Section 6 Incident Response

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/14

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

15 Terms

1
New cards

Incident Response Plans

provides structure during cybersecurity incidents and describes the policies and procedures governing cybersec incidents

2
New cards

Prior Planning

leads to a strong incident response

3
New cards

Incident Response Plan Elements

  • Statement of purpose

  • Strategies and goals for incident response

  • Approach to incident response

  • Communication with other groups

  • Senior leadership approval

4
New cards

Incident Response Teams must

have personnel available 24/7.

5
New cards

IR teams should be

worked with regularly, not just went an incident occurs

6
New cards

People in building an IR team

  • Management

  • Info sec teams

  • Subject Matter experts

  • Legal Counsel

  • Public Affairs

  • HR

  • Physical Security

7
New cards

Contractual details should be

worked out in advance of an incident

8
New cards

Communications Plans

ensure that all participants have timely accurate information

9
New cards

External communications to trusted parties

should be limited

10
New cards

The choice to involve law enforcement in an incident

is not required

11
New cards

Always involve your org’s legal team

True

12
New cards

Monitoring

is crucial to effective incident identification

13
New cards

Security Incident and Event Management (SIEM)

security solution that collects information from diverse sources, analyzes it for signs for security incidents and retains it for later use.

14
New cards

The first report of an incident may come from

external sources

15
New cards

The highest priority of a first responder

must be containing damage through isolation