click below
click below
Normal Size Small Size show me how
Incident response
| Question | Answer |
|---|---|
| incident | Act of violating an explicit or implied security policy |
| Incident response procedures | Guidelines for handling security incidents |
| Preparation | Involves strengthening systems and networks to resist attacks |
| Detection | Identifies security incidents |
| Analysis | Involves a thorough examination and evaluation of the incident |
| Containment | Limits the incident's impact by securing data and protecting business operations |
| eradication | Starts after containment and aims to remove malicious activity from the system or network |
| recovery | Restores systems and services to their secure state after an incident |
| post-incident activity or lessons learned | Happens after containment, eradication, and full system recovery |
| root cause analysis | Identifies the incident's source and how to prevent it in the future |
| lessons learned process | Documents experiences during incidents in a formalized way |
| after-action report | Collects formalized information about what occurred |
| threat hunting | Cybersecurity method for finding hidden threats not caught by regular security monitoring |
| establish a hypothesis | Predicting high impact, likely events through threat modeling |
| profiling threat actors and activities | Envisioning how potential attackers might intrude and what they aim to achieve |
| advisories and bulletins | Published by vendors and security researchers when new TTP's and vulnerabilities are discovered |
| intelligence fusion and threat data | Use SIEM and analysis platforms to spot concerns in the logs and real-world security threats |
| root cause analysis | A systematic process to identify the initial source of the incident and how to prevent it from occurring again |
| training | Ensures staff grasp processes and priorities for incident response |
| first responder | Procedures, machine, re-image, removing a malware, change configuration settings |
| Manager or executive | Risk vs reward, decision-making and communication, law enforcement and media |
| end User | Report suspected incident occurring, remedial training |
| testing | Practical exercise of incident response procedures |
| tabletop exercise (TTX) | Exercises simulate incidents within a control framework |
| penetration test | Simulates network intrusion based on threat scenarios |
| simulation | Replicates real incidents for hands-on experience |
| simple scenarios | Phishing or ransomware |
| complex scenarios | Multi stage attacks, data breaches in coordination with external parties |
| Digital forensic | Process of investigating and analyzing digital devices and data to uncover evidence for legal purposes |
| identification | Ensures the safety of the scene, secures it to prevent any evidence contamination, and determines the scope of the evidence to be collected |
| collection | Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields |
| order of volatility | Dictate the sequence in which data sources should be collected and preserved based on their susceptibility to modification or loss |
| chain of custody | Documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment it is collected until it is presented in a court of law |
| disk imaging | Involves creating a bit by bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space |
| file carving | Focuses on extracting files and data fragments from storage media without relying on the file system |
| analysis | Involves systematically scrutinizing the data to uncover relevant information, such as potential signs of criminal activity, hidden files, timestamps, and User interactions |
| reporting | involves documenting the findings, processes, and methodologies used during a digital forensic investigation |
| legal hold | Formal notification that instructions employees to preserve all potentially relevant electronic data, documents, and records |
| electronic discovery | Process of identifying, collecting, and producing electronically stored information during potential legal proceedings |
| data acquisition | The method and tools used to create a forensically sound copy of the data from a source device, such as system memory or a hard disk |