Lessons-Learned Review
Definition
A structured post-cycle review that identifies what worked, what failed, and what should change in the next audit cycle. The output is a set of concrete changes to scope, methodology, resource allocation, or risk ratings.
- Applies to
- Audit programmes, not incident response
- Timing
- Post-audit-cycle
- Examines
- What worked, what failed, what to change
- Output
- Changes to scope, methodology, resourcing, risk ratings
Common questions
How does an audit lessons-learned review differ from an incident lessons-learned meeting?+
This review closes out an audit cycle rather than a security incident, so its findings feed into how the next audit is scoped and resourced rather than into detection rules or an IR playbook.
What kind of change might come out of this review?+
Common outcomes include reallocating auditor time toward higher-risk areas that were under-sampled, revising testing methodology that produced weak evidence, or adjusting risk ratings that proved inaccurate against subsequent findings.
Related terms
- Audit Programme Maturity
- The degree to which an organisation's audit activities are systematically planned, resourced, executed, measured, and improved. Maturity is usually described on a...
- CMMC (Cybersecurity Maturity Model Certification)
- A United States Department of Defense framework that certifies defence contractors at one of five tiers of cybersecurity capability. Each tier requires...
- Enterprise Risk Management (ERM) Integration
- The practice of aligning audit planning with the organisation's ERM risk register so that audit coverage tracks actual risk. When the risk...
- Mean Time to Close (MTTC)
- The average elapsed time between the date a finding is formally reported and the date remediation is verified as complete. MTTC is...
- Repeat Finding Rate
- The percentage of findings in the current audit cycle that were also identified in the prior cycle. A high repeat finding rate...