mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-06-12 06:04:56 +03:00
1.9 KiB
1.9 KiB
Post-Incident Lessons Learned - Detailed Workflow
Pre-Meeting Preparation (1-3 days before)
- Compile complete incident timeline from all sources
- Gather all communication logs (email, chat, phone)
- Export incident metrics from ticketing system
- Collect detection data from SIEM/EDR
- Identify all participants and send calendar invites
Meeting Facilitation Guide
Ground Rules
- Blameless discussion - focus on processes and systems
- Everyone's perspective is valued equally
- Objective review of facts, not opinions
- All observations documented in real-time
- Action items must have owners and deadlines
Discussion Framework
- What was the incident? (5 min) - Brief factual summary
- Walk the timeline (20 min) - Chronological event review
- What went well? (15 min) - Effective actions and decisions
- What could improve? (15 min) - Gaps and failures
- Root cause deep dive (15 min) - 5 Whys or fishbone diagram
- Action items (10 min) - Assigned improvements
- Playbook updates (10 min) - Procedural changes
Key Metrics Framework
| Metric | Formula | Industry Benchmark |
|---|---|---|
| Dwell Time | Detection - Initial Compromise | Median: 10 days (Mandiant) |
| MTTD | Triage Complete - First Alert | Target: < 15 min (P1) |
| MTTC | Containment Complete - Detection | Target: < 4 hours |
| MTTR | Recovery Complete - Eradication | Target: < 48 hours |
| Total Duration | Closure - Detection | Target: < 7 days |
Action Item Categories
Process
- Updated playbooks and runbooks
- Communication plan updates
- Escalation criteria changes
Technology
- New detection rules
- Tool improvements
- Monitoring expansion
- Automation opportunities
People
- Training needs
- Staffing gaps
- Cross-training requirements
Follow-Up Schedule
- 1 week: Action items tracked in project system
- 1 month: First progress review
- 3 months: Validate improvements with tabletop
- 6 months: Re-evaluate metrics