Problem Statement
What policies should be reviewed after a major security incident?
Explanation
Policies related to access control, patch management, backups, and third-party risk should be reviewed.
Incident handling procedures and escalation workflows must also be updated based on gaps observed during the incident. Regular reviews prevent repeating mistakes.