From the course: CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep

Unlock the full course today

Join today to access over 24,700 courses taught by industry experts.

Post-incident activities

Post-incident activities

- [Instructor] Once the incident response team returns the organization to a normal operating state, all too often the response effort ends without completing an important final step, the Post-Incident Activities. Let's talk about four important post-incident activities, the lessons learned process, root cause analysis, evidence retention, and the generation of indicators of compromise. The lessons learned process is designed to provide everyone involved in the incident response effort and opportunity to reflect on their individual role in the incident and the team's overall response. It's an opportunity to improve the processes and technologies used in incident response to better respond to future security crises. The most common way to conduct lessons learned is to gather everyone in the same room or connect them by video conference or telephone, and then ask a trained facilitator to lead a lessons learned session. Ideally, this facilitator will have played no role in the incident…

Contents