CySA+ v4 · Objective 4.2

Incident reporting and handover

Communicate an incident clearly across audiences and shifts, preserving operational security, decision ownership, and measurable lessons.

What you will be able to do

  • Write an incident update that separates facts, uncertainty, impact, and the next decision.
  • Select stakeholders and approved communication paths for sensitive incident information.
  • Produce an actionable handover with accepted ownership and pending tasks.
  • Define operational metrics and convert post-incident findings into validated improvements.

Learn the concepts

  1. Lesson 1

    Tell the right people what they need to decide

    Communication is part of response, not a report written after the technical work finishes. A good update gives its audience enough reliable information to make the next decision without exposing unnecessary incident detail.

    Open lesson →
  2. Lesson 2

    Carry the incident across shifts and into improvement

    An incident can lose momentum when people change shifts or when service restoration removes the immediate pressure. Structured handover and carefully defined measures keep unfinished work visible and make learning actionable.

    Open lesson →

Apply your judgement · Synthetic scenario

The shift change before service release

A fictional housing association is responding to unauthorised access to its repair scheduling service. The evening team is about to leave, and a director wants a concise update. Technical restoration is ready, but an identity review and release approval remain open.

Confirmed scope
Two staff accounts used without authorisation; one scheduling service affected.
Uncertainty
Resident-record access review incomplete; no supported conclusion about disclosure yet.
Current controls
Affected accounts suspended and sessions revoked; replacement service remains restricted.
Pending work
Identity permission review due 19:00; service-owner release approval pending; next executive update 19:30.
Metric proposal
Analyst proposes reporting the incident resolved because the replacement server started successfully.

Your task

  1. Write a concise executive update with a clear uncertainty statement.
  2. Produce the three most important handover items and ownership acknowledgements.
  3. Explain why the proposed resolution metric is premature.
Compare your response

Two staff accounts accessed the scheduling service without authorisation and have been contained. The service remains restricted while access review and release checks finish; resident-data disclosure is still being assessed. Confirm support for continued restricted operation and provide the next update at 19:30.

The incoming lead accepts incident ownership; the identity analyst accepts the permission review and 19:00 check; the service owner and response lead retain the documented release decision. Link the evidence record, existing controls, pending impact assessment, and escalation path if either checkpoint slips.

Starting the replacement is an operational milestone, not verified remediation, authorised release, or administrative closure. Record the actual milestone and leave the incident open. Report each interval using its agreed boundaries and retain the unresolved identity and impact tasks.

Check your understanding

Choose the best response to each scenario, then check your reasoning. These are course practice questions.

1. A customer-facing update is due, but the impact review cannot yet establish whether records were disclosed. Which approach is most appropriate?
2. The outgoing analyst sends a long chat transcript containing several contradictory status messages. What would most improve the handover?
3. A team reports faster mean closure time after excluding every incident still open at month end. What should a reviewer request?

0 of 3 answered

Source reading: supplied book, chapters 12. Lessons, scenarios, and questions are original CyberCorps course material.