(12) Incident Reporting Flashcards

1
Q

Describe the importance of stakeholder notification when it comes to Incident response

A

The org needs to identify key stakeholders in order to get information to the right people are he right time.

These people include admins, developers, management, legal counsel, etc.

External stakeholders could include customers, law enforcement, service providers, external counsel, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When an incident is detected and analysis has begun, what communication needs to happen?

A
  1. The IoCs that cause the investigation need to be communicated to incident responders
  2. The incident responders need to determine if the IoCs point to an incident or false positive
  3. If an incident is declared, incident response processes kick in and the containment, eradication, and recovery stages happen.

Communication must happen at all stages of the incident response process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What should orgs do as far as legal council is concerned for the incident response process?

A

Orgs should engage legal council before an incident occurs so that they have pathways setup for easy decision making when they need it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is important to remember about customer communication during incident handling?

A

Customer communication is paramount because customer trust and protection is a very important consideration.

Useful information can be hard to provide up front because assumptions can be proven wrong later.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What media considerations need to be observed?

A

Media considerations include:

-Procedures for briefing the media

-Having an ongoing, regularly updated response document

-Prepping staff for contact with the media and requests for information

-Holding practice sessions for incident responders

Regulations may require that the company respond in a certain way as well

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) about?

A

It says that really REALLY bad events (that cause VERY big harm to national security, foreign relations, the economy, civil liberties, public health) be reported to the Cybersecurity Infrastructure Security Agency (CISA) within 72 hours and that ransomware payment be reported within 24 hours of the payment being made.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What happens if cybersecurity criminals are involved in an incident, especially those are involve nation state actors?

A

In the case of nation state actors, orgs may need to get law enforcement on the case.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What happens when law enforcement gets involved with an incident response process?

A

When law enforcement gets involved, systems may need to be handed over to law enforcement, they may need to be taken offline or other things may also need to happen.

The org can choose to cooperate or decline but should get legal counsel before doing so

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Root Cause Analysis? (RCA)

A

RCA is about figuring out why the incident occurred. The steps include:

  1. Identify the problems and events that occurred with the incident, and describe them as well as possible
  2. Get a timeline of events, it helps figure out what happened, and in what order
  3. Figure out the difference between each event and causal factors
  4. Document the analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What four measures should we consider when it comes to incident response?

A

The four measures we should consider are:

-Mean time to detect

-Mean time to respond

-Mean time to remediate

-Alert Volume

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do Orgs need to remember about KPIs?

A

Orgs need to understand what is being measured and why they are measuring it. They have to tie into the company objectives somehow.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What should an Incident Response (IR) report include in it according to the Dept of Homeland Security and the CISA?

A

The IR report should include:

-Executive Summary

-Recommendations

-Timeline

-Impact Assessment

-Scope

-Evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly