Chapter 8 Review Flashcards

1
Q

Chapter 8 Review

Security incident management, disaster recovery planning, and business continuity planning all support a central objective, which is what

A

RESILIENCE AND RAPID RECOVERY WHEN DISRUPTIVE EVENTS OCCUR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Chapter 8 Review

As a result of a security incident event, these 3 things of information systems have been or is in danger of being compromised.

A

CONFIDENTIALITY, INTEGRITY, AVAILABILITY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Chapter 8 Review

The condition of information systems is a secondary concern compared to this, which is always the top priority when any disaster event has occurred.

A

HUMAN SAFETY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Chapter 8 Review

The phases of incident response are these 10 things;

  1. ____ ; preparing
  2. ____ ; identification of an incident
  3. ____ ; Triggering the incident response processes
  4. ____ ; Investigating
  5. ____ ; Preventing spread
  6. ____ ; Removal of offending issues
  7. ____ ; Returning to normal operations
  8. ____ ; Implementing controls to minimise future impact
  9. ____ ; Declaring the incident and subsequeny actions over
  10. ____ ; Learning what we could do better, what went wrong
A
  1. PLANNING
  2. DETECTION
  3. INITIATION
  4. ANALYSIS
  5. CONTAINMENT
  6. ERADICATION
  7. RECOVERY
  8. REMEDIATION
  9. CLOSURE
  10. POST-INCIDENT REVIEW
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Chapter 8 Review

Security Incident response planning consists of the development of these 4 things/areas

A
  1. POLICIES
  2. ROLES and RESPONSIBILITIES
  3. PROCEDURES
  4. TESTING and TRAINING
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Chapter 8 Review

Security incident response requires these things that enable an organization to be aware of an incident as it occurs.

A

INCIDENT DETECTION CAPABILITIES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Chapter 8 Review

Without this, an organization may not know about an intrusion for many weeks or months, if ever.

A

INCIDENT DETECTION CAPABILITIES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Chapter 8 Review

A primary capability in incident response is event visibility, which is usually provided through what system

A

SECURITY INFORMATION and EVENT MANAGEMENT
(SIEM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Chapter 8 Review

Many organizations outsource this to a third-party managed security services provider.

A

SECURITY EVENT MONITORING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Chapter 8 Review

Organizations often outsource this to security professional services firms by purchasing a retainer, a prepaid arrangement.

A

INCIDENT RESPONSE

Outsourcing the incident response activity does not mean that the organization transfers the risk or responsibility of the incident response program or its impact on the business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Chapter 8 Review

With the proliferation of outsourcing to cloud-based service providers, many security incidents now occur on what

A

SYSTEMS MANAGED BY THIRD-PARTY PROVIDERS

Security incidents occuring on systems managed by third-party providers requires additional planning and coordination on the part of the organization, so that incident response involving a third party is effective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Chapter 8 Review

The organization may need to incorporate the third party’s one of these into their existing plan.

A

INCIDENT RESPONSE PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Chapter 8 Review

These 2 things work together to ensure the survival of an organization during and after a natural or human-made disaster.

A

BUSINESS CONTINUITY PLANNING and DISASTER RECOVERING PLANNING
(BCP & DR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly