An incident happens in an area you deliberately deferred. The not-doing entry exists, with its reasoning and its trigger. That conversation still has to be had, and how it goes depends almost entirely on what was written down beforehand.
Two versions of the same situation
| Undocumented | Documented with a trigger | |
|---|---|---|
| The question asked | Why was this not done? | Has the trigger been met? |
| What you produce | A recollection of a conversation | A dated entry naming the reasoning |
| What it looks like | An oversight being explained | A decision being revisited |
| Who it reflects on | You, personally | A process, which is what should be examined |
| What happens next | A reactive commitment to do everything | A specific reassessment of one item |
Holding the position, or changing it
- Check the trigger honestly, first. If the circumstances that made the deferral reasonable have changed, the entry has done its job and the answer is now different. Say so.
- If the trigger has not been met, the reasoning stands. An incident is evidence about the world, not automatically evidence that the reasoning was wrong. Deferring DNSSEC because the team cannot operate it is not refuted by a phishing campaign.
- Distinguish “would this have helped” from “was this the right call”. The four surfaces answer the first in seconds, and the answer is frequently no — the deferred control was on a different surface entirely.
- Do not concede a control that would not have helped. Agreeing to deploy something irrelevant to quiet a room spends budget and attention on the wrong surface, and the next incident will be in the same place.
The conversation, worked
"We were phished through a lookalike domain. Why hasn't this company deployed DNSSEC?" DNSSEC is an integrity control — it stops somebody forging answers for our zone. The attacker registered their own domain and published correct records for it. DNSSEC on our zone could not have affected that. What addresses this is detection and takedown, which is item 4 in the 90-day plan, and it found this domain on day two. The gap was that nobody was resourced to work the queue — which is the entry on the not-doing list, with the trigger "the internal queue is being worked and is the constraint". That trigger has now been met.
The four surfaces are the tool for this conversation
Name the surface the attack targeted, name the surface the deferred control defends, and the question answers itself. It is faster than arguing, it is checkable, and it moves the discussion to the control that actually would have helped — which is the outcome worth having.