Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2024 4.1 g3 #13

Open
wants to merge 203 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
203 commits
Select commit Hold shift + click to select a range
b6f6b30
traducción playbook phishing
raulalberti May 10, 2022
2af0160
traducción index roles
raulalberti May 10, 2022
7040e8a
Add files via upload
JesusJimenezSantana May 10, 2022
a7fe396
Traducción rol 4 experto
jesusrelinque May 10, 2022
d70fa08
Add files via upload
JesusJimenezSantana May 10, 2022
1f1c16b
Traducción after
jesusrelinque May 10, 2022
6aa7bc4
Add files via upload
AbelPosadoReyes May 10, 2022
985e47c
Update index.md
AbelPosadoReyes May 10, 2022
00153dc
Add files via upload
DavidValenClass May 10, 2022
46f749a
Add files via upload
alejandrosanchezman May 10, 2022
562ad0c
Add files via upload
DavidValenClass May 10, 2022
e358943
Add files via upload
alejandrosanchezman May 10, 2022
12f7f7a
Add files via upload
alejandrosanchezman May 10, 2022
cec6238
Add files via upload
alejandrosanchezman May 10, 2022
42e3263
Add files via upload
gdomram487 May 10, 2022
b6b1646
Traducción del rol 2
iglezb May 10, 2022
d5844a7
Add files via upload
alejandrosanchezman May 10, 2022
48acd6e
Add files via upload
iglezb May 10, 2022
9261ae7
Add files via upload
gdomram487 May 10, 2022
aa8d641
Add files via upload
gdomram487 May 10, 2022
b1357d5
Modificación menor
raulalberti May 10, 2022
3cfcd2c
Add files via upload
alejandrosanchezman May 10, 2022
bbc1c23
Add files via upload
alejandrosanchezman May 10, 2022
a01225b
Subida during.md
jmarrieta98 May 10, 2022
bb529f2
Add files via upload
alejandrosanchezman May 10, 2022
9a62a6e
Add files via upload
alejandrosanchezman May 10, 2022
73285c8
Add files via upload
alejandrosanchezman May 10, 2022
2344beb
Update index.md
raulalberti May 10, 2022
24ed2c2
arreglado cambios menores
raulalberti May 10, 2022
2583dfd
Update playbook-defacement.md
raulalberti May 10, 2022
1999bf1
cambios menores
raulalberti May 10, 2022
00ceb55
Update playbook-phishing.md
raulalberti May 10, 2022
c10a728
Update playbook-phishing.md
raulalberti May 10, 2022
a956a03
Update playbook-supply-chain.md
raulalberti May 10, 2022
de278ef
Update glossary.md
raulalberti May 10, 2022
9402efc
cambio del incident commander
raulalberti May 10, 2022
a5f2e5b
Update index.md
raulalberti May 11, 2022
0f3a4f1
Incident commander
raulalberti May 11, 2022
b27cf47
Update glossary.md
raulalberti May 11, 2022
bb9cee2
Incident commander
raulalberti May 11, 2022
bdfdfcd
Update role-1-commander.md
raulalberti May 11, 2022
48d1da1
Incident commander
raulalberti May 11, 2022
3b66f4d
Incident commander
raulalberti May 11, 2022
aea0427
incident commander
raulalberti May 11, 2022
3704160
incident commander
raulalberti May 11, 2022
8892efc
incident commander
raulalberti May 11, 2022
ed42935
incident commander
raulalberti May 11, 2022
a0a32fd
traducción español
raulalberti May 11, 2022
ce31473
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
c728ae8
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
fb96876
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
b894172
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
4515e8e
Update index.md
