Module 7: Post-incident learning#

Theme#

Post-incident learning

Essential Question#

How does the system improve after response?

Module Components#

  • Book prose: conceptual framing, domain scenario, methods, and failure modes

  • Assignment: evidence-backed production of a specific artifact

  • Slides: presentation sequence for seminar or lecture delivery

  • Narration: spoken version of the slide flow

  • Rubric: criteria for evaluating the module artifact

  • Notebook: executable lab aligned with the module theme using synthetic incident records with severity, confidence, blast radius, containment option, and approval outcome

Module Artifact#

automated response playbook with approval gates, rollback plan, and post-incident learning loop focused on post-incident learning: Write a postmortem and update workflow.

Professional Setting#

Students work as if advising an incident response team deciding which containment actions can be automated safely. Their work must be intelligible to incident commander, security engineer, legal/compliance reviewer, and affected service owner.

Use This Module in Order#

  1. Read the learning chapter.

  2. Review the slide deck with the matching narration.

  3. In Populi, open the private student-repository link for this course and enter modules/module-7.

  4. Clone the repository once or open its Codespace/Colab copy; run lab.ipynb and complete exercise.ipynb there.

  5. Self-check with the rubric, commit and push the work, then submit exactly what Populi requests.