227. Incident Response, 228. Incident Response Process

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

24 Terms

1
New cards

Incident Response Process

Outlines structured approach to manage and mitigate security incidents effectively

2
New cards

Incident

Act of violating an explicit or implied security policy

3
New cards

Incident Response Procedures

Guidelines for handling security incidents

4
New cards

Incident Response Cycle Phase 1

Preparation

5
New cards

Incident Response Cycle Phase 2

Detection

6
New cards

Incident Response Cycle Phase 3

Analysis

7
New cards

Incident Response Cycle Phase 4

Containment

8
New cards

Incident Response Cycle Phase 5

Eradication

9
New cards

Incident Response Cycle Phase 6

Recovery

10
New cards

Incident Response Cycle Phase 7

Post-incident activity/Lessons learned

11
New cards

Preparation

Strengthening systems and networks to resist attacks; Getting ready for future incidents

12
New cards

Detection

Identifies security incidents

13
New cards

Analysis

Involves a thorough examination and evaluation of the incident; Stakeholders are informed, containment begins, and initial response actions are taken

14
New cards

Containment

Limits the incident's impact by securing data and protecting business operations

15
New cards

Eradication

Aims to remove malicious activity from the system or network

16
New cards

Recovery

Restores systems and services to their secure state after an incident

17
New cards

Post-incident activity/Lessons learned

Spend time analyzing incident and response to it to make sure everything was as efficient as it should be

18
New cards

Root Cause Analysis

Identifies the incident's source and how to prevent it in the future

19
New cards

Root Cause Analysis Step 1

Define/scope the incident

20
New cards

Root Cause Analysis Step 2

Determine the causal relationships that led to the incident

21
New cards

Root Cause Analysis Step 3

Identify an effective solution

22
New cards

Root Cause Analysis Step 4

Implement and track the solutions

23
New cards

Lessons Learned Process

Document experiences during incidents in a formalized way

24
New cards

After-Action Report

Collects formalized info about what occurred