SlideShare une entreprise Scribd logo
1  sur  26
It’s an Incident Dr. Watson 
© HDI 2014. All Rights Reserved 
Developed by Rick Joslin 
HDI Executive Director, Certification & Training 
rjoslin@thinkhdi.com
The Facts and Nothing but the Facts 
2
Follow the Evidence 
3
Initial Response 
Arrive at the Scene (Take the call) 
4
Classification 
• What type of crime? 
• Whose jurisdiction? 
• What is the priority? 
• What is the severity? 
• Is this a known 
problem? 
5
Initial Response 
• Safety 
• Emergency 
Care 
• Establish 
Control 
6
Secure the Scene 
• No more changes 
7
Record Evidence 
• Document the symptoms 
8
Collect Evidence 
• Listen to the customer 
9
Interview Witnesses 
• Ask their name 
• Use empathy skills 
• Begin with open 
ended questions 
• Use their name 
• Paraphrase for 
understanding 
10
Record the Data 
• Who? 
• What? 
• When? 
• Where? 
• How? 
• Why? 
You don’t know what 
might be important. 
11
Seek to Understand What We Know 
• Search the Knowledge Base 
12
Ask Clarifying Questions 
• Use closed ended 
questions 
• Confirm what you 
heard 
• Get another 
perspective 
13
Analyze the Evidence 
• Search the 
Knowledge 
Base again 
14
Return to the Scene 
• Get a closer 
look at the 
evidence 
• Verify the 
evidence and 
witness 
statements 
15
Consider Possible Motives 
• Establish a list of 
possible causes 
16
Test the Most Probable Causes 
• Consider frequency 
of occurrence and 
the cost of the test 
• Don’t overlook the 
simple stuff 
17
Call Your Backup - Get Help 
• Escalate per the service level agreement 
18
Resolve and Recover 
• Emergency Care 
comes first 
• Stop the pain 
• Get the customer 
back to work 
19
Incident Closure 
• Confirm 
Resolution 
• Capture or 
Update the 
Knowledge 
• Document 
Actions 
20
Incident Ownership 
• Monitor, track, and communicate status 
21
The CSI Way 
1. Initial Response: 
Touch nothing, Observe and Listen 
2. Secure and Document: 
Touch nothing, Record observations 
3. Collect Evidence: Bag it and Tag it 
4. Interview Witnesses: Question and Record 
5. Analyze Evidence: Identify and Eliminate 
Record all data and actions 
22
CSI: A Guide for Law Enforcement 
Initial Response/Prioritization of Efforts 
1. Receipt of Information 
2. Safety Procedures 
3. Emergency Care 
4. Secure and Control Persons at the Scene 
5. Boundaries: Identify Establish, Protect, and 
Secure 
6. Turn over Control of the Scene and Brief 
Investigators 
7. Document Actions and Observations 
Source: January 2000 by the US Attorney General 
23
Kepner-Trego’s Problem Analysis 
A.K.A. The KT Process 
1. Define the Problem 
2. Describe the Problem 
3. Establish possible causes 
4. Test the most probable cause 
5. Verify the true cause 
24
ITIL® Incident Management Process 
1. Incident Detection and Recording 
2. Classification and Initial Support 
3. Investigation and Diagnosis 
4. Resolution and Recover 
5. Incident Closure 
6. Incident Ownership 
25
© HDI 2014. All Rights Reserved 
Thank you for attending this session. 
Please fill out a session evaluation form. 
Contact details: 
Rick Joslin 
HDI 
Executive Director, Certification & Training 
rick.joslin@ubm.com 
(412) 841-9793

Contenu connexe

En vedette

Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar
Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar
Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar Redbourn Business Systems
 
Halo walking on sunshine
Halo walking on sunshineHalo walking on sunshine
Halo walking on sunshineMickey1549
 
Partnership and open data as enablers of INSPIREd innovative services
Partnership and open data as enablers of INSPIREd innovative servicesPartnership and open data as enablers of INSPIREd innovative services
Partnership and open data as enablers of INSPIREd innovative servicessmespire
 
1 three partitioned-model_unifi_cnr
1 three partitioned-model_unifi_cnr1 three partitioned-model_unifi_cnr
1 three partitioned-model_unifi_cnrAle Cignetti
 
