ISC2 Certified in Cybersecurity (CC) flashcards
133 free flashcards. Tap a card to flip it.
Incident Response: Recovery Phase
Flip cardThe phase of incident response where affected systems, services, and data are restored to operations, often from clean backups, after the threat has been contained and eradicated.
- Involves restoring data and systems.
- Verifies full functionality and security.
- Often the most time-consuming phase.
Memory trick: PDCRPE: Prepare, Detect, Contain, Eradicate, Recover, Post-incident.
Incident Response: Containment Phase
Flip cardThe phase of incident response focused on limiting the scope and impact of an incident by isolating affected systems and preventing further damage.
- Objective: Stop the spread of the incident
- Actions: Isolate systems, disconnect networks, change firewall rules
- Precedes eradication and recovery
Memory trick: Preparation, Detection, Containment, Eradication, Recovery, Post-Incident.
Incident Response Planning (IRP)
Flip cardThe process of creating and maintaining a structured, documented approach that an organization will follow to prepare for, detect, contain, eradicate, recover from, and learn from security incidents.
- Defines roles, responsibilities, and communication channels.
- Outlines specific procedures for various types of incidents.
- A critical component of an overall cybersecurity strategy.
Memory trick: IRP: 'I'ncident 'R'esponse 'P'lan, your playbook for cyber-attacks.
Full Backup
Flip cardA backup strategy that copies all selected data, regardless of when it was last changed. It's the simplest to restore but requires the most storage and time.
- Copies all data every time
- Fastest recovery process
- Highest storage space requirement
Memory trick: Full, Incremental, Differential: Each has its Recovery-Storage balance.
Recovery Time Objective (RTO)
Flip cardThe maximum acceptable duration of time that a business process or system can be unavailable after an incident or disaster before unacceptable consequences occur.
- Determines the speed at which recovery must happen.
- Expressed in time (e.g., 4 hours, 24 hours).
- Should always be less than or equal to the MTD.
Memory trick: RTO: Recovery Time's Target Objective.
Testing BC/DR Plans
Flip cardThe process of regularly exercising business continuity and disaster recovery plans to identify deficiencies, validate procedures, and ensure the plan's effectiveness in meeting recovery objectives.
- Can range from tabletop exercises to full-scale simulations.
- Essential for maintaining plan relevance and readiness.
- Often leads to plan updates and improvements.
Memory trick: Test, Test, 1-2-3: Find the flaws before disaster strikes me!
Incident Handling: Containment Phase
Flip cardThe phase of incident handling focused on limiting the scope and impact of a security incident by preventing further damage, spread, or compromise.
- Involves actions like isolating systems, disconnecting networks, or stopping services.
- Aims to reduce the immediate threat.
- Often involves short-term, medium-term, and long-term strategies.
Memory trick: Containment: Like a 'container', keeping the bad stuff from spreading.
Failover
Flip cardA backup operational mode in which the functions of a system component (e.g., server, network) are assumed by a secondary system component when the primary component becomes unavailable.
- Typically automatic and transparent to users.
- Ensures high availability and business continuity.
- Requires redundant hardware and often real-time data synchronization.
Memory trick: Failover: When one 'fails', the other 'takes over' seamlessly.
Tabletop Exercise
Flip cardA discussion-based exercise that involves key personnel meeting in a conference room setting to discuss their roles and responsibilities during an emergency and how they would respond to a particular incident scenario.
- Low cost and low impact.
- Identifies gaps, misunderstandings, and weaknesses in plans.
- Does not involve actual system or facility activation.
Memory trick: Tabletop: Talking Through The Plan.
Post-Incident Activity
Flip cardThe final phase of incident response, involving review, documentation, and improvement of security measures and incident response plans after an incident has been resolved.
- Focuses on lessons learned.
- Aims to prevent recurrence.
- Includes updating policies and procedures.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Review: P.D.C.E.R.R.
Risk Management
Flip cardThe systematic process of identifying, assessing, and controlling threats to an organization's capital and earnings.
- Involves identification, assessment, and treatment of risks.
- A continuous process, not a one-time event.
- Aims to balance risk with cost of controls.
Memory trick: Manage risks, don't just react.
Secure Disposal (Degaussing)
Flip cardA method of secure data disposal for magnetic media that uses a strong magnetic field to neutralize the drive's magnetic properties, rendering data unrecoverable.
- Effective for hard disk drives and magnetic tapes.
- Cannot be used on solid-state drives (SSDs).
- Typically renders the media unusable afterward.
Memory trick: Only total obliteration ensures data is truly gone.
Behavioral Anomaly Detection
Flip cardA security monitoring technique that identifies deviations from established normal patterns of user or system behavior, signaling potential security incidents.
- Learns 'normal' behavior over time.
- Can detect novel or zero-day attacks.
- Often results in a higher rate of false positives.
Memory trick: Anomalies are the red flags, signatures are the wanted posters.