CNS PreFinals Flashcards
(92 cards)
is an unexpected event occurring when an attack, whether natural or human-made, affects information resources and/or assets, causing actual damage or disruption to a business’s assets.
incident
is a detailed set of processes that anticipate, detect, and mitigate the effects of an unexpected event that might compromise information resources and assets.
incident response plan (IRP)
the set of procedures, policies, and guidelines that commence at the detection of an incident
incident response (IR).
- It is important to point out that an IRP is one of three major components of ____.
contingency plan (CP)
three major components of contingency plan (CP).
Incident Response
Disaster Recovery
Business Continuity
Personnel and Plan Preparation
- In a large business or organization the delegation of tasks is essential to maintaining effective operations. When looking at the makeup of an IRP, a __ assumes responsibility for the creation of it.
company’s CISO
With the aid of other managers and systems administrators on the contingency planning (CP) team, the __ should select members from each community of interest to form an independent IR team, which executes the IRP.
CISO
- __ should follow this six-step process when creating each of the three CP components [_, _, and _]:
Contingency planners
IRP, DRP, and BCP
six-step process when creating each of the three CP components [IRP, DRP, and BCP]:
- Identify the mission-or business-critical functions
- Identify the resources that support the critical functions
- Anticipate potential contingencies or disasters
- Select contingency planning strategies
- Implement the selected strategy
- Test and revise contingency plans
- Select contingency planning strategies
In regards to step four, for every incident, the CP team creates three sets of incident-handling procedures:
- During the incident
- After the incident
- Before the incident
- __: The planners develop and document the procedures that must be performed ____.
During the incident
_ during the incident
- _: Once the procedures for handling an incident are drafted, the planners develop and document the procedures that must be performed immediately after the incident has ceased.
After the incident
- _, _, or _, or s may be hard to distinguish from an actual incident.
Incident Detection
Overloaded networks, computers, or servers, misbehaving computers systems or software packages
- _: The planners draft a third set of procedures which are tasks that must be performed to prepare for the incident.
Before the incident
- It is the responsibility of the __ to determine if an incident is a valid incident or is just the product of “normal” system use.
Incident Detection
_ IR team
- Incident candidates can be detected and tracked by end-users through several means; _
Incident Detection
; intrusion detection systems (IDS), host- and network-based virus detection software, and systems administrators.
- Therefore, managers must ensure IT professionals receive training to detect __
Incident Detection
possible, probable, and definite indicators.
- Possible Indicators:
- Presence of unfamiliar files
- Presence or execution of unknown programs or processes
- Unusual consumption of computing resources
- Unusual system crashes
- Probable Indicators:
- Activities at unexpected times
- Presence of new accounts
- Reported attacks
- Notification from a host- or network-based
intrusion detection system (IDS)
- Definite Indicators:
- Use of dormant accounts
- Changes to logs
- Presence of hacker tools
- Notifications by business partner
- Notification by hacker
- Once an actual incident has been confirmed and properly classified, the __ needs to be directed to move from the detection phase to the reaction phase.
Incident Response
_IR team
is designed to first stop the incident (if still continuing), mitigate its effects, and provide information for the recovery from the incident.
Incident Response
_IR
Incident Response
- Three key steps include:
❑ Notification of Key personnel
❑ Documentation of an Incident
❑ Incident Containment strategies
Notification of key Personnel.
Incident Response