Incident response · The post-incident review · Element

The changes

What was changed as a result, with owners and dates.

The part

What it is

Reviews that produce a document and no changes are the norm, and they are why the same incident recurs.

Changes should be tracked in the same findings log as monitoring findings rather than in a separate place that nobody reads.

The smallest level

The attributes it carries

Each attribute is one of the framework’s shared types. What a date is, and how it is written, is defined once for the whole model — the note here says what it means in this particular place.