02. Incident Investigation and Evaluation (478) Flashcards

1
Q

External Legal Counsel

Retaining outside legal counsel through contract agreement to provide legal advise in relation to security incidents

478

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cyber-Insurance

It is possible to transfer risk through insurance but organisations have a responsibility to read small print and understand the requirements they must meet to validate insurance.
Insurance companies will not pay out if proven that neccessary controls were not put in place to minimise the likliehood or impact.

478

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Dwell Time

The time that elapses betwen the beginning of an incident and the moment the organisation is aware

479

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Chain of Custody

Chain of custody documents in detail how and when evidence is protected against tampering through every step of the investigation

481

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Forensic Proceedings

Senior Management must make a call as early as possible into an incident if they wish to involve forensic investigations. Forensic procedures can consume significant resources that slow down incident response.

482

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Service Provider Incidents

Organistaions need to develop plans that include procedures for when an incident occurs in a service providers environment

483

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly