Reports Flashcards

1
Q

Who are the IR leaders according to Forrester?

A

Fire eye, crowdstrike, Deloitte, ibm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who are the strong performers in IR according to Forrester?

A

Aon cylance secureworks PwC Booz Allen Hamilton Verizon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the advantages of Fireye?

A

Focused on providing road map of proactive services

Offers training as intermediary step between tabletop exercises and purple teaming

Good client references

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the advantages of Deloitte?

A

Deep understanding of requirements for successful IR

Let’s you manage high impact events with confidence

Broad spectrum of services (tho references indicate challenges during incident triage and response)

Onsite and ready to begin triage when breach occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is so great about Crowdstrike?

A

Threat intelligence and response expertise

Combination of TI, endpoint protection and IR that complement each other well are are supported by service offerings

Has partnership with Dragos to provide in house capabilities for responding in ICS environments

Mantra: am I breached? Am i mature? Am I ready?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the advantages of IBM?

A

People products and services it delivers

Combines x-force threat intelligence analysts to its IR teams to ensure full situational awareness

Incident prep services, including IF training and red teaming

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is good about Aon?

A

Plan for cyber insurance brokerage and the mid market

Oil and gas companies

Works to assess cyber security posture to facilitate negotiation of insurance deductibles and premiums

Good for those who want IR and cyber insurance advocate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s good with Verizon?

A

Forensics labs worldwide + broad range of services

Reviews legal and regulator matters to defend its clients from litigation that follows an incident

Rapid response retainer

Expertise in forensic investigations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is good with cylance?

A

Partnerships with law firms and week as insurance brokers/ carriers

IR expertise

Investing ics environments

Not great when it comes to compliance reviews

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why choose Booz Allen?

A

Broad range of services that covers all points of an investigation

Helps respond to incidents and build prevention/prep capabilities

Strong ICS capability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Why PwC?

A

Talent management, diversity in the workplace

Strong retainer strategy + proactive service offerings for unused hours

Good about roadmaps for IR preparedness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why secureworks?

A

Post-IR reporting

College program that ensure stream of talent

Roadmap for prep services based on customer maturity and need

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Key takeaways from Forrester report

A

Fire eye Deloitte crowdstrike and IBM lead the pack

Cyber ranges and actionable deliverables are key differentiators - vendors that can provide cyber ranges and actionable deliverables position themselves to deliver strong incident prep and IR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 5 SOC models?

A

Virtual, multifunction, hybrid, dedicated, command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the attributes and benefits for a virtual SOC?

A

No dedicated facility
Part time and geographically distributed team
Reactive, activated when a critical alert or incident occurs
Primary model when filled delegated to an MSSP

Small to upper mid market orgs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the attributes and benefits for a multifunction SOC?

A

Dedicated facility and team performing not just security but other critical operations 24/7 from the same facility

Small midsize and low risk large enterprises where network and security functions are already performed by the same or overlapping team

17
Q

What are the attributes and benefits for a hybrid SOC?

A

Dedicated or semidedicated staff, internal or external
Operations performed by org’s internal staff 24/7; 8/5; 8/7 with some responsibilities offloaded to external provider
Control of processes and effectiveness will vary

Small midsize enterprises

18
Q

What are the attributes and benefits for a dedicated SOC?

A

Dedicated facility and team
Fully in-house
24/7

Large enterprises, service providers, high risk organizations

19
Q

What are the attributes and benefits for a command SOC?

A

Coordinates other SOC
tI, situational awareness, additional expertise
Rarely directly involved in day to day

Very large enterprises and service providers, governments, military, intel