raulalberti May 11, 2022
e8e98db
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
430684e
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
9d1ddd3
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
9d08dac
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
62693f8
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
f1dda3e
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
5ce52f2
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
3fc5543
arreglo para que se autogenere bien con info.yml
raulalberti May 11, 2022
e50d02b
Update index.md
AbelPosadoReyes May 12, 2022
3bd8cc4
Arreglo during.md
jmarrieta98 May 17, 2022
c7c6ec9
Actualización info
jmarrieta98 May 17, 2022
81bae0c
correciones menores
raulalberti May 17, 2022
30a9d26
Update playbook-phishing.md
raulalberti May 17, 2022
d71d77f
Update playbook-phishing.md
raulalberti May 17, 2022
558ecc0
Update index.md
raulalberti May 17, 2022
01dd4a8
Update index.md
raulalberti May 17, 2022
96e9c75
Update index.md
raulalberti May 17, 2022
a7b0a6f
Update index.md
raulalberti May 17, 2022
71c323e
Arreglo during.md
jmarrieta98 May 17, 2022
615768d
Cambio autor2
any3l0 Jun 2, 2022
3e4cacb
Revisión traducción V1
any3l0 Jun 4, 2022
7050a9a
Revisión traducción V1
any3l0 Jun 4, 2022
9e398f6
Merge remote-tracking branch 'origin/traduccion' into traduccion
any3l0 Jun 4, 2022
7bf106f
Revisión traducción V1_1
any3l0 Jun 4, 2022
89b8a31
Revisión traducción V1_2
any3l0 Jun 4, 2022
95e3dac
Revisión de la traducción de pandoc.yml
any3l0 Jun 5, 2022
0f1175b
Revisión de la traducción V1 playbook-defacement.md
any3l0 Jun 5, 2022
33be35a
Revisión de la traducción glossary.md
any3l0 Jun 5, 2022
73642ab
Revisión de la traducción playbook-ransomware.md
any3l0 Jun 5, 2022
25b275b
Revisión de la traducción playbook-supply-chain.md
any3l0 Jun 5, 2022
17ddd32
Revisión de la traducción de ROLES
any3l0 Jun 5, 2022
1052260
Revisión de la traducción PYMES --> SME y Formato a la tabla de about
any3l0 Jun 7, 2022
2002285
Update during.md
revilofe Jun 23, 2022
c926448
feat: añadir documentos desarrollados previamente
cromeoli Mar 30, 2024
dc4a713
feat: añadir preguntas (falta incluir esquema)
cromeoli Mar 30, 2024
4b5a882
feat: añadir playbooks base (a mejorar)
cromeoli Mar 30, 2024
5eb4aac
feat: añadir nomenclatura incidente
cromeoli Mar 30, 2024
7e72087
feat: variables base modificadas
cromeoli Mar 30, 2024
323b62e
Delete playbooks/playbook-identity-and-access.md
sergioguerrero94 Mar 31, 2024
ea6f3cd
Delete playbooks/playbook-supply-chain.md
sergioguerrero94 Mar 31, 2024
f36948f
Add files via upload
sergioguerrero94 Mar 31, 2024
f0d0f04
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
b508ea7
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
9e226b5
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
b979ff6
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
845face
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
1bd0229
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
41702e2
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
b47db2c
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
1ac501d
Update playbook-Supply-Chain.md
sergioguerrero94 Mar 31, 2024
1b1e896
