CISA Certified Information Systems Auditor – Question2614

The MAIN reason an organization’s incident management procedures should include a post-incident review is to:

A.
ensure evidence is collected for possible post-event litigation.
B. take appropriate action when procedures are not followed.
C. enable better reporting for executives and the audit committee.
D. improve processes by learning from identified weaknesses.

Correct Answer: D