SecondMark position
Incident review must distinguish proximate failure from systemic cause while preserving uncertainty. It should explain how controls behaved, not only how code broke.
The examination is bounded to defined claims, a versioned system, and evidence that can be traced to the state under review. Any material exclusion or uncertainty remains visible in the conclusion.
Core questions
What the examination needs to establish.
- 01
What sequence of states produced the event?
- 02
Which signals existed and who could act on them?
- 03
Did controls fail, get bypassed, or never apply?
- 04
What evidence supports recurrence prevention?
Evidence model
Evidence is assembled around the claim—not the folder structure.
Architecture and system boundaries
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Implementation and model provenance
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Runtime behavior and operational history
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Controls, qualifications, and unresolved risk
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Intended outcome
An independent causal record, control assessment, and evidence-based view of remediation sufficiency.
Professional boundary
What an opinion does—and does not—mean.
It provides
A traceable independent conclusion on defined claims, grounded in the evidence and system state examined.
It does not provide
A guarantee that failure is impossible, a permanent certification, or a conclusion beyond the stated scope and validity conditions.
