cyber:IncidentResponseLessonLearnedCategoryCodeSimpleType

Code Value Definition
Lesson Learned DefenseAn improvement that can be made to lower the mean time to defense
Lesson Learned Defensive MeasuresA defensive measure that can be implemented to prevent similar incidents
Lesson Learned Discovery MethodAn improvement that can be made to lower the mean time to detection
Lesson Learned Effective Analysis ImprovementAn improvement that can be made to lower the mean time to effective analysis
Lesson Learned Future Watch IndicatorA precursor or indicator that should be watched for in the future to detect similar incidents
Lesson Learned Information HandlingAn improvement that can be made to the incident handling process
Lesson Learned Information NeedsInformation that could help with an incident, if provided in a timely manner
Lesson Learned Information SharingAn improvement that can be made to the information sharing process
Lesson Learned Information SourceA source of information that could help with an incident
Lesson Learned ReportingAn improvement that can be made to lower the mean time to reporting
Lesson Learned Resource NeedAn additional tool or resource that are needed to detect, analyze, and mitigate future incidents
Lesson Learned ResponseAn improvement that can be made to lower the mean time to response