Supporting your Child with Literacy and Numeracy, October 2012
Supporting your Child with Literacy and Numeracy, October 2012Supporting your Child with Literacy and Numeracy, October 2012
Supporting your Child with Literacy and Numeracy, October 2012avgee
 
Brigada cu destinaţie specială
Brigada cu destinaţie specialăBrigada cu destinaţie specială
Brigada cu destinaţie specialăBargan Ivan
 
I can i can't
I can i can't I can i can't
I can i can't larinaea
 

En vedette (12)

Coca Cola
Coca ColaCoca Cola
Coca Cola
 
Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar
Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar
Mobile Your Data | AdvantageNFP | CHASE 2011 Seminar
 
Halo walking on sunshine
Halo walking on sunshineHalo walking on sunshine
Halo walking on sunshine
 
Partnership and open data as enablers of INSPIREd innovative services
Partnership and open data as enablers of INSPIREd innovative servicesPartnership and open data as enablers of INSPIREd innovative services
Partnership and open data as enablers of INSPIREd innovative services
 
1 three partitioned-model_unifi_cnr
1 three partitioned-model_unifi_cnr1 three partitioned-model_unifi_cnr
1 three partitioned-model_unifi_cnr
 
Supporting your Child with Literacy and Numeracy, October 2012
Supporting your Child with Literacy and Numeracy, October 2012Supporting your Child with Literacy and Numeracy, October 2012
Supporting your Child with Literacy and Numeracy, October 2012
 
Brigada cu destinaţie specială
Brigada cu destinaţie specialăBrigada cu destinaţie specială
Brigada cu destinaţie specială
 
I can i can't
I can i can't I can i can't
I can i can't
 
Tipografía
Tipografía Tipografía
Tipografía
 
Ruin of Rebellion
Ruin of RebellionRuin of Rebellion
Ruin of Rebellion
 
Pres projecte habitatge
Pres projecte habitatgePres projecte habitatge
Pres projecte habitatge
 
Assessment photo album
Assessment photo albumAssessment photo album
Assessment photo album
 

Similaire à Its an Incident Dr Watson

ACCA-IIA Singapore Seminar 2015 Part 5 Investigation
ACCA-IIA Singapore Seminar 2015 Part 5 InvestigationACCA-IIA Singapore Seminar 2015 Part 5 Investigation
ACCA-IIA Singapore Seminar 2015 Part 5 InvestigationBillyCheuk
 
How to Conduct a Bullet Proof Harassment Investigation
How to Conduct a Bullet Proof Harassment InvestigationHow to Conduct a Bullet Proof Harassment Investigation
How to Conduct a Bullet Proof Harassment InvestigationNow Dentons
 
Cyber Incident Response - When it happens, will you be ready?
Cyber Incident Response - When it happens, will you be ready?Cyber Incident Response - When it happens, will you be ready?
Cyber Incident Response - When it happens, will you be ready?Dan Michaluk
 
Incident investigation and Root Cause Analysis
Incident investigation and Root Cause AnalysisIncident investigation and Root Cause Analysis
Incident investigation and Root Cause AnalysisHeatherawarens
 
Conducting an Effective Internal Investigation
Conducting an Effective Internal InvestigationConducting an Effective Internal Investigation
Conducting an Effective Internal InvestigationParsons Behle & Latimer
 
fy14_sh-27638-sh4_Incident-Investigation.pptx
fy14_sh-27638-sh4_Incident-Investigation.pptxfy14_sh-27638-sh4_Incident-Investigation.pptx
fy14_sh-27638-sh4_Incident-Investigation.pptxRezi Purnama
 
Workplace Investigation 2012 Webinar
Workplace Investigation 2012 WebinarWorkplace Investigation 2012 Webinar
Workplace Investigation 2012 WebinarDrake International
 
Ethical & Practical Issues in Managing Internal Investigations
Ethical & Practical Issues in Managing Internal InvestigationsEthical & Practical Issues in Managing Internal Investigations
Ethical & Practical Issues in Managing Internal InvestigationsGowling WLG
 
