Module 9: Incident Reporting Flashcards
What is incident reporting
The process of reporting the information regarding the encountered security breach in a proper format
When a breach occurs what needs to be reported
- Logs of unauthorized access
- Disturbances in services
- DoS
- The system used to store or process data
- Modifications in system hardware or software
Why is it important to report an incident
It is able to generate assistance in responding to the incident and helps the victim to be in touch with others who have encountered similar incidents
TRUE or FALSE: It is necessary to report an incident in order to receive technical assistance including guidance on detecting and handling the incidents
TRUE
TRUE or FALSE: Reporting an incident doesn’t help with legal issues
FALSE
TRUE or FALSE: Reporting an incident improves awareness on IT security issues and prevent other nuisance
TRUE
What are some of the reasons why organizations do not report computer crimes
- Misunderstanding the scope (Assuming no one else has had this incident)
- Fear of negative publicity (Negatively impact their reputation via the media)
- Potential loss of customers (Customers lose faith in the organization)
- Desire to handle things internally
- Lack of awareness of the attack (Unaware of the methods of attack or its impact)
Why is it a good idea to know who to report an incident to
Timely reporting and notification to all who need to be involved will be able to exercise their roles efficiently
Who are some of the people you need to report an incident to
- Head of IT Security (Dave)
- Local Information Security Officer (Danny)
- Incident response teams in the organization (IT Forensics)
- Human Resources
- Public Affairs Officer
- Legal
- CERT
What kind of communication methods should be used to communicate the incident to other teams
- Telephone calls
- FAX
- Online forms
- In person
- Voice mailbox, memos, bulletin boards
Pretty much any sort of communication that we have at Gulfstream
Who needs to observe every step and sign all the documents regarding the incident which helps in legal issues
Incident handler
TRUE or FALSE: Such things such as the nature of the private data involved in the incident, circumstances that revealed the incident, other individuals involved, immediate responses taken, etc. Are details that need to be reported
TRUE
Think of the information that we put into FIR.
Who should collect all the facts regarding the incident
Incident Response Team
The SOC
What does CERT use to keep track of incidents
Incident reference numbers
How are the reference numbers selected
They are unique and random