IS4670 CHAPTER 13 TERMS & DEFINITIONS Flashcards
1
Q
- An event with negative consequences, such a system crash, network packet floods, unauthorized use of system privileges, unauthorized access to sensitive data, and execution of malicious code that destroys data
A
Adverse event
2
Q
- A violation or an imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.
A
Computer security incident
3
Q
- Any observable occurrence in a system or network. Examples include a user connecting to a file share, a server receiving a request for a Web page, a user sending e-mail, and a firewall blocking a connection attempt.
A
Event
4
Q
- A document that outlines specific procedures to follow in the event of a security incident.
A
Incident response plan
5
Q
- A group of people with responsibilities for dealing with any security incident in an organization
A
Incident response team (IRT)
6
Q
- Part of the National Cyber Security Division of the Department of Homeland Security that assists civilian agencies in their incident- handling efforts.
A
U.S. Computer Emergency Readiness Team (US-CERT)