Effective Fraud Investigations: 10 Keys to a Successful Outcome
Effective Fraud Investigations: 10 Keys to a Successful OutcomeEffective Fraud Investigations: 10 Keys to a Successful Outcome
Effective Fraud Investigations: 10 Keys to a Successful OutcomeCase IQ
 
Incident Investigation ASSE 2014
Incident Investigation ASSE 2014Incident Investigation ASSE 2014
Incident Investigation ASSE 2014John Newquist
 
Accident investigation BY Muhammad Fahad Ansari 12IEEM14
Accident investigation BY Muhammad Fahad Ansari 12IEEM14Accident investigation BY Muhammad Fahad Ansari 12IEEM14
Accident investigation BY Muhammad Fahad Ansari 12IEEM14fahadansari131
 
SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...
SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...
SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...Penelope Toth
 
Take Charge of Your Life - Personal & Professional (ICLEF)
Take Charge of Your Life - Personal & Professional (ICLEF)Take Charge of Your Life - Personal & Professional (ICLEF)
Take Charge of Your Life - Personal & Professional (ICLEF)Cynthia Sharp
 
Investigating Misconduct: Reaching a Decision and Determining Root Causes
Investigating Misconduct: Reaching a Decision and Determining Root CausesInvestigating Misconduct: Reaching a Decision and Determining Root Causes
Investigating Misconduct: Reaching a Decision and Determining Root CausesCase IQ
 
acci.invest.revised.ppt
acci.invest.revised.pptacci.invest.revised.ppt
acci.invest.revised.pptAldrienCabinte
 
Chapter 10 11_advocacy_during_hearing_abct_week_9
Chapter 10 11_advocacy_during_hearing_abct_week_9Chapter 10 11_advocacy_during_hearing_abct_week_9
Chapter 10 11_advocacy_during_hearing_abct_week_9Nyi Maw
 
Conducting an Effective Internal Investigation
Conducting an Effective Internal InvestigationConducting an Effective Internal Investigation
Conducting an Effective Internal InvestigationParsons Behle & Latimer
 
Fundamentals of investigation
Fundamentals of investigationFundamentals of investigation
Fundamentals of investigationjaredplata
 

Similaire à Its an Incident Dr Watson (20)

ACCA-IIA Singapore Seminar 2015 Part 5 Investigation
ACCA-IIA Singapore Seminar 2015 Part 5 InvestigationACCA-IIA Singapore Seminar 2015 Part 5 Investigation
ACCA-IIA Singapore Seminar 2015 Part 5 Investigation
 
How to Conduct a Bullet Proof Harassment Investigation
How to Conduct a Bullet Proof Harassment InvestigationHow to Conduct a Bullet Proof Harassment Investigation
How to Conduct a Bullet Proof Harassment Investigation
 
Cyber Incident Response - When it happens, will you be ready?
Cyber Incident Response - When it happens, will you be ready?Cyber Incident Response - When it happens, will you be ready?
Cyber Incident Response - When it happens, will you be ready?
 
Incident investigation and Root Cause Analysis
Incident investigation and Root Cause AnalysisIncident investigation and Root Cause Analysis
Incident investigation and Root Cause Analysis
 
Conducting an Effective Internal Investigation
Conducting an Effective Internal InvestigationConducting an Effective Internal Investigation
Conducting an Effective Internal Investigation
 
The golden hour
The golden hour  The golden hour
The golden hour
 
fy14_sh-27638-sh4_Incident-Investigation.pptx
fy14_sh-27638-sh4_Incident-Investigation.pptxfy14_sh-27638-sh4_Incident-Investigation.pptx
fy14_sh-27638-sh4_Incident-Investigation.pptx
 
Workplace Investigation 2012 Webinar
Workplace Investigation 2012 WebinarWorkplace Investigation 2012 Webinar
Workplace Investigation 2012 Webinar
 
Ethical & Practical Issues in Managing Internal Investigations
Ethical & Practical Issues in Managing Internal InvestigationsEthical & Practical Issues in Managing Internal Investigations
Ethical & Practical Issues in Managing Internal Investigations
 
Effective Fraud Investigations: 10 Keys to a Successful Outcome
Effective Fraud Investigations: 10 Keys to a Successful OutcomeEffective Fraud Investigations: 10 Keys to a Successful Outcome
Effective Fraud Investigations: 10 Keys to a Successful Outcome
 
Incident Investigation ASSE 2014
Incident Investigation ASSE 2014Incident Investigation ASSE 2014
Incident Investigation ASSE 2014
 
Accident investigation BY Muhammad Fahad Ansari 12IEEM14
Accident investigation BY Muhammad Fahad Ansari 12IEEM14Accident investigation BY Muhammad Fahad Ansari 12IEEM14
Accident investigation BY Muhammad Fahad Ansari 12IEEM14
 
SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...
SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...
SIA Tas Safety Symposium 2017: Workplace incident response options, alternati...
 
