Annex H20 Incident Response, Reporting, and Auditing Flashcards
0
Q
Incident
A
An adverse event in an information system and/or network or the threat of the occurrence of such an event
1
Q
Definition of Event as it relates to incident response
A
An event is any observable occurrence in a system and/or network
2
Q
Eight (8) categories of an incident
A
Malicious code Unauthorized access Inappropriate usage Service disruption Espionage Hoaxes Spillages Multiple Category
3
Q
Six (6) components of an Incident Response Policy
A
Preparation Detection Containment Eradication Recovery Follow Up
4
Q
Audit
A
An independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures and to recommend necessary changes in controls, policies, and procedures
5
Q
How to conduct evidence processing
A
Immediate Action- When in doubt contact MCNOSC Turn off/leave system alone Seizure of equipment Technical evidence gathering Policy or legal Notification Documentation time date individual involved with action description of action chain of custody