graphgrc

SCF - IRO-13 - Root Cause Analysis (RCA) & Lessons Learned

Mechanisms exist to incorporate lessons learned from analyzing and resolving cybersecurity & data privacy incidents to reduce the likelihood or impact of future incidents.

Mapped framework controls

ISO 27002

NIST 800-53

Control questions

Does the organization incorporate lessons learned from analyzing and resolving cybersecurity & data privacy incidents to reduce the likelihood or impact of future incidents?