10 - Incident Management Flashcards

1
Q

What is an incident?

A

Any event that violates an org’s security policies.

May disrupt normal operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cycle of diaster planning/recovery (3 things)

A
  • Planning
  • Disaster
  • Recovery
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Planning process

RCIDP

A
  • Risk assessment
  • Conduct aq business impact analysis
  • Identify preventative controls
  • Develop IT recovery and reconsitution strategy
  • plann testing, training, maintenance and exercises
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Business Impact Analysis

A

Determines the impact in the event that key processes are not available

Built on worst case scenarios: what assets needed to recover?
Identify recovery time (maximum down time)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

3 steps of BIA

A

Assess and analyse
Report
Develop Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Business COntinuity Plan

A

Creates a plan to continue business after disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Recovery time objective

A

How quickly business process should be recovered, based on business tolerance to loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Recovery Point Objective

A

Defines the maximum acceptable level of data loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Incident response plan helps to do what

A

helps to identify the security event and bring it to closure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Disaster Recovery Plan

A

How an org manages a catastrophic event, such as a natural disaster or accidental data loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

GDPR requires a backup and disaster recovery plan. What is the maximum time for informing authorities of a breach?

A

72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SANS Institute’s 6 steps of incident response

PICERL

A
  • Preparation
  • Identification
  • Containment
  • Eradication
  • Recovery
  • Lessons Learned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Incident Response reactive and/or proactive?

A

reactive (handling incidents as they occur) but also proactive (prepare/prevent)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Backup considerations

A
  • Frequency
  • Location
  • Medium
  • Vaulting
  • Mirroring
  • What to backup
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Redundant/Mirrored

A

Mirror of original

Fully available
Real time info mirroring

Drawbacks:
Expensive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Hot site & drawbacks

A
  • Fully configured
  • Readily available
  • annually tested

Drawbacks:
- Expensive
- Hardware/software choices limited
- Short term

17
Q

Warm Site

A
  • Partially Configured
  • Long term
  • Choice of hardware/software use

Drawbacks:
- Not readily available
- No testing
- Resources not available

18
Q

Cold Site

A
  • Core equipment only

Drawbacks
- take up to a week
- Operation resources not available

19
Q

Mobile/rolling site

A
  • Transportable with necessary hardware and equipment

Drawbacks:
- Short term

20
Q

Disaster Declaration Policy

A

Outlines the process by with BCP and DRP are activated

Defines the roles and responsibilities for assessing/declaring disaster.

Includes notification of people and alternate site activations

21
Q

Forensic Investigation

A

who, what, when, where, how and why etc

Evidence…:
- Collection
- Preservation
- Analysis
- Presentation

22
Q

What to do after the incident

A

Review readiness for next incident
Review risk management and security policies
Further investigation

23
Q

SANS report format

A
  • When and who
  • scope
  • how contained/eradicated
  • recovery work
  • effective response areas
  • areas of improvement