Week 4 Flashcards
What are two frameworks for playbooks?
-NIST
-IACD
What is an important non-IT aspect to explain in a playbook?
The impact on wider operations outside of the IT department - helps to get both understanding and funds from management
What is one way to reduce the amount of false positive alarms?
Buy proprietary tools, however these can hide the reason for the alarm
What is a problem with using ML for classification in a SOC?
It is good at seeing correlations but not so good at understanding causalities
What does computer forensics deal with?
Digital evidence that is present in any top of crime - they do not necessarily work on cybercrimes
What is the foundation of digital forensics?
The practice of collecting, analysing and reporting on digital data
What is important to remember regarding the state of the evidence during digital forensics?
It must not be changed in order to be valid in court