Root Cause Analysis and Lessons Learned

Always remember that "lessons learned" is knowledge or understanding gained by experience (in this case, by the experience during the security incident). The Lessons Learned section in your postmortem should focus on identifying incremental and innovative improvements that will measurably improve the following areas of the organization:

Processes and policies

• Technology and configurations

The postmortem should include both negative and positive experiences. You should highlight the recurrence of successful outcomes while helping to prevent the recurrence of unsuccessful outcomes.

The Lessons Learned section in the postmortem will also help you to improve your risk management processes. You can incorporate these lessons learned into several areas of risk management. One of the key inputs to risk identification is historical information. An input to both qualitative and quantitative risk analysis is identified risks, which can be obtained in your postmortem. Each incident response team should evolve to reflect new threats, improved technology, and lessons learned.

You should establish criteria for a lessons learned process. More importantly, you should turn "lessons learned" into "applied lessons." The following section gives you tips on how to build an action plan from the lessons learned during each phase of the incident response.

Figure 6-3 shows the Lessons Learned section of the SecureMe Incident Response Report and Postmortem.

Figure 6-3 Lessons Learned Section of Report

SecureMe, Inc. Incident Response Report and Postmortem Lessons Learned

Success stories (describe what good, repeatable practices and procedures took place):

How well did the incident response staff and management perform in dealing with the incident?

Were the documented procedures followed? Explain if they were adequate.

What information was needed sooner?

What should be done differently the next time a similar incident takes place?

What corrective actions can prevent similar incidents in the future?

What additionally tools or resources are needed?

The questions and information in the form outlined in Figure 6-3 are just examples of the items you can incorporate within your Lessons Learned section in your postmortem. In addition, you can build a rating system of different areas within your incident response ecosystem. For instance, you can list several areas under several major sections, such as the following:

• Tools and resources

• Incident response policies and processes

• Incident response team

• Timeliness of resolution

• Collaboration with other teams

Under each of these categories, you can list more detailed items or subcategories and then rate them. You can use a simple scale from 1 to 5, such as the following:

1 Poor

2 Needs improvement

3 Average

4 Good

5 Excellent

NOTE The rating system outlined here is just an example. The numbering scheme should be based on the needs of your organization.

At the end of this phase, you can calculate an overall average and use metrics to rate the effectiveness of your incident response process and resources.

Continue reading here: Proactive Security Framework

Was this article helpful?

0 0