IncidentResponsev2

Conduct After Action Review to support redeployment efforts Task

Conditions

Given an IR Team deployed supporting a designated MP in Cyber Incident Recovery.

Standards

Upon moving into the redeployment Phase, the IR Team should develop an AAR containing the following elements:

End State

The IR Team completes a full after action review with MP. The MP contains knowledge from knowing lessons learned, ways to prevent future incidents, and how to detect an actionable incident.

Manual Steps

Running Script

Dependencies

Other available tools

References

NIST Cyber Security Framework
[NIST SP 80061: Computer Security Incident Handling Guide](https://csrc.nist.gov/publications/detail/sp/80061/rev*2/final)

Revision History