The questions that arise in this phase are: What measures have failed that allowed the incident to happen. What preventive measures have you taken to avoid incidents? Who is responsible? Which barriers or controls are more critical than others? Are you prepared for a situation in which you lose control of a critical process?
This question is about the 'how'. About the way in which your company has set up measures and controls. And about whether or not these were in place and working. We elaborate this question with our TRIPOD Beta methodology.