CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A financial services firm is updating its incident response plan. The firm has identified that phishing attacks are the most common initial vector for security breaches. To improve their response capability, they decide to implement an automated email analysis tool that quarantines suspicious emails and provides immediate alerts to the security operations center (SOC). This action primarily aims to improve which phase of the incident response lifecycle?

  1. ARecovery
  2. BEradication
  3. CPreparation
  4. DDetection and Analysis
Show answer & explanation

Correct answer: D. Detection and Analysis

Implementing an automated email analysis tool that quarantines suspicious emails and provides immediate alerts directly enhances the ability to quickly identify and understand security incidents, which falls under the Detection and Analysis phase of incident response.

Why the other options are wrong

  • A. Recovery focuses on restoring systems and services, occurring much later in the process.
  • B. Eradication involves removing the cause of the incident, which happens after detection.
  • C. Preparation involves activities *before* an incident, like training or developing the plan, but this tool is for active incident handling.

Detection and Analysis (Incident Response)

The phase of incident response focused on identifying security events, determining if they are actual incidents, and analyzing their scope, nature, and impact.

  • Involves monitoring systems and alerts.
  • Aims for rapid identification of incidents.
  • Includes initial assessment and categorization.

Memory trick: Plan, Detect, Contain, Eradicate, Recover, Post-mortem.

More Information Technology and Security questions