GCGA Ch. 11 Incident Response (ST) Flashcards
(8 cards)
Incident response policy
defines incident response procedures. Organizations review and update incidents periodically and after reviewing lessons learned after actual incidents.
Communication plan
identifies who to inform when an incident occurs. It also outlines the roles and responsibilities of various personnel, including a communication expert that would communicate with the media.
First step in incident response
preparation. It includes creating and maintaining an incident response policy and includes prevention steps such as implementing security controls to prevent malware infections.
Second step in incident response
analysis. After detecting a potential incident, personnel perform an analysis to confirm that a security incident is underway.
Third step in incident response
containment. Next, they attempt to contain or isolate the problem. Disconnecting a computer from a network will isolate it.
Fourth step in incident response
eradication attempts to remove all malicious components left after an incident. Recovery restores a system to its original state. Depending on the scope of the incident, administrators might completely rebuild the system, including applying all updates and patches.
Reviewing lessons learned
A review of lessons learned helps an organization prevent a reoccurrence of an incident.
Tabletop exercises vs simulations
Tabletop exercises are a type of scenario-based training where participants discuss and analyze a hypothetical incident in a non-threatening environment, whereas simulations involve recreating real-world incidents as closely as possible.