Chapter 2 mod 1 Flashcards
Incident Response, Business Continuity, Disaster Recovery
Define Breach
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: a person other than an authorized user accesses or potentially accesses personally identifiable information; or an authorized user accesses personally identifiable information for other than an authorized purpose
Define Event
Any observable occurrence in a network or system.
Define Exploit
A particular attack. It is named this way because these attacks exploit system vulnerabilities.
Define Incident
An event that actually or potentially jeopardizes the confidentiality, integrity or availability of an information system or the information the system processes, stores or transmits.
Define Intrusion
A security event, or combination of events, that constitutes a deliberate security incident in which an intruder gains, or attempts to gain, access to a system or system resource without authorization.
Define Threat
an activity, deliberate or unintentional, with the potential for causing harm to an automated information system or activity.
Define Vulnerability
Weakness in an information system, system security procedures, internal controls or implementation that could be exploited by a threat source.
Define Zero Day
A previously unknown system vulnerability with the potential of exploitation without risk of detection or prevention because it does not, in general, fit recognized patterns, signatures or methods.
What is the top priority of any incident response?
The top priority of any incident response is to protect life, health, and safety, and safety is always chosen first when making decisions related to priorities.
What is the primary goal of incident management?
The primary goal of incident management is to be prepared, requiring a policy and a response plan to guide the organization through a crisis.
What term is sometimes used interchangeably with incident management to describe the process?
The term “crisis management” is sometimes used interchangeably with incident management to describe the process.
define an event in the organizational context?
An event is defined as any measurable occurrence, and most events are harmless. However, if the event has the potential to disrupt the business’s mission, it is called an incident.
What is the key requirement for preserving business viability and survival during an incident?
Every organization must have an incident response plan to help preserve business viability and survival during an incident.
What is the ultimate aim of the incident response process?
The incident response process is aimed at reducing the impact of an incident, enabling the organization to resume interrupted operations as soon as possible.
How does incident response planning relate to business continuity management (BCM)?
incident response planning allows the organization to handle an incident from the start.
Business continuity management keeps the organization running during the lifecycle of an incident, while disaster recovery patterns the recovery process back to normalcy
What is the overarching goal of incident response in relation to organizational operations?
The overarching goal of incident response is to reduce the impact of an incident, allowing the organization to resume its interrupted operations as quickly as possible.
What broader discipline does incident response planning fall under?
Incident response planning falls under the broader discipline of business continuity management (BCM).
What role does the incident response plan play in relation to the incident response policy?
The incident response plan is referenced by the incident response policy, serving as a living representation that employees follow based on their role in the process.
What aspects of the organization should shape the incident response process?
The organization’s vision, strategy, and mission should shape the incident response process.
What does the incident response plan contain, and what does it represent for an organization?
The incident response plan may contain several procedures and standards related to incident response and represents a living representation of an organization’s incident response policy.
What should the procedures to implement the incident response plan define?
The procedures to implement the incident response plan should define the technical processes, techniques, checklists, and other tools that teams will use when responding to an incident.
What components are commonly found in the preparation phase of an incident response plan?
Components in the preparation phase include developing an approved policy, identifying critical data and systems, training staff, implementing an incident response team, practicing incident identification, identifying roles and responsibilities, and planning communication coordination.
What activities are involved in the detection and analysis phase of an incident response plan?
Activities in the detection and analysis phase include monitoring all possible attack vectors, analyzing incidents using known data and threat intelligence, prioritizing incident response, and standardizing incident documentation.