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
e650bd1
Update playbook-Wipe-Disk.md
sergioguerrero94 Mar 31, 2024
f2ca870
Update playbook-Supply-Chain.md
sergioguerrero94 Mar 31, 2024
52f895d
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
25fa8a1
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
2a50e39
Update playbook-Wipe-Disk.md
sergioguerrero94 Mar 31, 2024
878d3ce
Update playbook-Supply-Chain.md
sergioguerrero94 Mar 31, 2024
2559f8a
Update playbook-Supply-Chain.md
sergioguerrero94 Mar 31, 2024
e3297b8
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
9f503b8
Update playbook-Wipe-Disk.md
sergioguerrero94 Mar 31, 2024
9aa1c34
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
2828547
Update playbook-Wipe-Disk.md
sergioguerrero94 Mar 31, 2024
75a029d
Update playbook-Supply-Chain.md
sergioguerrero94 Mar 31, 2024
a0869c8
Update playbook-Wipe-Disk.md
sergioguerrero94 Mar 31, 2024
f67f00a
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
7394e15
Update 3.a.md
sergioguerrero94 Mar 31, 2024
115e07e
Update 3.a.md
sergioguerrero94 Mar 31, 2024
8361c30
Delete playbooks/playbook-phishing.md
JMCumbrera Mar 31, 2024
7f88a0f
Añadidos Playbooks
JMCumbrera Mar 31, 2024
8a15d62
Update index.md
sergioguerrero94 Mar 31, 2024
f2a2d5d
Update index.md
sergioguerrero94 Mar 31, 2024
ff13486
añadir archivo tarea y nombrar incidente bien
cromeoli Mar 31, 2024
5a3a4e3
Merge branch '2024-4.1-G3' of github.com:IES-Rafael-Alberti/incident-…
cromeoli Mar 31, 2024
cafe715
Añadido playbook de fuerza bruta
JMCumbrera Mar 31, 2024
4e78856
Update index.md
JMCumbrera Mar 31, 2024
f64bcdf
Update playbook-brute force.md
JMCumbrera Mar 31, 2024
ccd6809
Update info.yml
sergioguerrero94 Mar 31, 2024
9aecab4
solventados la mayoria de TODOs de plan de respuesta
cromeoli Mar 31, 2024
809417d
Update plan.md
JMCumbrera Mar 31, 2024
5e3da3d
Update plan.md
JMCumbrera Mar 31, 2024
1324464
feat: modificar playbook DDoS
cromeoli Mar 31, 2024
bc82569
Merge branch '2024-4.1-G3' of github.com:IES-Rafael-Alberti/incident-…
cromeoli Mar 31, 2024
b57dbc4
Update 3.a.md
sergioguerrero94 Mar 31, 2024
8c3b277
Update 3.a.md
sergioguerrero94 Mar 31, 2024
4c99c60
feat: 1.b terminada
cromeoli Mar 31, 2024
639017d
upgrade: mejora pregunta 1.b
cromeoli Mar 31, 2024
7b3c2a9
Merge branch '2024-4.1-G3' of github.com:IES-Rafael-Alberti/incident-…
cromeoli Mar 31, 2024
8d54c8c
Create hello.md
sergioguerrero94 Mar 31, 2024
d5965d2
Add files via upload
sergioguerrero94 Mar 31, 2024
15a3d36
Delete imagenes/hello.md
sergioguerrero94 Mar 31, 2024
8818280
Update 2.a.md
sergioguerrero94 Mar 31, 2024
261eed7
Update 2.a.md
sergioguerrero94 Mar 31, 2024
624d663
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
1a9a76a
Update playbook-Identity-and-Access.md
sergioguerrero94 Mar 31, 2024
81782c7
Update playbook-Supply-Chain.md
sergioguerrero94 Mar 31, 2024
ae6e163
Update playbook-Wipe-Disk.md
sergioguerrero94 Mar 31, 2024
59e6871
Update index.md
sergioguerrero94 Mar 31, 2024
8ffaeef
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
651b7c3
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
814297a
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
0f7bda7
Update 1.c.md
JMCumbrera Mar 31, 2024
6f448b2
