4.0 Reporting and Communication Flashcards
Vulnerabilities
Affected hosts
Risk score
Mitigation
Recurrence
Prioritization
Compliance reports
Action plans
Configuration management
Patching
Compensating controls
Awareness, education, and training
Memorandum of understanding (MOU)
Service-level agreement (SLA)
Organizational governance
Business process interruption
Degrading functionality
Legacy systems
Proprietary systems
Metric and key performance indicators (KPIs)
Trends
Top 10
Critical vulnerabilities and zero-days
SLOs
Stakeholder identification and communication
Incident declaration and escalation
Executive summary
Who, what, when, where, and why
Recommendations
Timeline
Impact
Scope
Evidence
Legal
Public relations
Customer communication
Media
Regulatory reporting
Law enforcement
Root cause analysis
Lessons learned
Metrics and KPIs
Mean time to detect
Mean time to respond
Mean time to remediate
Alert volume