> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/online-courses/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/online-courses/cyber-incident-response/follow-up-lessons-learned/implementing-improvements.md).

# Implementing improvements

## Different approaches

* Immediate implementation
* Phased implementation

### Immediate implementation

Should generally be reserved for solutions that:

* Have very low impact on operations
* Do not require significant resources or effort from other organizations in the enterprise
* Address critical failures in the response effort

### Phased implementation

May require significant resources and input from other teams

Solutions that may impact operations and other business functions

Will usually require some type of impact assessment

Sometimes things that address critical flaws will still need this approach

* Communication with other teams was flawed
* Getting access to tools was flawed
