ICS
3Stage 3 of 3

Learn

Google's guide makes learning from outages a core tenet and notes that outages left unchecked tend to come back and pile up. Its main tool is the blameless postmortem. NIMS reaches the same place through the after-action report and improvement plan, the AAR/IP format of the Homeland Security Exercise and Evaluation Program.

Start while it is fresh

Start the write-up as soon as the incident is resolved. Planning already holds the raw material: the activity logs, the timeline, the Incident Action Plans, the decision records and the status summaries. The review turns that record into an explanation.

Blameless

Everyone in the response acted in good faith on what they knew at the time. Findings go to systems, procedures and training. Record the decisions and the information behind them, and leave individual names out of the causes.

Review the management as well as the fix

The technical cause is examined in the PIVTR-D debrief. Review the incident management alongside it, area by area.

AreaQuestions
DetectionHow long from first sign to someone taking command? What would have paged sooner?
CommandWas command clear from the start? How many handovers, and did each carry the open decisions?
PlanningWere objectives written before tactics? Did each period have a plan, and did the work follow it?
CommunicationsDid every audience get the same facts on schedule? Did anything contradict or leak?
OperationsDid span of control hold? Did anyone work without an assignment?
LogisticsDid responders have access, tools and rest when they needed them?
Finance/AdminWere hours, costs and insurer deadlines tracked from the first hour?
SafetyDid anyone work past the shift limit? Did containment put a physical process at risk?

Improvement plan

Each corrective action gets one owner, a due date agreed with the people who will staff and fund it, and a way to confirm it is done. Actions go into the owning team's backlog and are tracked there until closed. Share the review widely inside the organization.

Across incidents

Once reviews are routine, keep their findings in one structured register. Findings that recur across incidents show where larger investment belongs: a detection gap that keeps adding hours, a handover that keeps dropping decisions, a supplier that keeps being the way in.

After-action report and improvement plan (after HSEEP AAR/IP)

AFTER-ACTION REPORT AND IMPROVEMENT PLAN (after HSEEP AAR/IP)
Incident name and number:
Dates, first sign to close:
Incident type at peak:
Prepared by:                  Reviewed by:

1. Summary
   What happened, in five sentences or fewer.

2. Timeline
   First sign, command established, contained, eradicated, recovered, closed.

3. What worked
   Strength      Why it worked      How we keep it

4. What to improve
   Area      Observation      Cause      Recommendation

5. Improvement plan
   Action      Owner      Due      How we confirm it is done      Status

6. Hours and costs
   Responder hours:        Outside costs:        Insurance claim status:

7. Distribution
   Who receives this report:
Adapted from the National Incident Management System, Third Edition (FEMA, 2017). Cyber adaptation, examples and templates by Habib Tora, licensed under CC BY 4.0. Not published by, endorsed by, or affiliated with FEMA or the Department of Homeland Security. Structure after Google's SRE Incident Management Guide. Companion to PIVTR-D.