Under active development Content is continuously updated and improved

3.4.5Forensic Investigation and Post-Incident Review

>Control Description

FRFIs should conduct a forensic investigation for incidents where technology assets may have been materially exposed. For high-severity incidents, the FRFI should conduct a detailed post-incident assessment of direct and indirect impacts (financial and/or non-financial), including a root cause analysis to identify remediation actions, address the root cause and respond to lessons learned. The root cause analysis should assess threats, weaknesses and vulnerabilities in its people, processes, technology and data.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.