Skip to main content

πŸ’Ό A.16.1.6 Learning from information security incidents

Description​

Knowledge gained from analysing and resolving information security incidents shall be used to reduce the likelihood or impact of future incidents.

Similar​

  • Internal
    • ID: dec-c-4c1cb4c0

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό DE.DP-5: Detection processes are continuously improved1416
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.RA-4: Potential business impacts and likelihoods are identified77
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-7: Protection processes are improved2
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-8: Effectiveness of protection technologies is shared77
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RC.IM-1: Recovery plans incorporate lessons learned
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RC.IM-2: Recovery strategies are updated
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.AN-2: The impact of the incident is understood
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.IM-1: Response plans incorporate lessons learned
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.IM-2: Response strategies are updated

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags