1/43
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Incident Response
Outlines a structured approach to manage and mitigate security incidents effectively. Minimize impact, reduce response time, hasten recovery
Incident
Act of violating an explicit or implied security policy
Incident Response Procedures
Guidelines for handling security incidents
Incident Response Steps
Preparation, Detection, Analysis, Containment, Eradication, Recovery, Post-Incident Activity
Preparation
Get everything ready for future incidents. Gets an organization ready for future incidents. Focuses on making systems resilient to attacks by hardening systems and networks
Detection
Determines if a security incident has occurred. Identifies a security incident
Eradication
Starts after containment and aims to remove malicious activity from the system or network
Analysis
Involves a thorough examination of the incident
Containment
Limits the incidents impact by securing data and protecting business operations
Recovery
Restores systems and services to their normal secure state
Post-Incident Activity
Happens after containment, eradication, and full system recovery. Analyze the situation and see if you effectively taken care of the incident
Root cause analysis
Identifies the incident’s source and how to prevent it in the future. Define/scope the incident, Determine what caused the incident, Identify an effective solution, implement and track solutions
Lessons Learned Process
Documents experienced during incidents in a formalized way
After-action Report
Collects formalized information about what occurred
Incident Response Teams
The core team includes cybersecurity professionals with incident response experience
Threat Hunting
Cybersecurity method for finding hidden threats not caught by regular security monitoring
Threat Hunting Steps
Establish a Hypothesis, Profiling Threat Actors and Activities, Threat Hunting Process
Benefits of Threat Hunting
Improves detection capabilities by identifying threats that bypass existing defenses. Enhances threat intelligence by correlating external threat feeds with internal logs. Provides actionable intelligence to strengthen security measures
Advisories and Bulletins
Published by veneers and security researchers when new TTPs and vulnerabilities are discovered
Intelligence Fusion and Threat Data
Use SIEM and analysis platforms to spot concerns in the logs and real-world security threats
Define the scope of the incident
What is the cause and how big is the impact?
Determine the Causal Relationship
Understand how the incident occurred, such as through malware
Identify an effective solution
Find solutions to prevent the incident from recurring
Implement and Track Solutions
Execute the solutions and ensure the incident is fully resolved
No-Blame Approach
Can encourage open reporting to improve cybersecurity. Root Cause Analysis should not assign blame to individuals or teams.
Training
Ensures staff grasp processes and priorities for incident responses. Tailor it to all employees based on needs. Base it on lessons learned from past incidents
Testing
Practical exercise of incident response procedures. Costly and can be complex. Use a tabletop exercise, Penetration Test, or a Simulation
Tabletop Exercise (TTX)
Exercises simulate incidents within a control framework
Simulation
Replicates real incidents for hands on experience
Digital Forensics
Systematic process of investigating and analyzing digital devices and data to uncover evidence for legal purposes. Identification, Collection, analysis, and reporting
Identification
Focus on scene safety, prevention of evidence contamination, and scope determination. Secure the scene, preserve evidence, and document the scene. Identify where relevant data might be stored
Collection
Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields
Order of Volitility
Dictates the sequence in which data sources should be collected and preserved based on their susceptibility to be modification or loss. First collect system memory, data from system state, storage device, network traffic and logs, remotely stored or archived data
End User Training
Report incidents and remedial training for people who make mistakes
Chain of Custody
Documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment it is collected until it is presented in a court of law
Disk Imaging
Involves creating a bit-by-bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space
File Carving
Focuses on extracting files and data fragments from storage media without relying on the file system
Analysis for digital forensics
Systematically scrutinizing the data to uncover relevant information
Reporting for digital forensics
Involves documenting the findings, processes, and methodologies used during a digital forensics investigations
Legal Hold
Formal notification that instructs employees to preserve all potentially relevant event electronic data, documents, and records
E-Discovery (Electronic Discovery)
Process of identifying, collecting, and presenting electronically stored information for potential legal proceedings. Involves searching, analyzing, and formatting electronic data for litigation
Ethical considerations for digital forensics
Avoiding Bias, Repeatable Actions, Evidence Preservation
Data Acquisition
The method and tools used to create a forensically sound copy of the data from a source device, like system memory or a hard disk