Module 12: Post-Mortem Reporting
The Post-mortem Report
Post-Mortem Reporting Basics
Metrics and KPIs in Post-Mortem Reporting
Distinguishing Between Blame and Accountability
Process
SOC Mgr
SOC Level 1
SOC Level 2
CSIRT
Post-Mortem Report Template
Field
Description
Field
Description
Field
Description
Field
Description
Field
Description
Field
Description
Root Cause Analysis
Cause Mapping for Root Cause Analysis
Why
Question
Finding



Initial and Subsequent Points of Compromise
Impact and Damage Assessment
Connecting Technology to Business

Updating our Initial Impact Assessment
Lessons Learned
Incident Response Lessons Learned
Identifying Capability Improvements
Bringing It Together
Lab Scenario Post-Mortem Report
Last updated