Which of the following BEST describes the purpose of an after-action report (AAR) following an incident?
-
A
To prosecute the attacker
-
B
To document findings and recommend improvements to the IR process
-
C
To restore systems from backup
-
D
To notify regulators of the breach