Take Charge of Your Life - Personal & Professional (ICLEF)
Take Charge of Your Life - Personal & Professional (ICLEF)Take Charge of Your Life - Personal & Professional (ICLEF)
Take Charge of Your Life - Personal & Professional (ICLEF)
 
002 bei structure1
002 bei structure1002 bei structure1
002 bei structure1
 
Investigating Misconduct: Reaching a Decision and Determining Root Causes
Investigating Misconduct: Reaching a Decision and Determining Root CausesInvestigating Misconduct: Reaching a Decision and Determining Root Causes
Investigating Misconduct: Reaching a Decision and Determining Root Causes
 
acci.invest.revised.ppt
acci.invest.revised.pptacci.invest.revised.ppt
acci.invest.revised.ppt
 
Chapter 10 11_advocacy_during_hearing_abct_week_9
Chapter 10 11_advocacy_during_hearing_abct_week_9Chapter 10 11_advocacy_during_hearing_abct_week_9
Chapter 10 11_advocacy_during_hearing_abct_week_9
 
Conducting an Effective Internal Investigation
Conducting an Effective Internal InvestigationConducting an Effective Internal Investigation
Conducting an Effective Internal Investigation
 
Fundamentals of investigation
Fundamentals of investigationFundamentals of investigation
Fundamentals of investigation
 

Dernier

Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...
Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...
Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...Pooja Nehwal
 
George Lever - eCommerce Day Chile 2024
George Lever -  eCommerce Day Chile 2024George Lever -  eCommerce Day Chile 2024
George Lever - eCommerce Day Chile 2024eCommerce Institute
 
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024eCommerce Institute
 
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...Sheetaleventcompany
 
Night 7k Call Girls Noida Sector 128 Call Me: 8448380779
Night 7k Call Girls Noida Sector 128 Call Me: 8448380779Night 7k Call Girls Noida Sector 128 Call Me: 8448380779
Night 7k Call Girls Noida Sector 128 Call Me: 8448380779Delhi Call girls
 
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...Krijn Poppe
 
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Hasting Chen
 
CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...
CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...
CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...henrik385807
 
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptxMohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptxmohammadalnahdi22
 
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...Kayode Fayemi
 
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdfCTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdfhenrik385807
 
Call Girl Number in Khar Mumbai📲 9892124323 💞 Full Night Enjoy
Call Girl Number in Khar Mumbai📲 9892124323 💞 Full Night EnjoyCall Girl Number in Khar Mumbai📲 9892124323 💞 Full Night Enjoy
Call Girl Number in Khar Mumbai📲 9892124323 💞 Full Night EnjoyPooja Nehwal
 
Motivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdfMotivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdfakankshagupta7348026
 
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝soniya singh
 
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...NETWAYS
 
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesVVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesPooja Nehwal
 
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...NETWAYS
 
Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...
Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...
Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...NETWAYS
 
ANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docxANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docxNikitaBankoti2
 
Microsoft Copilot AI for Everyone - created by AI
Microsoft Copilot AI for Everyone - created by AIMicrosoft Copilot AI for Everyone - created by AI
Microsoft Copilot AI for Everyone - created by AITatiana Gurgel
 

Dernier (20)

Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...
Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...
Navi Mumbai Call Girls Service Pooja 9892124323 Real Russian Girls Looking Mo...
 
