# Manage an incident from detection to recovery

Taiga Learning · Worksheet
https://taiga.training/en/lessons/incident-management/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Assign incident coordination, technical work, and communication.
- Choose containment from impact and available evidence.
- Separate restored service from completed follow-up work.

## Exercise
Use the fictional incident timeline in this lesson. Write the first situation update, name three response roles, and define two recovery checks. Identify one action that needs a security-response decision.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
During an incident, coordinate decisions and reduce harm. After recovery, verify corrective work against the observed failure.

## Sources
- [Google SRE: Incident Response](https://sre.google/workbook/incident-response/)
- [Google SRE: Postmortem Culture](https://sre.google/workbook/postmortem-culture/)
- [NIST: Incident Response Recommendations, SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final)

This worksheet supports learning. Completing it does not itself authorize a production change.
