Post-incident activity

Hosting a lessons learned meeting or post-mortem analysis report can help the team to learn from the incident. The primary objective of the lessons learned meeting is to look for the improvement of each phase during the security incident response process. This kind of meeting is often neglected once the security issue is solved. It's suggested that you at least document the process of the security incident and incorporate it into the knowledge base.

For a lessons learned meeting, the meeting should focus on how the team can improve together and prevent a similar issue in the future instead of blaming someone for the error. The inputs of the post-mortem meeting typically include the proposed security control changes, ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.