George Lever - eCommerce Day Chile 2024
George Lever -  eCommerce Day Chile 2024George Lever -  eCommerce Day Chile 2024
George Lever - eCommerce Day Chile 2024
 
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
Andrés Ramírez Gossler, Facundo Schinnea - eCommerce Day Chile 2024
 
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
 
Night 7k Call Girls Noida Sector 128 Call Me: 8448380779
Night 7k Call Girls Noida Sector 128 Call Me: 8448380779Night 7k Call Girls Noida Sector 128 Call Me: 8448380779
Night 7k Call Girls Noida Sector 128 Call Me: 8448380779
 
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
Presentation for the Strategic Dialogue on the Future of Agriculture, Brussel...
 
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
 
CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...
CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...
CTAC 2024 Valencia - Sven Zoelle - Most Crucial Invest to Digitalisation_slid...
 
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptxMohammad_Alnahdi_Oral_Presentation_Assignment.pptx
Mohammad_Alnahdi_Oral_Presentation_Assignment.pptx
 
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
Governance and Nation-Building in Nigeria: Some Reflections on Options for Po...
 
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdfCTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
CTAC 2024 Valencia - Henrik Hanke - Reduce to the max - slideshare.pdf
 
Call Girl Number in Khar Mumbai📲 9892124323 💞 Full Night Enjoy
Call Girl Number in Khar Mumbai📲 9892124323 💞 Full Night EnjoyCall Girl Number in Khar Mumbai📲 9892124323 💞 Full Night Enjoy
Call Girl Number in Khar Mumbai📲 9892124323 💞 Full Night Enjoy
 
Motivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdfMotivation and Theory Maslow and Murray pdf
Motivation and Theory Maslow and Murray pdf
 
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
Call Girls in Sarojini Nagar Market Delhi 💯 Call Us 🔝8264348440🔝
 
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
 
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesVVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
 
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
 
Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...
Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...
Open Source Camp Kubernetes 2024 | Monitoring Kubernetes With Icinga by Eric ...
 
ANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docxANCHORING SCRIPT FOR A CULTURAL EVENT.docx
ANCHORING SCRIPT FOR A CULTURAL EVENT.docx
 
Microsoft Copilot AI for Everyone - created by AI
Microsoft Copilot AI for Everyone - created by AIMicrosoft Copilot AI for Everyone - created by AI
Microsoft Copilot AI for Everyone - created by AI
 

Its an Incident Dr Watson

  • 1. It’s an Incident Dr. Watson © HDI 2014. All Rights Reserved Developed by Rick Joslin HDI Executive Director, Certification & Training rjoslin@thinkhdi.com
  • 2. The Facts and Nothing but the Facts 2
  • 4. Initial Response Arrive at the Scene (Take the call) 4
  • 5. Classification • What type of crime? • Whose jurisdiction? • What is the priority? • What is the severity? • Is this a known problem? 5
  • 6. Initial Response • Safety • Emergency Care • Establish Control 6
  • 7. Secure the Scene • No more changes 7
  • 8. Record Evidence • Document the symptoms 8
  • 9. Collect Evidence • Listen to the customer 9
  • 10. Interview Witnesses • Ask their name • Use empathy skills • Begin with open ended questions • Use their name • Paraphrase for understanding 10
  • 11. Record the Data • Who? • What? • When? • Where? • How? • Why? You don’t know what might be important. 11
  • 12. Seek to Understand What We Know • Search the Knowledge Base 12
  • 13. Ask Clarifying Questions • Use closed ended questions • Confirm what you heard • Get another perspective 13
  • 14. Analyze the Evidence • Search the Knowledge Base again 14
  • 15. Return to the Scene • Get a closer look at the evidence • Verify the evidence and witness statements 15
  • 16. Consider Possible Motives • Establish a list of possible causes 16
  • 17. Test the Most Probable Causes • Consider frequency of occurrence and the cost of the test • Don’t overlook the simple stuff 17
  • 18. Call Your Backup - Get Help • Escalate per the service level agreement 18
  • 19. Resolve and Recover • Emergency Care comes first • Stop the pain • Get the customer back to work 19
  • 20. Incident Closure • Confirm Resolution • Capture or Update the Knowledge • Document Actions 20
  • 21. Incident Ownership • Monitor, track, and communicate status 21
  • 22. The CSI Way 1. Initial Response: Touch nothing, Observe and Listen 2. Secure and Document: Touch nothing, Record observations 3. Collect Evidence: Bag it and Tag it 4. Interview Witnesses: Question and Record 5. Analyze Evidence: Identify and Eliminate Record all data and actions 22
  • 23. CSI: A Guide for Law Enforcement Initial Response/Prioritization of Efforts 1. Receipt of Information 2. Safety Procedures 3. Emergency Care 4. Secure and Control Persons at the Scene 5. Boundaries: Identify Establish, Protect, and Secure 6. Turn over Control of the Scene and Brief Investigators 7. Document Actions and Observations Source: January 2000 by the US Attorney General 23
  • 24. Kepner-Trego’s Problem Analysis A.K.A. The KT Process 1. Define the Problem 2. Describe the Problem 3. Establish possible causes 4. Test the most probable cause 5. Verify the true cause 24
  • 25. ITIL® Incident Management Process 1. Incident Detection and Recording 2. Classification and Initial Support 3. Investigation and Diagnosis 4. Resolution and Recover 5. Incident Closure 6. Incident Ownership 25
  • 26. © HDI 2014. All Rights Reserved Thank you for attending this session. Please fill out a session evaluation form. Contact details: Rick Joslin HDI Executive Director, Certification & Training rick.joslin@ubm.com (412) 841-9793