pregunta 1.a y cambios de estructura directorios
cromeoli Mar 31, 2024
b160b5b
Delete imagenes/diagrama-de-flujo.drawio.png
sergioguerrero94 Mar 31, 2024
5516472
Add files via upload
sergioguerrero94 Mar 31, 2024
0f609a7
Update 2.a.md
sergioguerrero94 Mar 31, 2024
37636da
Delete imagenes/Diagrama de toma de decisiones y escalado.drawio.png
sergioguerrero94 Mar 31, 2024
1fa5de3
Add files via upload
sergioguerrero94 Mar 31, 2024
dee39c4
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
67eab73
plan añadido
cromeoli Mar 31, 2024
474da3e
Update index.md
sergioguerrero94 Mar 31, 2024
abec5cf
Update plan.md
sergioguerrero94 Mar 31, 2024
6f7415a
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
ee659b8
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
d578fb8
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
e08a32d
Update IS-4.01-G3.md
sergioguerrero94 Mar 31, 2024
de02a8d
Update playbook-Create-or-Modify-System-Process.md
sergioguerrero94 Mar 31, 2024
96f05c7
Update IS-4.01-G3.md
JMCumbrera Mar 31, 2024
d7372fc
Delete imagenes/Diagrama de toma de decisiones y escalado.drawio.png
sergioguerrero94 Mar 31, 2024
85a8d8e
Add files via upload
sergioguerrero94 Mar 31, 2024
3bb570f
Update IS-4.01-G3.md
JMCumbrera Mar 31, 2024
4af3909
Delete imagenes/Diagrama de toma de decisiones y escalado.drawio.png
sergioguerrero94 Apr 2, 2024
d63253c
Add files via upload
sergioguerrero94 Apr 2, 2024
9600880
Update playbook-Supply-Chain.md
sergioguerrero94 Apr 2, 2024
8619f9c
Update playbook-Wipe-Disk.md
sergioguerrero94 Apr 2, 2024
2af248d
Update playbook-Wipe-Disk.md
sergioguerrero94 Apr 2, 2024
f6c5365
style: cambios en documento principal
cromeoli Apr 2, 2024
9288f5b
mejoras
cromeoli Apr 2, 2024
91b73e4
IS-P02-CRO
cromeoli Apr 21, 2024
befde49
Add files via upload
cromeoli Apr 21, 2024
da593fd
corregidas imagenes IS-P02-CRO
cromeoli Apr 21, 2024
a960908
Añadido trabajo IS-4.2-JCL.md
JMCumbrera Apr 27, 2024
621f506
Create readme.txt
sergioguerrero94 Apr 28, 2024
e62d7fe
Add files via upload
sergioguerrero94 Apr 28, 2024
47365db
Delete IS-4.2-SGM/img directory
sergioguerrero94 Apr 28, 2024
b204a86
Add files via upload
sergioguerrero94 Apr 28, 2024
82436ab
Add files via upload
sergioguerrero94 Apr 28, 2024
3487c5a
Add files via upload
sergioguerrero94 Apr 28, 2024
87d6310
Add files via upload
sergioguerrero94 Apr 28, 2024
27b23fc
Add files via upload
sergioguerrero94 Apr 28, 2024
951c25f
Add files via upload
sergioguerrero94 Apr 28, 2024
503fb16
Add files via upload
sergioguerrero94 Apr 28, 2024
93803e5
Update IS-4.2-SGM.md
sergioguerrero94 Apr 28, 2024
a730271
Update IS-4.2-SGM.md
sergioguerrero94 Apr 28, 2024
a4ebcf9
Update IS-4.2-SGM.md
sergioguerrero94 Apr 28, 2024
3b398d0
Update IS-4.2-SGM.md
sergioguerrero94 Apr 28, 2024
a262f1f
Delete IS-4.2-SGM.md
sergioguerrero94 Apr 28, 2024
7cc7aec
Add files via upload
sergioguerrero94 Apr 28, 2024
1ace3ed
Update and rename IS-4.2-SGM.md to IS-4.02-SGM.md
sergioguerrero94 Apr 28, 2024
54a8c33
Update IS-4.02-SGM.md
sergioguerrero94 Apr 28, 2024
fce18cc
Update IS-4.02-SGM.md
sergioguerrero94 Apr 28, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
197 changes: 197 additions & 0 deletions IS-4.01-G3.md

