After-Action Reviews: Feeding Security Incidents Back into Your RMF Package
Updated: 2 days ago
A door held open, a credential misused, a camera outage during an alarm event: every security incident is a live test of the assumptions in your risk assessment. Most organizations close the incident and file it. The mature ones run a structured after-action review (AAR) and feed the results directly back into their Risk Management Framework (RMF) artifacts. Blue Violet Security, LLC (BVS) helps facilities turn incident response into continuous improvement, so the authorization package reflects how the system actually behaves, not how it behaved on paper the day it was fielded.
What an AAR Should Produce
A useful AAR answers four questions with evidence:
What actually happened? A single merged timeline from PACS events, video, alarm data, and human reporting, not competing narratives.
What did each control do? Which controls detected, delayed, and responded as designed, and which did not.
What did the response cost? Time to detect, time to respond, and points where the procedure stalled.
What changes as a result? Specific, assigned, dated actions, not a general commitment to vigilance.
Closing the Loop into RMF
The answers above map directly onto RMF outputs. In Step 6, the assessment and authorization phase, a documented AAR process is itself evidence that the organization takes assessment seriously. In Step 7, continuous monitoring, incident-driven AARs are among the strongest signals an Authorizing Official (AO) can see:
Updated risk assessments reflecting observed adversary behavior, not just hypothesized scenarios.
POA&M entries for control gaps the incident exposed, with milestones the incident makes credible.
Control enhancement recommendations where the baseline proved insufficient.
Lessons-learned documentation that demonstrates organizational learning to future assessors.
Where AARs Go Wrong
The common failure is blame. An AAR that becomes a disciplinary exercise stops producing truth, and without truth, the RMF updates are fiction. The second failure is scope: reviewing only the responder's actions while skipping the system architecture that made the response necessary. The third is no owner: findings without an assigned owner and date decay into a binder of good intentions.
Recommendations
Stand up a standing AAR template: merged timeline, control-by-control performance, cost of response, assigned actions.
Run the AAR on near misses, not just losses. A tailgating event that failed quietly is a free lesson.
Route every AAR output into the risk register, the POA&M, or a documented reason not to.
Trend AAR findings quarterly to catch systemic weaknesses.
Schedule a Consultation with Blue Violet Security to build an AAR process that strengthens your authorization posture with every incident.
This content is provided for general informational purposes only and does not constitute legal or regulatory advice. Compliance requirements and regulations are subject to change. Blue Violet Security, LLC recommends consulting with appropriate legal and regulatory counsel before making compliance determinations.



Comments