(12) Incident Reporting Flashcards

1
Q

Describe the importance of stakeholder notification when it comes to Incident response

A

The org needs to identify key stakeholders in order to get information to the right people are he right time.

These people include admins, developers, management, legal counsel, etc.

External stakeholders could include customers, law enforcement, service providers, external counsel, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When an incident is detected and analysis has begun, what communication needs to happen?

A
  1. The IoCs that cause the investigation need to be communicated to incident responders
  2. The incident responders need to determine if the IoCs point to an incident or false positive
  3. If an incident is declared, incident response processes kick in and the containment, eradication, and recovery stages happen.

Communication must happen at all stages of the incident response process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly