ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A global financial institution is redesigning its incident response plan. A key objective is to ensure that all security incidents, regardless of their origin or severity, are handled consistently and documented thoroughly. Which security operations concept is fundamental to achieving this consistency and detailed record-keeping?

  1. ALog Management
  2. BAsset Management
  3. CSecurity Awareness Training
  4. DPatch Management
Show answer & explanation

Correct answer: A. Log Management

Consistent handling and thorough documentation of security incidents heavily rely on effective log management. Logs provide the forensic evidence, activity records, and audit trails necessary to understand, respond to, and document incidents.

Why the other options are wrong

  • B. Asset management tracks IT assets but isn't primarily focused on incident documentation or consistent handling procedures.
  • C. Security awareness training educates users but doesn't directly provide incident documentation or consistency.
  • D. Patch management focuses on updating software to fix vulnerabilities, not on incident response documentation.

Log Management

The process of collecting, storing, analyzing, and securing log data from various systems and applications to support security, operational, and compliance requirements.

  • Crucial for incident detection and response.
  • Provides an audit trail for accountability.
  • Aids in compliance and forensic investigations.

Memory trick: Logs are the silent witnesses of every digital event, crucial for justice.

More Security Operations questions