Learning from information security incidents
Purpose
Use knowledge gained from incidents to strengthen controls and reduce the chance or impact of future ones.
How to meet this control
In short: Use knowledge from incidents to strengthen controls.
- Step 01Run a post-incident review for significant incidents and capture lessons learned with assigned actions
- Step 02Track incident types, volumes and costs to spot recurring or trending issues
- Step 03Feed lessons back into the incident plan, scenarios, runbooks and the risk assessment
- Step 04Implement additional controls that reduce the likelihood or impact of similar incidents
- Step 05Use anonymised real examples to strengthen awareness training
Tip: Run a post-incident review and feed actions back into controls.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Set up procedures to quantify and monitor the types, volumes and costs of incidents
- ›Feed lessons learned back into the incident management plan, scenarios and procedures
- ›Identify recurring or serious incidents and their causes to update the risk assessment
- ›Determine and implement additional controls to reduce the likelihood or impact of similar incidents
- ›Use real incident examples to improve user awareness and training
- ›Review whether existing controls failed, contributed to or missed the incident
- ›Track trends over time so patterns can inform broader security improvements
Audit evidence to keep
- - Post-incident review reports with documented lessons and actions
- - Incident trend metrics (types, volumes, costs) over time
- - Evidence that lessons learned drove control or process changes
- - Updated training material referencing real incident learnings
Common mistakes
- - Having an incident plan that staff cannot find
- - Closing incidents without root cause or lessons learned
- - Not preserving evidence before systems are changed
Owner, cadence, and proof
Assign one accountable owner for A.5.27. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.