How should a post-incident review be run?
After recovery, create a timeline from event and incident records and compare actual detection, assessment, decisions, response, communications, recovery, and evidence handling with the plan. Include the incident coordinator, relevant responders, affected business or service owners, providers, control owners, and the members needed to route improvements.
The depth should match the incident's nature and severity. Separate urgent remediation from longer-term improvements, and record unresolved facts rather than forcing a final cause. Each action needs a risk-based priority, owner, due date, acceptance criteria, dependency, evidence, and closure authority.
- Review what worked as well as failures, including informal adaptations worth formalizing; for example, a monitoring rule that detected lateral movement, an emergency authority that allowed timely isolation, or a supplier handoff that delayed recovery.
- Address technical, process, people, supplier, communications, legal, continuity, and evidence issues.
- Feed conclusions into the incident plan, playbooks, risk assessment, controls, training, exercises, metrics, and management review.
Primary ISO listing for incident management principles and process.
Primary ISO listing for planning, preparing, and lessons-learned guidance.