Skip to content

Instantly share code, notes, and snippets.

@travis-g
Last active September 16, 2018 01:00
Show Gist options
  • Save travis-g/b6de33a164b84752cbb52370d6df8ff0 to your computer and use it in GitHub Desktop.
Save travis-g/b6de33a164b84752cbb52370d6df8ff0 to your computer and use it in GitHub Desktop.
Incident Report template

Incident Report/2018-07-04

Incident Metadata

  • Status: Resolved
  • Incident Commander: travis-g
  • Communications: Links

Incident Summary

Summary about what happened goes here. This should only be a few sentences, but should cover everything. The title of the report should include the date of when the actual incident ocurred.

Impact

  • All impact items.
  • How long did the incident have an effect?

Root Cause

The base cause of the issue should go here. This may only be certain after the fact.

Background

This is the area for context, and may have subsections.

Lessons

What went well

  • Good things first.
  • These should be full sentences, with periods.
  • Bullets.
  • Bullets.

What went badly

  • Bad bullets.
  • Full sentences!
  • Maybe worse bullets.
  • There could be many...

Lucky items

  • Anything fortunate should go here.
  • Full sentences, with periods.

Action Items

  • Action items are things that should be done
  • Still bullets
    • Things completed should be marked as such.
  • There doesn't need to be an order per se
    • This item is completed.

Timeline

This should be compiled from Symphony logs, emails, etc., with times in UTC. The real message here should be something along the lines of "These times are in UTC and are compiled from Symphony, emails, and activity logs."

2018-07-01 - 2018-07-03

Things leading up to the event.

2018-07-04

  • 19:04 I read this writeup from Gentoo's wiki about their breach.
  • 19:05 Started writing this example writeup.
    • Started on gist.github.com.
  • 19:08 Looked for more references
  • 19:08 Decided some guidelines.
    • Seconds should be omitted if unknown, but order should be retained.
    • Repo names like travis-g/dotfiles should be italicized.
    • URLs should be italicized as well.
    • Commit hashes should be italicized.

Appendix

Subheadings

Extra stuff that should be known, like known bad commits.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment