Skip to content

Pauldoom/ir checklist reboot#418

Merged
pauldoomgov merged 7 commits intomainfrom
pauldoom/ir-checklist-reboot
Apr 20, 2023
Merged

Pauldoom/ir checklist reboot#418
pauldoomgov merged 7 commits intomainfrom
pauldoom/ir-checklist-reboot

Conversation

@pauldoomgov
Copy link
Copy Markdown
Contributor

This is part 1 of a N part refinement of the checklist and IR guide.

The main purpose here: Restructure the checklist to allow each role holder to focus on their responsibilities.

Copy link
Copy Markdown
Contributor

@zachmargolis zachmargolis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM


### Executive On-Call

* Notified by the @login-executive-oncall Slack handle
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Notified by the @login-executive-oncall Slack handle
* Notified by the `@login-executive-oncall` Slack handle

* Check in with Situation Lead if incident is active
* Use [emergency contact process]({% link _articles/secops-incident-response-guide.md %}#emergency-contact-process) to pull in responders if a situation has not been declared
* NOT acting as Login.gov Situation Lead
* Partner situation room joined
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

everything else is present tense? maybe we switch this around for consistency?

Suggested change
* Partner situation room joined
* Joins partner situation room (or equivalent)

Find and follow your appropriate role checklist. Checklists are intentionally terse
with links to supporting process and information where needed.

These additional roles are external to and highly engaged with responders in the situation room:
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

commas to help with emphasis

Suggested change
These additional roles are external to and highly engaged with responders in the situation room:
These additional roles are external to, and highly engaged with, responders in the situation room:

*Mitigate* (Continous)
* [Technical context shared]({% link _articles/secops-incident-response-guide.md %}#sharing-technical-context) with responders in room
* [Incident Response Runbooks](https://github.com/18F/identity-devops/wiki/Incident-Response-Runbooks) used where appropriate and steps executed
* Parallel lines of investigation and mitigation to delegate to [other responders](#responder)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add a verb here?

Suggested change
* Parallel lines of investigation and mitigation to delegate to [other responders](#responder)
* Creates parallel lines of investigation and mitigation to delegate to [other responders](#responder)

@pauldoomgov pauldoomgov merged commit 0395444 into main Apr 20, 2023
@pauldoomgov pauldoomgov deleted the pauldoom/ir-checklist-reboot branch April 20, 2023 19:55
@aduth aduth mentioned this pull request Dec 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants