Precisely!
One large company I know has a technical review system which we use frequently to root cause failure and more importantly to update systems and workflows that will avoid the cockup being discussed in future. Blaming a team or oneself is not entertained (we don't care about the who), the important question is why and what can we do to fix it.
In my opinion, I think the OpenSSL team should come up with such a document and a list of corrective countermeasures.