Information Security Incident Management Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information Security Incident Management flashcards as text
According to ISO 27000, what is an information security event?
Answer: An identified occurrence indicating a possible breach of information security policy
ISO 27000 defines an information security event as an identified occurrence of a system, service, or network state indicating a possible breach of policy, failure of controls, or a previously unknown security-relevant situation.
How does ISO 27000 distinguish an information security incident from an information security event?
Answer: An incident is an event assessed to have a significant probability of compromising business operations
An information security incident is one or more unwanted or unexpected events that have a significant probability of compromising business operations and threatening information security, distinguishing it from a mere event.
What is the correct order of the first three phases in a typical information security incident response lifecycle?
Answer: Detection and Identification → Containment → Eradication and Recovery
Incident response begins with detecting and identifying the incident, then containing its spread, and then eradicating the cause and recovering affected systems.
What is the purpose of triage in information security incident management?
Answer: To prioritize incidents based on their severity and potential business impact
Triage involves assessing and prioritizing incidents so that the most critical ones receive immediate attention first, based on severity and potential business impact.
Which of the following is an example of a containment action during incident response?
Answer: Isolating compromised systems from the network to prevent further spread
Containment limits the spread and impact of an incident; isolating affected systems from the network is a classic containment technique that stops further damage.
What is the primary purpose of conducting a post-incident review?
Answer: To identify lessons learned and improve future incident prevention and response
Post-incident reviews (lessons learned sessions) aim to identify what worked well, what failed, and how processes and controls can be improved to prevent or better handle future incidents.
Which ISO standard specifically provides guidance on information security incident management?
Answer: ISO 27035
ISO 27035 is the dedicated standard that provides guidelines for information security incident management, covering principles and processes for planning and responding to incidents.