Large diffs are not rendered by default.

720 changes: 720 additions & 0 deletions IS-4.02-SGM.md

Large diffs are not rendered by default.

701 changes: 701 additions & 0 deletions IS-4.2-JCL.md

Large diffs are not rendered by default.

808 changes: 808 additions & 0 deletions IS-P02-CRO.md

Large diffs are not rendered by default.

234 changes: 117 additions & 117 deletions README.md

Large diffs are not rendered by default.

76 changes: 40 additions & 36 deletions about.md
Original file line number Diff line number Diff line change
@@ -1,36 +1,40 @@
# About

This template was developed by the team at [Counteractive Security](https://www.counteractive.net), to help all organizations get a good start on a concise, directive, specific, flexible, and free incident response plan. Build a [plan you will actually use](https://www.counteractive.net/posts/an-ir-plan-you-will-use/) to respond effectively, minimize cost and impact, and get back to business as soon as possible.

## License

This template is provided under the Apache License, version 2.0. You can view the source code for this plan at https://github.com/counteractive.

## Instructions

Customize this plan template for your own organization. Instructions are available in the project's [README](https://github.com/counteractive). For professional assistance with incident response, or with customizing, implementing, or testing your plan, please contact us by [email](mailto:support@counteractive.net) or [phone](tel:+18889255765).

## References and Additional Reading

* [NIST Computer Security Incident Handling Guide](http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf) (NIST)
* [CERT Societe Generale Incident Response Methodologies](https://github.com/certsocietegenerale/IRM/tree/master/EN)
* [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)
* [Incident Handler's Handbook](https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901) (SANS)
* [Responding to IT Security Incidents](https://technet.microsoft.com/en-us/library/cc700825.aspx) (Microsoft)
* [Defining Incident Management Processes for CSIRTs: A Work in Progress](http://resources.sei.cmu.edu/library/asset-view.cfm?assetid=7153) (CMU)
* [Creating and Managing Computer Security Incident Handling Teams (CSIRTS)](https://www.first.org/conference/2008/papers/killcrece-georgia-slides.pdf) (CERT)
* [Incident Management for Operations](http://shop.oreilly.com/product/0636920036159.do) (Rob Schnepp, Ron Vidal, Chris Hawley)
* [_Incident Response & Computer Forensics, Third Edition_](http://a.co/cUkFzMh) (Jason Luttgens. Matthew Pepe. Kevin Mandia)
* [_Incident Response_](http://shop.oreilly.com/product/9780596001308.do) (Kenneth R. van Wyk, Richard Forno)
* [The Checklist Manifesto](http://atulgawande.com/book/the-checklist-manifesto/) (Atul Gawande)
* [The Field Guide to Understanding Human Error](https://www.amazon.com/Field-Guide-Understanding-Human-Error/dp/0754648265) (Sidney Dekker)
* [Normal Accidents: Living with High-Risk Technologies](https://www.amazon.com/Normal-Accidents-Living-High-Risk-Technologies/dp/0691004129) (Charles Perrow)
* [Site Reliability Engineering](https://landing.google.com/sre/book.html) (Google)
* [Debriefing Facilitation Guide](http://extfiles.etsy.com/DebriefingFacilitationGuide.pdf) (Etsy)
* [Every Minute Counts: Leading Heroku's Incident Response](https://www.heavybit.com/library/video/every-minute-counts-coordinating-herokus-incident-response/) (Blake Gentry)
* [Three Analytical Traps in Accident Investigation](https://www.youtube.com/watch?v=TqaFT-0cY7U) (Dr. Johan Bergström)
* [US National Incident Management System (NIMS)](https://www.fema.gov/national-incident-management-system) (FEMA)
* [Informed's NIMS Incident Command System Field Guide](https://www.amazon.com/gp/product/1284038408) (Michael J. Ward)
* [Advanced PostMortem Fu and Human Error 101 (Velocity 2011)](http://www.slideshare.net/jallspaw/advanced-postmortem-fu-and-human-error-101-velocity-2011)
* [Blame. Language. Sharing.](http://fractio.nl/2015/10/30/blame-language-sharing/)


# Acerca de

Esta plantilla ha sido creada por el equipo de [Counteractive Security](https://www.counteractive.net), para ayudar a todas las organizaciones a comenzar de forma concisa, directa, especifica, flexible y gratuita un plan de respuesta de incidentes. crea un plan [que utilizaras](https://www.counteractive.net/posts/an-ir-plan-you-will-use/) para responder de manera eficiente, minimizando los costes e impactos, para volver a trabajar lo mas rapido posible.


