Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: After Action Review SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
After Action Review

I recently read an article from the Harvard Business Review Learning in the Thick of It that discussed the value of an After Action Review (AAR). It describes ways the US Army has used these intentional exercises to improve in future missions. As outlined in the article, an AAR is “a method for extracting lessons from one event or project and applying them to others.”

I continue to benefit from applying this practice regularly and have written about this concept before in the below Diary posts. 

   An Occasional Look in the Rear View Mirror

   Get Wisdom as Cheaply as You Can

I believe this practice if followed, can serve as a benefit and not a burden. I find these most successful when everyone actively participates intending to make the next time be the best time. Specific actions that can be used when applying this concept in your organization include

  • ”Lessons must first and foremost benefit the team that extracts them. 
  • The AAR process must start at the beginning of the activity. 
  • Lessons must explicitly link to future actions. 
  • And leaders must hold everyone, especially themselves, accountable for learning.”

In what project can you apply the practice of an After Action Review next week? Engage with us in the comments section below!


Russell Eubanks

ISC Handler


I will be teaching next: Leading Cybersecurity Change: Building a Security-Based Culture - SANS London December 2021


100 Posts
ISC Handler
Feb 8th 2020
This is similar to an RCA which is a key component of the ITIL processes. Most mature IT organizations should have this process.

1 Posts
In addition to the standard question in an AAR. I have started adding this one "What do we know now that we didn't when we started." It seems to help identify all of the unknown-unknown that discovered along the way and now seem obvious.

2 Posts

Sign Up for Free or Log In to start participating in the conversation!