Notes de l'éditeur

  1. It’s an Incident, Dr. Watson Support analysts need similar training to crime scene investigators. Both professions must leverage similar skills to be effective at work. The analyst is challenged to restore service, and the investigators are challenged to solve the crime. Both are solving puzzles. Structured problem solving (SPS) is a technique developed by Kepner-Tregoe. The Consortium for Service Innovation promotes the adoption of SPS within the incident management process. Law enforcement professionals utilize these techniques to solve cases. In this presentation we will walk through the incident management process and relate the work to that of the crime scene investigator. Using the structured problem solving methodology within the incident management process, support analysts can learn to support customers the CSI way. Attend this session if you want to learn how to improve incident management and solve the crime efficiently. Feedback from HDI Annual Conference Session 304 - Tuesday, April 07, 2009 3:00 PM - 4:00 PM The overall feedback for this presentation was extremely positive. The content itself is not new trends, it presents a new way to help support analyst understand their role and how to be successful. Delivery Note: Rick wore a CSI hat and vest, had a crime scene setup, complete with a taped area with the outline of a dead body and bullet casings. Delivery was done in character for the entire presentation as he was a member of the Vegas crime lab sharing how their process is similar to the process that is followed within a support center. Select Survey Comments: Great analogy & comparison to relatable subject This was really good. I like the approach & I thought Rick was pretty creative in the way he presented this was awesome. Great presentation. Rick stayed in character the entire time. Great correlation of CSI Agents and Service Desk. Liked the role play & very helpful, yet still metaphorical Most interesting presentation I’ve been too so far. Great way to compare investigation to problem solving Good tie into crime scene investigation. Greate way to connect the info. Very informative. Will be able to take this back and make nice use for new hires. Very Engaging – innovated presentation on subject This presentation has been delivered at a small number of events and continues to get positive response as a training tool for the support center. 100 word description Support analysts need similar training to crime scene investigators. Both professions must leverage similar skills to be effective at work. The analyst is challenged to restore service, and the investigators are challenged to solve the crime. Both are solving puzzles. Law enforcement professionals utilize these techniques to solve cases. In this presentation we will walk through the incident management process and relate the work to that of the crime scene investigator. Using the structured problem solving methodology within the incident management process, support analysts can learn to support customers the CSI way.
  2. Solving an incident for a customer is like solving a crime Sherlock Homes was known for his skills of solving problem by looking at the evidence and asking questions of the people involved. Sherlock Holmes pre-dates the Help Desk, but he does not pre-date problem solving, a critical skill of every support center analyst. If we look at how crimes are solved, we can find a close correlation to how we manage incident recovery today.
  3. CSI has made a major impact in today’s culture. The TV series just completed it’s 200th episode and has resulted in many similar and very popular shows. Of course the original is CSI based here in Las Vegas. Then there is CSI Miami, CSI New York, NCIS, Criminal Minds, The Mentalist, Law & Order, and the list goes on. My personal favorite is NCIS. As a result of these shows, our educational institutions are seeing a rise in applications for people wanting to enter this field of work. Who even knew what CSI stood for 15 years ago? My daughter is now in college, I know I don’t look that old. She is studying for her degree in Forensic Investigation with the goal of working for the FBI or the Secret Service. We need a TV Show to increase the focus on our field and to get more people interested in our work. All of the popular CSI shows are about problem solving. And they are teaching us that problem solving is a structured process and we need follow the evidence. Let’s look at this process a little closer.
  4. The initial response is to get experts to the scene quickly. Customers now dial 911 for assistance. This is the single point of contact for all emergency services. How many of you remember the days before 911 when we had different phone numbers for different services and they varied from city to city? Support has been centralized to make it easier for the customer and to improve efficiencies and effectiveness. There is more than one 911 center, but we leverage technology today to a number of locations look like one virtual contact center. Does this sound familiar to what is happening in our industry? The agents on the other end of the phone line are trained to manage the customer and the situation. They have to have customer service skills and problem solving skills. They may even be called upon to guide a father through the delivery of his own child. Whether you are an officer in a 911 center or an analyst in a support center, its starts with taking the call. Neither person know what to expect when the phone rings, they just know someone needs their help.
