Home

This documentation covers parts of the RealSelf Incident Response process. It provides information not only on preparing for an incident, but also what to do during and after. It is intended to be used by on-call practitioners and those involved in an operational incident response process (or those wishing to enact a formal incident response process). See the about page for more information on what this documentation is and why it exists.
Don't know where to start?
If you're new to incident response and don't yet have a formal process in your organization, we recommend looking at our Getting Started page for a quick list of things you can do to begin.
Before an Incident#
Reading material for things you probably want to know before an incident occurs. You likely don't want to be reading these during an actual incident.
- Severity Levels - Information on our severity level classification. What constitutes a P2 vs P0? What response do they get?
During an Incident#
Information and processes during a major incident.
- During an Incident - Information on what to do during an incident, and how to constructively contribute.
- Security Incident Response - Security incidents are handled differently to normal operational incidents.
After an Incident#
Our followup processes, how we make sure we don't repeat mistakes and are always improving.
- After an Incident - Information on what to do after an incident is resolved.
- Post-Mortem Process - Information on our post-mortem process; what's involved and how to write or run a post-mortem.
- Post-Mortem Template - The template we use for writing our post-mortems for major incidents.
- Effective Post-Mortems - A guide for writing effective post-mortems.
Additional Resources#
Useful material and resources from external parties that are relevant to incident response.
- Reading - Recommended reading material relevant to incident response.