INTRA/IR/IR009Post-incident review
The examination, after the fact, of what the program saw, when, and what it did with it.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| IR009/EUMandatory | European Union | Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026 | What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings. | For the digital infrastructure and service providers it reaches, a review after the fact is carried out once recovery is done, where appropriate. It identifies the root cause where that can be done and produces documented lessons, and what those lessons are to improve is named: the approach to security, the treatment of risk, and the procedures for handling, detecting, and responding. Whether incidents led to a review at all is itself checked at planned intervals. |
| IR009/ITMandatory | Italy | Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026 | The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter. | For a subject in the national NIS register, the plan is reviewed and where appropriate updated periodically and in any case at least every two years, and again whenever a significant incident occurs, with the lessons learned from it worked in. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An incident should be worked through afterwards to a standard form, examining how quickly it was detected and remedied, whether the reporting routes worked, whether there was enough information to assess it, and whether the detection measures were effective. What is learned is used to write instructions for comparable incidents, made known to the groups they concern, and updated as more is learned. The leadership of the organization is told about the incidents once a year, and at once where something has to be done immediately. |
| Recommended | Norwaywhere written | NSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026 | A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working. | What worked and what can be improved are both identified. The controls that were compromised are mapped and reviewed and then updated or replaced, and it is assessed whether what is in place covers the organization’s risk picture at all. The processes, procedures, reporting formats, and organizational structures are evaluated for how effective they were, regularly and after an incident. |
