incident Review?
See how Post-Incident Review applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.