After-Action Report (AAR)
Definition
The formal document produced during Lessons Learned that records the incident timeline, decisions made, outcomes, and recommended improvements. The AAR drives updates to IR plans, playbooks, and detection rules.
- Produced during
- Lessons Learned phase of incident response
- Contents
- Incident timeline, decisions taken, outcomes, recommendations
- Model context
- SANS PICERL incident response model
- Downstream use
- Updates IR plans, playbooks, and detection rules
Common questions
Who typically attends the meeting that produces an AAR?+
Incident responders, affected system owners, and often legal or management stakeholders, so the timeline and decisions are agreed from multiple vantage points rather than written solely by the responding analyst.
How is an AAR different from an incident report filed for legal or regulatory purposes?+
A legal or regulatory report focuses on what happened and its impact for external disclosure. An AAR is internally focused on process improvement, so it also captures what went wrong operationally and specific fixes to detection rules or playbooks.
Related terms
- Containment Strategy
- A deliberate decision about how to limit an incident's spread, balancing the need to stop harm immediately against the risk of alerting...
- Eradication
- The phase in which the root cause of an incident is removed from the environment: deleting malware, patching exploited vulnerabilities, revoking compromised...
- Incident Declaration
- The formal decision, made during the Identification stage, that a detected event meets the organisation's criteria for a security incident. Declaration triggers...
- NIST SP 800-61
- The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
- PICERL
- Acronym for the six SANS IR stages: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The model is cyclical: the final stage...