Which action will be performed as part of the ‘information security incident review’ of the ‘information security incident management’ process, after a server has been compromised?