Writing Assignment: Module 04 Flashcards

1
Q

What are the steps of the overall IR development process?

A

Preparation, detection and analysis, containment, eradication and recovery, and post-incident activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the general stages followed by the IRP team?

A

*Form the IR planning committee
*Develop the IR planning policy
*Integrate the BIA
*Identify preventive controls
*Organize the Computer Security Incident Response Team
*Create IR strategies and procedures
*Develop the IR plan
*Ensure plan, testing, training, and exercises
*Ensure plan maintenance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are two external sources for performing IRP that were mentioned in this module?

A

The National Institute of Standards and Technology (NIST) and CERT coordinating center

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the organizational phase of the IRP process begin with?

A

Begins with staffing the IR planning committee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who are the typical stakeholders of the IR process?

A

-General management
-IT and InfoSec management
-Organizational departments
*Legal department
*Human resources department (HR)
*Public relations (PR)
*Departments with an information security overlap
-General end users, key business partners, contractors, temporary employee agencies, consultants

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which individuals should be assembled to form the IRP team?

A

Information technology (IT) involvement
Information security involvement
CPMT organizational management representatives
Team leader: liaison between IR team and CPMT
Champion: chief information officer (CIO) or vice president of IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What should be among the first deliverables created by the IR planning committee?

A

IR policy
-First deliverable prepared by the IRP committee

-Similar in structure to other organization policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the primary function of the IR policy?

A

-Defines team operations
-Articulates response to various types of incidents
-Advises end users on how to contribute to the effective response
Rather than contributing to the problem at hand

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In order for IP policy to be effective, what group must give its full support?

A

Important to gain support top management and be clearly understood by all affected parties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the essential attributes of an IR policy document?

A

*Statement of management commitment
*Purpose and objectives of the policy
*Scope of the policy
*Definition of Information security incidents
* Organizational structure and delineation of roles
*Prioritization or severity ratings of incidents
*Performance measures
*Reporting and contact forms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an incident response plan (IR plan)?

A

Detailed set of processes and procedures
Anticipate, detect, and mitigate unexpected event effects that might compromise information resources and assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What characteristics must be present if an adverse event is to be considered an incident?

A
  1. If is directed against information assets owned or operated by the organization.
  2. It has a realistic chance of success
  3. It threatens the confidentiality, integrity, or availability of the information resources and assets
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the three sets of time-based procedures that are often part of the IR planning process?

A

Addressing the steps taken before, during, and after an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is meant by the “trigger” for an IR-related plan?

A

Circumstance causing IR team activation and IR plan initiation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a “reaction force” in terms of IR planning?

A

IRP team determines individuals needed to respond to each particular end case
Unique team for each attack scenario end case
Team leader specified in IR plan
Resources and skill sets added as necessary
IR plan specifies the scribe (archivist or historian)
Develops and maintains event log used in reviewing actions during the after-action review
CSIRT reaction force
The resulting incident team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is an after-action review (AAR)?

A

Detailed examination of events
Key players review and verify notes, documentation
Update plan and train future staff
IR team action closed

17
Q

What are the ways that training can be undertaken for the CSIRT?

A

Key part of CSIRT training
Strategies
Desk check, structured walk-through, simulation, parallel testing, full interruption, war gaming

18
Q

Briefly describe the strategies used to test contingency plans.

A

Desk check, structured walk-through, simulation, parallel testing, full interruption, war gaming

19
Q

Briefly describe the possible training delivery methods.

A

One-on-one, a dedicated trainer works with each trainee on the areas specified.

Formal class, a single trainer works with multiple trainees in a formal setting.

Computer-based training (CBT), prepackaged software provides training at the trainee’s workstation.

Distance learning and web seminars, trainees receive a seminar presentation at their computers. Some model allow teleconferencing for voice feedback; other have text questions and feedback.

User support group

On-the-job training

Self-study

20
Q

When should the “final” version of the IR plan be assembled?

A

Final IR plan document created
Once all individual IR plan components drafted and tested