Incident response · The post-incident review · Element
The changes
What was changed as a result, with owners and dates.
The part
What it is
Reviews that produce a document and no changes are the norm, and they are why the same incident recurs.
Changes should be tracked in the same findings log as monitoring findings rather than in a separate place that nobody reads.
The smallest level
The attributes it carries
Each attribute is one of the framework’s shared types. What a date is, and how it is written, is defined once for the whole model — the note here says what it means in this particular place.
The other elements in the post-incident review
The cause
What allowed the incident to happen.
LearnThe response assessment
How well the response actually worked.
Learn