Unit 2 - Module 4 Flashcards
Define Playbook
A manual that provides details about any operational action.
What does Incident response mean?
Incident response is an organization’s quick attempt to identify an attack, contain the damage, and correct the effects of a security breach.
What are the 6 Incident responses in the playbook phase?
1) Preparation
2) Detection and analysis
3) Containment
4) Eradication and recovery
5) Post incident activity
6) Coordination
Playbooks sometimes cover what 2 specific things?
Incidents and Vulnerabilities.
Define the Preparation phase (1)
Before incidents occur, mitigate potential impacts on the organization by documenting, establishing staffing plans, and educating users.
Define the Detection and analysis phase (2)
Detect and analyze events by implementing defined processes and appropriate technology.
Define the Containment phase (3)
Prevent further damage and reduce immediate impact of incidents.
Define the Eradication and recovery phase (4)
Completely remove artifacts of the incident so that an organization can return to normal operations.
Define the Post-incident activity phase (5)
Document the incident, inform organizational leadership, and apply lessons learned.
Define the Coordination phase (6)
Report incidents and share information throughout the response process, based on established standards.
What can playbooks be used for? ( What kind of incidents, leaks and attacks ) 5 Examples
Open attacks
Privacy incidents
Data leaks
Denial of service attacks
Service alerts
Others