ISO/IEC 27000 Learning From Information Security Incidents, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to learning from information security incidents.

Assessment Step

1
Learning From Information Security Incidents (LearningFromInformationSecurityIncidents)
Is knowledge gained from information security incidents used to strengthen and improve the organization's information security controls?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Learning From Information Security Incidents
Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls.
Citations
27001
Annex A, Control 5.27
27002
Section 5.27