1/22
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
incident
act of violating an explicit or implied security policy
CompTIA Incident Response Process
preparation
detection and analysis
containment
eradication and recovery
post-incident activity
CompTIA Incident Response Process- 1
preparation
makes the system resilient to attacks by hardening systems, writing policies and procedures, and setting up confidential lines of communication
includes testing and exercises, preparing kits, and training staff
CompTIA Incident Response Process- 2
detection and analysis
determines if an incident has taken place, triage it, and notify relevant stakeholders
CompTIA Incident Response Process- 3
containment
limits the scope and magnitude of the incident by securing data and limiting impact to business operations and your customers
CompTIA Incident Response Process- 4
eradication and recovery
removes the cause of the incident and brings the system back to a secure state
post incident activity
analyzes the incident and the responses to identify whether procedures or systems could be improved
preparation
CompTIA Incident Response Process phase 1
makes the system resilient to attack by hardening systems, writing policies and procedures, and setting up confidential lines of communication
preparing for an incident response involves documenting procedures, putting resources and procedures in place, and conducting training
incidentresponse.com/playbook
gallery of playbooks that tell you exactly what to do in different scenarios
call list
a predefined list of Incident Response contacts in hierarchical order for notification and escalation
incident form
records the detail about the reporting of an incident and assigns it a case or job number
sensitive personal information(SPI)
information about a subject’s opinions, beliefs, and nature that is afforded specially protected status by privacy legislation
the GDPR definition of SPI includes religious beliefs, political opinions, trade union membership, gender, sexual orientation, racial or ethnic origin, genetic data, and health information
personal health information(PHI)
information that identifies someone as the subject of medical records, insurance records, hospital results, or laboratory test results
intellectual property
information created by an organization, usually about the products or services that it makes or provides
corporate information
confidential data owned by a company like product, sales, marketing, legal, and contract information
includes profit, cash flow, salaries, market shares, and key customers
out of band communication
signals are sent between two parties or devices that are sent via a path or method different from that of the primary communication between those two parties or devices
reporting requirements
notifcations that must be made to affected parties in the event of a data breach, as required by legislation or regulation
5 types of data breaches
data exfiltration
insider data exfiltration
device theft/loss
accidental data breach(public disclousre of information or unauthorized transfer caussed by human error or a misconfiguration)
integrity/availability breach
business continuity plan(BCP)
refers to the plans and processes used during a response to a disruptive event
disaster recovery plan(DRP)
refers specifically to the plans used during a disaster
hot site
site that is up and running continuously
warm site
site that is not fully equipped like a hot site
cold site
adds more time to recovery but is even cheaper than a warm site