Appendix A: CSIRT Flashcards

1
Q

Coordination centers

A

Coordinate handling of incidents across various CSIRTs. (i.e. US-CERT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Analysis Centers

A

Synthesize data. Look for trends in incident activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Vendor teams

A

Vendor team that handles vulnerabilities in their products. Also remediation and mitigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Incident response providers

A

MSSP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CSIRT Constituency

A

Who they support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CSIRT relationship to others

A

Peers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CSIRT place in org.

A

Roots (mostly in the SOC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Reactive service

A

Triggered by an event, request,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Proactive service

A

Prepare, protect systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Triage function

A

Help desk level activities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Handling function

A

Reviews incident report. Analysis. Responses. Notification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Feedback function

A

Supports giving feedback on issues not related to specific incident.

Interface with media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Optional announcement function

A

Provides advisories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly