UNIT 6: DOCUMENTATION IN DISASTER MANAGEMENT Flashcards
is a group of individuals who are responsible for managing and responding to security incidents within an organization.
Incident Response Team (IRT)
goal of an IRT
to quickly detect, contain, and mitigate the impact of security incidents to minimize damage and restore normal operations.
Monitoring systems and networks for signs of
security incidents, such as unusual activity or unauthorized access.
Detection and Identification
solating affected systems to prevent further
damage, removing malware, and restoring systems to a secure state.
Containment and Eradication
Conducting forensic analysis to determine the cause and scope of the incident, identifying vulnerabilities, and gathering evidence for
potential legal proceedings.
Investigation and Analysis:
Managing internal and external
communications during the incident, including notifying stakeholders, coordinating
with law enforcement, and managing public relations.
Communication and Coordination:
Restoring affected systems and services to normal
operations, implementing security patches and updates, and implementing
measures to prevent similar incidents in the future.
Resolution and Recovery:
■ Leads the incident response efforts.
■ Makes strategic decisions regarding the response.
■ Coordinates with internal teams and external partners.
Incident Commander:
Identifies the root cause of the incident.
Gathers evidence for potential legal proceedings.
Forensics Analyst:
Identifies and escalates potential security incidents.
■ Assists in containing and mitigating the impact of incidents.
Security Analyst:
Manages internal and external communications during the incident.
■ Ensures timely and accurate information dissemination.
■ Coordinates with public relations and legal teams.
Communications Coordinator:
Provides legal guidance on incident response efforts.
■ Ensures compliance with relevant laws and regulations.
■ Assists in drafting legal documents and reports.
Legal Advisor
Assists in isolating affected systems to prevent further damage.
■ Restores affected systems and services.
■ Implements security patches and updates to prevent future incidents.
IT Operations:
Assists in managing the impact of the incident on employees.
■ Coordinates with management on employee communications and support.
■ Ensures compliance with HR policies and regulations.
Human Resources:
Manages external communications with the media and stakeholders.
■ Helps maintain the organization’s public image during the incident.
■ Coordinates with the communications coordinator for consistent
messaging.
Public Relations