5.4 Follow incident response procedures Flashcards

1
Q

Incident response plan

A
  • Identify and prioritize all incidents that pose risk without overloading the security team.
  • Re-establish a secure working system.
  • Preserve evidence of the incident with the aim of prosecuting the perpetrators.
  • Prevent reoccurrence of the incident.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Documented incident types/category definitions

A
  • Data Integrity
  • Downtime
  • Economic/publicity
  • Scope
  • Detection time
  • Recovery time
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Roles and responsibilities

A

Some organizations will provide a dedicated cyber incident response team (CIRT) or computer security incident response team (CSIRT) as a single point-of-contact for the notification of security incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Reporting requirements/escalation

A

The process by which more senior staff become involved in the management of an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Cyber incident response teams

A

(cyber incident response team) A group that handles events involving computer security breaches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Preparation

A

Making the system resilient to attack in the first place. This includes hardening systems, writing policies and procedures, and establishing confidential lines of communication. It also implies creating a formal incident response plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Identification

A

Determining whether an incident has taken place and assessing how severe it might be, followed by notification of the incident to stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Containment

A

Limiting the scope and impact of the incident. The typical response is to “pull the plug” on the affected system, but this is not always appropriate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Eradication

A

Removing an incident from the system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Lessons learned

A

Analyzing the incident and responses to identify whether procedures or systems could be improved. It is imperative to document the incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly