Carrying out post-incident reviews
After an incident, the organization should know what went wrong or right during IR, what measures the team carried out, and how future incidents can be handled better. It is noteworthy that reviews should concern the incident management process only, not the cause of the incident. While it may be tempting for some teams to want to include in-depth details on the cause of an incident in the review, this may take a long time as some causes are not simple to identify. Due to the increased sophistication of attacks, it is rarely one flaw, one system, or one person that can be said to have caused an attack. Therefore, some premature communication about a cause might, later on, be ruled out once thorough forensics have been carried out. This may cause confusion or distrust. Hence, the postmortem should focus on the IR process alone, with the aim of improving the efficiency and effectiveness of future response processes.
The post-incident review should...