インシデント対応チームは最近、未知の種類のサイバーイベントに遭遇しました。チームは問題を解決できましたが、特定にかなりの時間を要しました。今後、同様のインシデントをより迅速に特定できるようにするには、どのような方法が最も効果的でしょうか?
正解:B
Performing a post-incident review (also known as a lessons-learned session) is the best way to ensure similar incidents are identified and addressed more efficiently in the future. This review helps in understanding what went wrong, what went right, and how processes can be improved. The knowledge gained from the review can be incorporated into incident response plans and training.
"Post-incident reviews help determine root causes, assess the effectiveness of the response, and identify opportunities for improvement."
- CISM Review Manual 15th Edition, Chapter 4: Incident Management, Section: Post-incident Analysis Additionally, the ISACA CISM Practice Question Database emphasizes that post-incident reviews are essential for improving future response times and understanding patterns of threats.