So, I discovered my presentation on #SIEM from 2012 where I talked about "SIEM trifecta of complexity" which is "complexity of deployment, administration, operation." Guess what? Much of 2020 SIEM has this too....
Why can't we have "blameless post-mortems" in security? #question
To me, however, this does NOT mean that gross incompetence should not be found, blamed and punished. Just that the post-mortem analysis process needs to be run blamelessly (am I off here?)
BTW (and please correct me if I am off here), I trace the origin of "blameless postmortem" concept to this: landing.google.com/sre/sre-book/c…