A.5.27 Learning from information security incidents
Feed lessons from incidents back into stronger controls.
14
artefacts
2
held by a system
5
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Change request ticket for patching vulnerable system after ransomware · Vulnerability scanner / patch tooling
- Metrics dashboard showing reduction in similar incidents · Source control / CI pipeline
periodic reviewEvidence produced at each review
- Meeting minutes of post-incident review for phishing incident · Policy repository / GRC workspace
- Stakeholder review minutes for ransomware event · Policy repository / GRC workspace
- Executive summary minutes for data breach · Policy repository / GRC workspace
- Implementation evidence of updated email filtering controls · Policy repository / GRC workspace
- Training attendance record for staff after data breach · HR system / LMS
governing documentDocuments that govern the control
- Root cause analysis report for phishing incident · Document repository
- Technical forensic analysis report for ransomware event · Document repository
- Business impact analysis summary for data breach · Document repository
- Corrective action plan for phishing incident · Policy repository / GRC workspace
- Lessons learned document uploaded to knowledge base · Policy repository / GRC workspace
- Updated security policy reflecting lessons from ransomware · Policy repository / GRC workspace
- Training module revision incorporating breach lessons · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your Vulnerability scanner / patch tooling on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Root cause analysis limited to symptoms
- No formal tracking of corrective actions
- Lessons not shared beyond IT team
- Updates to policies delayed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.26 Response to information security incidents · A.5.28 Collection of evidence