Skip to main content

💼 A.16.1.6 Learning from information security incidents

  • ID: /frameworks/iso-iec-27001-2013/16/01/06

Description​

Knowledge gained from analysing and resolving information security incidents shall be used to reduce the likelihood or impact of future incidents.

Similar​

  • Internal
    • ID: dec-c-4c1cb4c0

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 DE.DP-5: Detection processes are continuously improved1316no data
💼 NIST CSF v1.1 → 💼 ID.RA-4: Potential business impacts and likelihoods are identified77no data
💼 NIST CSF v1.1 → 💼 PR.IP-7: Protection processes are improved2no data
💼 NIST CSF v1.1 → 💼 PR.IP-8: Effectiveness of protection technologies is shared67no data
💼 NIST CSF v1.1 → 💼 RC.IM-1: Recovery plans incorporate lessons learnedno data
💼 NIST CSF v1.1 → 💼 RC.IM-2: Recovery strategies are updatedno data
💼 NIST CSF v1.1 → 💼 RS.AN-2: The impact of the incident is understoodno data
💼 NIST CSF v1.1 → 💼 RS.IM-1: Response plans incorporate lessons learnedno data
💼 NIST CSF v1.1 → 💼 RS.IM-2: Response strategies are updatedno data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance