Domain 7 Flashcards
NIST 800-86 Covers What?
Digital Forensics Process
Steps of Digital Forensics
- Collection
- Examination
- Analysis
- Reporting
What forensics is prioritized to collect
volatile data to most stable
Forensics Process is Covered in which document
NIST SP-800-86
3 P’s of Incident Response
Policy
Plan
Procedures
Phases of Incident Response Handling
- Preparation
- Detection and Analysis
- Containment, Eradication, Recovery
- Post incident activity (Lessons Learned)
Steps of Change Management
- Change Request (documented)
- Evaluate (prioritize) and test
- Rollback Procedure
- Change Control Board Review and approval(standard changes can be pre-authorized)
- Change window/implemented
- Document updated change
MTBF
Medium Time Before Failure
MTTR
Medium Time To Recover
What is Software Escrow
Source Code is put into a third party trust that maintains it. If the developing person or company ends, the escrow can be released to company.
Load balancing
Server Cluster, will fail over to another server if one fails
Who manages a DR
DR Manager
Who communicates with Media
No one, except for CEO or designated person per policy
RTO
Recovery Time Objective
Define RTO
The amount of time planned to recover in the event of a DR or outage. (i.e. 30 minutes, or 30 days)