QS0034-02: Incident Response Plan Flashcards
QS0034-01: Incident Response Plan
Which role is responsible for determining the nature and scope of the incident?
The Information Security Officer
QS0034-01: Incident Response Plan
Which role is a central point of contact for all computer incidents?
DevOps
QS0034-01: Incident Response Plan
What are the responsibilities of Application Engineers?
- Contacts DevOps with any information relating to a suspected breach
- Collects pertinent information regarding the incident at the request of the ISO
QS0034-01: Incident Response Plan
What are examples of incidents requiring the Incident Team activation?
- Breach of sensitive data, especially Personal Information
- Attacks that impact services or may lead to information that can lead to a breach. For example:
- Denial of Service / Distributed Denial of Service
- Excessive Port Scans
- Firewall Breach
- Virus / Malware Outbreak
- Disasters that result in potential loss of information
QS0034-01: Incident Response Plan
What is meant by a Security Breach?
A security breach is the unauthorized acquisition of data that compromises the security, confidentiality, or integrity of data maintained by LabLynx.
QS0034-01: Incident Response Plan
How is the impacted entity notified?
Written, or Email notices. At minimum, client facing helpdesk tickets accomplish this.