4. Timeline
The timeline of a CoE describes what happened when and who did what. It should answer most questions:
When was the problem first discovered, and how?
Who noticed or reported the problem first to us?
Who engaged in the incident, and helped recover from the failure?
When was the failure resolved?
What indicators did we use to prove it was resolved?
How did we prove that the failure was resolved?
The more accurate and specific the timeline the better. There are often process failures during the incident response itself which should be assessed and learned from. In many cases, a failure might have been responded to or fixed more quickly, had we known about the exact nature of the problem sooner - therefore the alerts we received, and the actions we took discovering and analysing the nature of the problem, are just as important as those around the cause of the failure itself.