Fork me on GitHub

CultureAndOrganization -> Education and Guidance: Security-Lessoned-Learned

Risk and Opportunity

Risk: After an incident, a similar incident might reoccur.
Opportunity: Running a 'lessons learned' session after an incident helps drive continuous improvement. Regular meetings with security champions are a good place to share and discuss lessons learned.

Usefulness and Requirements of this Activitiy

Usefullness: Medium
Required knowledge: Medium (two disciplines)
Required time: Medium
Required resources (systems): Very Low

Additional Information

OWASP SAMM VERSION 2

ISO27001 2017