Skip to content

Post-Incident Activity

Definition

The NIST SP 800-61 label for the final phase of the incident response lifecycle. It encompasses evidence retention, lessons-learned meetings, and the translation of findings into documented improvements to the IR plan, policies, and controls.

Source standard
NIST SP 800-61
Position
Final phase of the incident response lifecycle
Includes
Evidence retention, lessons-learned meeting
Output
Documented updates to the IR plan, policies and controls

Common questions

Why does NIST place a formal review after the incident is already resolved?+

Containment and eradication end the immediate threat but do not by themselves fix the gap that allowed it, so the framework requires a separate step to convert what was learned into concrete changes to detection, controls or procedure before the next incident.

How long should evidence be retained during this phase?+

NIST SP 800-61 does not set a fixed retention period; it directs organisations to retain evidence long enough to support any prosecution, litigation, or root-cause work still in progress, which in practice is set by legal counsel and applicable regulation rather than a single universal figure.

Related terms

Action Item
A specific, time-bound improvement task generated by a post-incident finding. An action item has a named owner, a target completion date, a...
Blameless Post-Mortem
A cultural approach to post-incident review, popularised in site reliability engineering, in which the analysis focuses on systemic and process failures rather...
Lessons-Learned Register
A persistent record, maintained by the security programme, that links each post-incident action item to the originating incident, tracks its status, and...
Root-Cause Analysis (RCA)
A structured method for identifying the underlying systemic cause of a failure rather than its immediate trigger. Common techniques in incident review...
Timeline Reconstruction
The process of ordering digital events from multiple sources into a single chronological account. Requires normalising all timestamps to a common reference...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.