  5. Now that we are talking with the customer, we have to gather information. We need to understand what type of service do they need? What is the crime? We need to classify the call. Our job is to figure out who has the appropriate skills and authority to solve the problem. If we can’t resolve the problem over the phone, then we are going to have to escalate the call to the right people. You would not expect the 911 center to send fire department to a burglary. We also need to understand the impact and urgency so that we prioritize resources appropriately. There is a difference between a grass fire and hospital on fire. There is a difference between a shooting and vandalism. The officer or analyst on the phone will also attempt to determine if this is a known problem. Perhaps they can resolve it without getting anyone else involved. Service management systems today can quickly tell you if the customer has a PC or a MAC. That type of data is important to capture.
  6. When a police officer arrives to the scene, the first order of business is defined as Initial Response. The safety of the responding personnel and the people at the scene comes first. When they enter a building, they walk cautiously room to room to ensure that it is “Clear” of danger. They provide emergency care to the injured. And they establish control. This is both of the crime scene and the people near it. Over the phone, the support professional also needs to establish control. They first must empathize with the customer and address the emotional state of mind. Then they establish control by taking ownership of the problem and using the customers name to build rapport.
  7. Then they secure the scene. The goal is to protect the evidence from contamination. NO MORE CHANGES One of the first things a support professional should do when working with a customer is to advise them to stop all changes. No more typing on the keyboard. Imagine trying to solve a problem and the customer continues to install software patches they believe will address their issue. The support professional needs to secure the scene.
  8. In addition to collecting evidence, everything must be recorded. At a crime scenes, there is always someone with a camera. Their job is to record things before they are moved so that they can be analyzed later. This is the key point, analyze it later. They take pictures of things that may or may not have anything to do with the crime. How doe this apply to the support center? Record everything. Like what? - Who called, when did the call, what software, what hardware, etc. We have software tools today that can capture tremendous amount of information quickly.
  9. The next step is to collect evidence. After the scene has been secured, the crime scene investigators begin the task of collecting evidence. This is not the time to solve the problem or analyze the data. How do we collect evidence in the support center?
  10. And then there is the task of interview witnesses to get additional information. Does the police office start with questions like, how tall was the man? Absolutely not. That would be there is an assumption that there was a man and that this person saw them. They are trained not to lead the witness, but to follow the answers with other questions. They may ask controlling, or closed questions to determine if you are a witness or person of interest, but then the office is trained to use open questions first. What did you see? Support analysts need to do the same thing. Once they have asked a few controlling questions to gather initial data, they need to use open questions to discover additional evidence. Describe for me what you saw, explain what you expected to have happen, And what are they suppose to do this all this data?
  11. Absolutely. Record it Record everything. They do not know what might be important. Every police officer carries a pen and tablet with them. They cannot depend on their memory. Analysts need to record the information in their little notebook we call, the incident management or service management system.
  12. Once we have collected initial data, we need to seek to understand what we already know about this data. The police officer or crime scene investigator will use technology to review existing information that has been stored in database. They can check the history of the people involved. They can check the history of the cars involved. They can also check the history to see if other issues have occurred at the same location. They want to know what is known so as to minimize time and rework. Why do research about a person if they can get a copy of their police record and see what other officers have already learned about the person. How does this compare to the support center? We can search the knowledge base We can search the CMDB to learn more about the parts We can search the incident history to see if the customer has had this problem before.
