Detection and Response Flashcards
(7 cards)
Incident
An occurrence that actually or imminently jeopardizes, without lawful authority, confidentiality, integrity or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Event
An observable occurrence on a network, system to device.
The 5 W’s of an incident ?
- Who triggered the incident?
- What happened ?
- When the incident took place?
- Where the incident took place?
5.Why the incident occured?
Incident handlers journal?
A form of documentation used during an incident response.
Computer security incident response teams (CSIRT)
A specialized group of security professionals that are trained in incident management and response
Roles in CSIRT
1.Security analyst
2. Technical lead
3. Incident Cordinator