What should the ISO/IEC 27035 lessons-learned phase produce?
Analyse patterns across events and incidents as well as the individual case. Identify improvements to the incident plan, and performance, security controls, risk assessment, management review inputs, awareness, training, external relationships, tools, and metrics.
Prioritize improvements by risk, recurrence, and feasibility. A recommendation remains open until an accountable owner implements it and verifies effectiveness, or an authorized decision maker records why it was rejected, deferred, or accepted as residual risk, meaning the risk that remains after current controls and the approved decision.
- Connect each lesson to the observation and incident evidence that supports it; examples include a delayed alert caused by a missing monitoring rule, an isolation delay caused by unclear authority, repeated supplier handoff failures, or a recovery test that did not cover a critical dependency.
- Track actions with owner, priority, due date, dependency, success measure, closure evidence, and residual risk.
- Use exercises and later incidents to verify that the change improved capability rather than only changing documentation.
Primary ISO listing for incident management principles and process.
Primary ISO listing for planning, preparing, and lessons-learned guidance.