Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

5.6. Lessons Learned After the incident is resolved, the FSTI Providers should perform a post-incident review to identify lessons and improve the incident response plan. The steps are, among others:

1.

Conduct a post-incident review, including gathering all involved stakeholders in the incident response team to discuss what occurred, what was done to intervene, and what could be improved.

2.

Document every aspect of the incident for a thorough review.

3.

Update the incident response plan and revisit and revise the incident response plan based on the findings from the post-incident review. Focus on weaknesses that were identified in the process response.

4.

Conduct training to improve awareness on cybersecurity.

5.

If appropriate, share learnings with other departments or external parties to improve collective security mechanisms.

60

Made with FlippingBook. PDF to flipbook with ease