## Licencia

Esta plantilla esta proporcionado bajo la licencia de apache, version 2.0. puedes ver el codigo fuente en https://github.com/counteractive.


## Instrucciones

Personaliza esta plantilla para tu organizacion. Las instrucciones estan disponibles en el [README](https://github.com/counteractive) del projecto. Para asistencia profesional con respuestas de incidentes, o con customizacion, implementacion, o testeo de tu plan, porfavor contacta con nosotros por [email](mailto:support@counteractive.net) o [telefono](tel:+18889255765).


## Referencias y material adicional

* [NIST Computer Security Incident Handling Guide](http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf) (NIST)
* [CERT Societe Generale Incident Response Methodologies](https://github.com/certsocietegenerale/IRM/tree/master/EN)
* [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)
* [Incident Handler's Handbook](https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901) (SANS)
* [Responding to IT Security Incidents](https://technet.microsoft.com/en-us/library/cc700825.aspx) (Microsoft)
* [Defining Incident Management Processes for CSIRTs: A Work in Progress](http://resources.sei.cmu.edu/library/asset-view.cfm?assetid=7153) (CMU)
* [Creating and Managing Computer Security Incident Handling Teams (CSIRTS)](https://www.first.org/conference/2008/papers/killcrece-georgia-slides.pdf) (CERT)
* [Incident Management for Operations](http://shop.oreilly.com/product/0636920036159.do) (Rob Schnepp, Ron Vidal, Chris Hawley)
* [_Incident Response & Computer Forensics, Third Edition_](http://a.co/cUkFzMh) (Jason Luttgens. Matthew Pepe. Kevin Mandia)
* [_Incident Response_](http://shop.oreilly.com/product/9780596001308.do) (Kenneth R. van Wyk, Richard Forno)
* [The Checklist Manifesto](http://atulgawande.com/book/the-checklist-manifesto/) (Atul Gawande)
* [The Field Guide to Understanding Human Error](https://www.amazon.com/Field-Guide-Understanding-Human-Error/dp/0754648265) (Sidney Dekker)
* [Normal Accidents: Living with High-Risk Technologies](https://www.amazon.com/Normal-Accidents-Living-High-Risk-Technologies/dp/0691004129) (Charles Perrow)
* [Site Reliability Engineering](https://landing.google.com/sre/book.html) (Google)
* [Debriefing Facilitation Guide](http://extfiles.etsy.com/DebriefingFacilitationGuide.pdf) (Etsy)
* [Every Minute Counts: Leading Heroku's Incident Response](https://www.heavybit.com/library/video/every-minute-counts-coordinating-herokus-incident-response/) (Blake Gentry)
* [Three Analytical Traps in Accident Investigation](https://www.youtube.com/watch?v=TqaFT-0cY7U) (Dr. Johan Bergström)
* [US National Incident Management System (NIMS)](https://www.fema.gov/national-incident-management-system) (FEMA)
* [Informed's NIMS Incident Command System Field Guide](https://www.amazon.com/gp/product/1284038408) (Michael J. Ward)
* [Advanced PostMortem Fu and Human Error 101 (Velocity 2011)](http://www.slideshare.net/jallspaw/advanced-postmortem-fu-and-human-error-101-velocity-2011)
* [Blame. Language. Sharing.](http://fractio.nl/2015/10/30/blame-language-sharing/)

73 changes: 36 additions & 37 deletions after.md
Original file line number Diff line number Diff line change
@@ -1,37 +1,36 @@
# Conduct an After Action Review (AAR)

1. Schedule an After Action Review (AAR) meeting within {{AAR_SLA}} and invite the attendees listed at {{AAR_ATTENDEES}}. Always include the following:
* The incident commander.
* Service owners involved in the incident.
* Key engineer(s)/responders involved in the incident.
1. Designate an AAR owner who will investigate the incident in advance of the meeting to prepare, looking into the incident process itself including reviewing notes and reports.

