Incident Response Planning Flashcards
Who are the key people that have to be available to respond to any incident that meets the severity and thresholds laid out in the incident response plan?
Incident Response Team
What are the key positions of an Incident Response Team?
Incident Response Manager Security Analysts (Two Types) --Triage Analyst (Security Analyst) --Forensic Analyst (Security Analyst) Threat Researcher Cross Functional Support
Note: This team is often known as a CSIRT (See-Sirt)
Who is the single point of contact for a security incident?
CSIRT
Note: The CSIRT may be a part of the SOC (Security Operations Center) or an independent team (often outsourced)
Who are the executives and managers who are responsible for business operations and functional areas, and why are the important regarding incident response?
Senior Leadership, they will have to be the ones to make the business end decisions regarding how incidents are handled such as shutting down a server.
What are the governmental organizations that oversee the compliance with specific regulations and laws?
Regulatory Bodies
Who is the business or organization component responsible for mitigating risk from civil lawsuits?
Legal
Who may provide services to assist in incident handling or to help prepare legal action against the attacker?
Law Enforcement
Note: Senior Execs and Legal Counsel will make the decisions to involve low enforcement
What department is used to ensure no breaches of employment law or employee contracts occur during an incident response?
Human Resources
Who manages the publicity from a serious incident?
Public Relations