LO4 Flashcards
Procedures to think about after a cyber security incident
What are the procedures? When do I need to implement them? in what order?
What is meant by responsibilities
who is involved? What is their authority?
Who is the target
The organisation? particular department? An individual?
What are the procedures to follow whilst responding to an incident
prepare
Detect
Contain
Eradicate
Recover
Lessons learnt
What are the steps in preparation
Make sure employees are aware of what to do
Perform regular drills and mock scenarios
create an incident response plan
What are the steps in detection
When did the incident happen
how did the incident happen
Who discovered the incident
What other areas have been affected
What was the source of the incident
What are the steps in containment
Restricting further damage being caused
Quarantining infected systems
Keeping system users informed of actions being taken
What are the steps in eradication
Identify and implement measures to eliminate further infection
Identify the origin of the infection and rebuild devices in a sandboxed environment
Removing/Repairing any infected system files
Checks for any remaining traces of infection
Identification of the vulnerability that was exploited
What are the steps in recovery
Networked devices are tested for malware
Upon successful testing, devices are restored to their original state
What are the steps in lessons learnt
Incident manager will write a report
Organisation will consider above advice and apply where feasible
What are critical incidents
Services are ruined that are essential to the organisation
Seriously breach the security if the organisations network
affect critical equipment or services
What are significant incidents
Incidents that affect a smaller group of users/ devices
Interfere with non essential services
What are minor incidents
Are able to be addressed by IT support technicians in the organisation
What are negligble incidents
Have little or no impact on the organisation
Minor hardware failure
Loss of connectivity between devices