Assessment

Assessment is the structured review conducted after an incident is resolved to understand what happened, how much it cost, and why it occurred. It establishes an agreed account of the event, measures the impact on operations and data, and traces the chain of causes back to their roots.

Within the Post-Incident phase, assessment is the first step toward learning. Once the immediate threat is contained and recovery is underway, the organization needs an honest picture of the event before it can decide what to change. Assessment supplies that picture, grounded in evidence rather than impression.

In practice, assessment combines impact analysis with root-cause investigation. Teams quantify what was affected, how long disruption lasted, and which assets or records were touched, then work backward through the timeline to find the conditions that allowed the incident: a missing control, a process gap, or a delayed response. The most effective reviews are blameless, focusing on systems and decisions rather than individuals, so that people share information freely. The output is a clear set of findings that feeds improvement, turning a painful event into durable understanding.

References#

  • NIST SP 800-61, Computer Security Incident Handling Guide
  • SANS, Incident Handler's Handbook

Cookie Consent

We use cookies to enhance your experience. Learn more