Domain 7 - Security Operations Flashcards
The following represent what?
- Administrative
- Criminal
- Civil
- Regulatory - Gov Agency Investigation
- Industry Standards - Electronic Discovery
Investigation types
The following is what in regards to Forensics Techniques / evidence?
- must be relevant to determining fact
- the fact must be material relevant to the case
- must be competent, must have obtained legally
admissible evidence
What are the three types of evidence that can be used in a court of law?
- Real Evidence - Physical items that are brought into court and can be seen/examined
- Documentary Evidence - Written items brought into court to prove a face about the case
Best Evidence Rule
Parol Evidence Rule - Testimonial Evidence - Testimony of a witness
Direct
Expert
Hearsay
Documents the evidence lift cycle from discovery and collection through analysis and storage to reporting and presentation.
Chain of Evidence
a. general description
b. time and date
c. exact location
d. name of the person collecting evidence
e. relevant circumstances surrounding collection
What do the following steps represent in regards to Investigations?
- Call in Law Enforcement
- Gather evidence
- Conduct Investigation
- Interview Individuals
- Report on and document Investigation
Investigative Process
TRUE / FALSE
IDS = PASSIVE IPS = ACTIVE
TRUE
IPS has the ability to take action such as re configuring a firewall to block a threat. IDS can only send alerts which doesn’t qualify as taking action.
Ensures no single person has total control
Separation of duties
Applies concept of least privilege to applications and processes
Separation of privileges
Separation of duties + least privilege
Designated to guard against excessive system access to prevent conflicts of interest
Segregation of Duties
Activity requires the approval of two people to be carried out
Two Person Control (Rule)
Separation of Duties + Two Person Rule
Split-Knowledge
Move people through various jobs / tasks to spread knowledge & responsibility
a. mandatory vacations
Job Rotation
Mandatory Vacations classified as a form of Job Rotation
What do the following represent?
a. Create of Capture
b. Classification
c. Storage
d. usage
e. archive
f. Destruction or purging
Information Lifecycle Phases
Document describing the level of service expected by a customer
SLA - Service Level Agreement
OLA - Internal facing SLAs. (Example: IT and Sales)
Examples:
MOU - Memorandum of Understanding
ISA - Interconnection Security Agreement
What do the following steps represent?
- Detection
- Response
- Mitigation
- Reporting
- Recovery
- Remediation
- Lessons Learned
Incident Response Process
Mantra of the CSIRT (Computer Incident Response Team) is what?
Isolation is good. Powering off is bad.