1/27
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is NIST
National Institute of Standards and Technology. A U.S. government organization that creates cybersecurity standards, frameworks, and guidelines. NIST publications are free
What is ISO/IEC?
International organizations that create internationally recognized standards and guidelines. Unlike NIST publications, official ISO/IEC standards generally must be purchased
What is incident management?
A predictable response to damaging situations.
What NIST publication is a major resource for incident response?
NIST SP 800-61 Rev. 3.
What is CISA?
The Cybersecurity and Infrastructure Security Agency. It is part of the U.S. Department of Homeland Security and helps protect cybersecurity and critical infrastructure.
What is US-CERT?
The United States Computer Emergency Readiness Team. It is part of CISA and assists government organizations with cyber threats and incidents.
What is an information security incident?
A violation or threat of violation of computer security policies, acceptable-use policies, or standard security practices.
What parts of the CIA triad can an information security incident affect?
Confidentiality, integrity, and availability.
What is an event?
Any observable occurrence in a system or network.
What is an adverse event?
An event that has a negative consequence, such as a system crash, unauthorized access, or malware execution.
What is a disaster?
An event that causes widespread damage or destruction, loss of life, or drastic environmental change.
Why should organizations perform periodic risk assessments?
To identify risks created by threats, threat sources, and vulnerabilities so the risks can be reduced to an acceptable level.
How can risks be handled?
Risks can be mitigated, transferred, or avoided until an acceptable level of risk is reached.
What should organizations have prepared before an incident happens?
Policies, strategies, plans, procedures, trained personnel, and mock exercises.
What are the four major incidents all organizations should plan to defend against?
Intentional unauthorized access, DDoS attacks, malicious code or malware, and inappropriate usage.
What is intentional unauthorized access?
When an insider or intruder gains logical or physical access to a network, system, application, data, or other resource without permission.
What is a DDoS attack?
An attack that prevents or harms normal network, system, or application functions by exhausting resources or overloading communications
What is malicious code or malware?
Code inserted with the intent to gain unauthorized access, steal information, disrupt operations, destroy data, or compromise a system.
What is inappropriate usage?
When an authorized user performs actions that violate policy, an agreement, law, or regulation.
What is a false positive?
A security system sounds an alarm even though there is no malicious activity or attack
What is a false negative?
A real security event occurs, but the security system fails to detect it.
What is a true positive?
A security system correctly identifies a real attack or malicious event.
What is a true negative?
A security system correctly identifies that there is no malicious event.
Why are incident severity levels important?
They classify incidents based on their impact and help determine response times and notification requirements
What types of incidents should employees report?
Both actual incidents and suspected incidents.
Why is chain of custody important?
It documents and preserves evidence so the evidence can be proven reliable if it is needed in court.
What four things make up an incident response program?
Policies, plans, procedures, and people
What do policies do in an incident response program?
They document management directives.