## Conduct the AAR Meeting

Document answers to the following key questions:

1. **What happened?** Create a timeline, supported with data or other artifacts. **Avoid blame. Find facts.**
1. **What was supposed to happen?**
* Detail deviations from process, procedure, or best practice, including SME assessments.
* Identify ways the incident could have been detected sooner, or responded to more effectively
1. **What were the root causes?** Find root cause to things that happened and to things that should have happened.
1. **How can we improve?** Capture action items _with assignees and due dates_. Consider:
* Stop: what should we stop doing?
* Start: what should we start doing?
* Continue: what should we keep doing?

## Communicate AAR Status and Results

The AAR owner, in coordination with the Internal Liaison, will communicate the status of the AAR (see below)

### Status Descriptions

| Status | Description |
|-|-|
| **Draft** | AAR investigation is still ongoing |
| **In Review** | AAR investigation has been completed, and is ready to be reviewed during the AAR meeting. |
| **Reviewed** | AAR meeting is over and the content has been reviewed and agreed upon.<br>If there are additional "External Messages", the communications team will take action to prepare. |
| **Closed** | No further actions are needed on the AAR (outstanding issues are tracked in tickets).<br>If no "External Messages", skip straight to this once the meeting is over.<br>If there are additional "External Messages", communications team will update AAR Closed once sent. |

Communicate the results of the AAR internally and finalize the AAR documentation.

# Realizar una revisión posterior a la acción (Conduct an After Action Review, AAR)

1. Programe una reunión de revisión posterior a la acción (AAR) dentro de {{AAR_SLA}} e invite a los asistentes que figuran en {{AAR_ATTENDEES}}. Incluya siempre a los siguientes:
* El Incident Commander.
* Los propietarios de los servicios implicados en el incidente.
* Ingeniero(s)/responsable(s) clave(s) implicado(s) en el incidente.
1. Designe a un propietario del AAR que investigue el incidente antes de la reunión para prepararlo, estudiando el proceso del incidente en sí, incluyendo la revisión de notas e informes.

## Realización de la reunión AAR

Documente las respuestas a las siguientes preguntas clave:

1. **¿Qué ocurrió?** Cree una línea de tiempo, apoyada con datos u otros artefactos. **Evitar las culpas. Busca los hechos.**
1. **¿Qué se suponía que iba a ocurrir?**
* Detallar las desviaciones del proceso, el procedimiento o las mejores prácticas, incluidas las evaluaciones de los SME.
* Identifique las formas en que el incidente podría haberse detectado antes o haberse respondido con mayor eficacia.
1. **¿Cuáles fueron las causas fundamentales?** Encuentre la raíz de lo que ocurrió y de lo que debería haber ocurrido.
1. **¿Cómo podemos mejorar?** Capture los elementos de acción con asignados y fechas de vencimiento. Considerar:
* Detener: ¿Qué debemos dejar de hacer?
* Empezar: ¿Qué deberíamos empezar a hacer?
* Continuar: ¿Qué debemos seguir haciendo?

## Comunicar el estado y los resultados del AAR

El propietario del informe, en coordinación con el enlace interno, comunicará el estado del informe (véase más abajo).

### Descripciones de estado

| Estado | Descripción |
|-----------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Borrador** | La investigación de la AAR sigue en curso |
| **En revisión** | La investigación AAR se ha completado, y está lista para ser revisada durante la reunión AAR. |
| **Revisado** | La reunión de AAR ha terminado y el contenido ha sido revisado y acordado. <br/>Si hay "Mensajes externos" adicionales, el equipo de comunicación tomará medidas para prepararlos. |
| **Cerrado** | No es necesario realizar más acciones en el AAR (los problemas pendientes se rastrean en los tickets).<br>Si no hay "Mensajes Externos", pase directamente a esto una vez que la reunión haya terminado.<br/>Si hay "Mensajes Externos" adicionales, el equipo de comunicaciones actualizará el AAR Cerrado una vez enviado. |

Comunicar internamente los resultados del AAR y finalizar la documentación del AAR.
Binary file added documentosEmpresa/IS-1.a.02-G3.docx-1.pdf
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.