  13. If we do not find the information we need, we need to gather more data. The investigator will re-interview witnesses. They will ask clarifying questions to make sure they captured the information correctly. They will gather information from other people to get another perspective. They may discuss this with other officers to get yet another perspective on the problem. Support Analysts need to do the same thing. The need to seek to understand before they seek to solve.
  14. And then they analyze the data again. CSI’s check and double check all the evidence in the lab, not in the field. As new data is discovered, the support analyst needs to search the knowledge base again. They may need to get assistance through either collaboration or escalation. Sometimes the evidence may have been planted. The witness may have given false testimony. Has anyone in the support center ever had a customer give you information that was wrong and as a result you were working on solving the wrong problem? Sometimes the witness will tell you who did it, but you have to prove it. Has anyone ever had a customer demand new equipment to solve their problem? And they never really told you what the problem was.
  15. Sometime the CSI will return to the scene of the crime. They want to a clear view of what might have happened in the environment. In the support center we are fortunate to have technology today that allows the support analyst to get a close look at the environment without ever leaving their chair. Remote control software allows them to return to the scene of the crime to gather information and to get a closer look at what is actually happening.
  16. When solving a crime, the investigator wants to understand the motive. If they can understand the motive, then they can get closer to solving the crime. Why would a person do what they did? Were they after money, drugs, alcohol or women? In the support center the support analysts may need to discover the cause of the problem before they can solve it. They need to create a list of possible causes.
  17. Then they need to test the probable causes to determine what to do next. When testing probable causes you need a plan. Consider the frequency of occurrence and the cost of the test. It is better to see if the door was unlocked before you test to see how much force is required to open the closed door. Don’t overlook the simple stuff. If the robbery was in a bank, the motive is most likely money. In order to test for possible causes, you may need to recreate the crime scene in the lab. Support professional sometimes have to reproduce the problem as part of the problem solving process.
  18. Calling for backup must be done wisely. If a police officer calls for backup every time they stop a car, the chief is most likely going to remove the officer from the force. Some things they are expected to handle on their own. And then there are times when the situation dictates you always call for backup. In the support center, the service level agreement may dictate that the incident is to be escalated immediately. Why would we do this? And there are also reasonable time limits or specific skills needed. So calling for backup is expected.
  19. In the support center are primary task is to resolve and recover. We need to get the customer back into business. Emergency care always comes first in the field. We need to find away to stop or minimize the pain for the customer. Workarounds are appropriate to get the customer back to work. We can turn the problem over to problem management if a permanent fix is required. ITIL incident management is about getting the customer back to work. A workaround may be more appropriate than fixing the problem.
  20. In the process of closing the incident, the investigator needs to confirm the evidence support his actions. In the support center, we can only confirm the resolution has resolved the problem by asking the customer. Even if we know it did, we need to ask. Just as even when the officer knows they guy is guilty, he needs to make sure that he can support his claim.
  21. Everyone has to be accountable for their actions. Just as the officer owns the case until it is closed, the support professional must own the incident until it is closed. They need to monitor and track the progress and give status updates as appropriate. They may also be asked to give testimony to what they did and why they took the actions they did.
  22. Here is the CSI way to solve a crime. Note all actions and data are to be recorded. The support professional must record all emails, phone calls, test, escalations, etc that finally lead them to the resolution.
  23. Note the steps from the Guide for Law Enforcement as published by the US Attorney General. If we changed a few terms, could we not make this the guide for support professionals.
  24. Kepner-Trego is a well known for their structured problem solving methodology. This is the base process that should serve as a foundation for incident management. This is most often used in root cause analysis, which may be required for new problems where a workaround is not apparent in order to restore service. This would be known as reactive problem management.
  25. When we look at the ITIL incident management process we see similar steps. Perhaps it is not so far fetched to think we could create a popular TV series where each week viewers tuned in to watch how the support analyst solved the problem.