Information Security Incident Management Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security Incident Management flashcards as text
What is a vulnerability as defined in the ISO 27000 vocabulary?
Answer: A weakness of an asset or control that can be exploited by one or more threats
ISO 27000 defines a vulnerability as a weakness of an asset or control that can be exploited by one or more threats, representing a potential entry point for harm.
What is the primary role of a Computer Security Incident Response Team (CSIRT)?
Answer: To coordinate and manage the organization's response to information security incidents
A CSIRT is specifically established to coordinate and execute responses to information security incidents, ensuring a structured and effective handling process.
How should digital evidence collected during an incident investigation be handled?
Answer: Preserved in a manner that maintains its integrity and admissibility
Evidence must be collected and preserved according to forensic best practices to maintain its integrity and ensure it remains admissible in legal proceedings if required.
Which phase of incident management involves removing the threat and restoring systems to normal operation?
Answer: Eradication and Recovery
The eradication and recovery phase involves removing malware, closing vulnerabilities, and restoring affected systems to their normal, trusted operational state.
What is an escalation procedure in the context of incident management?
Answer: A defined path for elevating an incident to higher management or specialists when needed
Escalation procedures define when and how an incident should be elevated to higher authority or specialized teams when it exceeds the current responder's ability or authority to handle it.
How does incident management relate to an organization's ISMS under ISO 27001?
Answer: Incident management is a required component of the ISMS covering response and improvement
ISO 27001 requires organizations to plan and implement incident management processes as a mandatory part of the ISMS, particularly through Annex A controls A.5.24 to A.5.28.
What is the key benefit of classifying information security incidents by type and severity?
Answer: It helps organizations allocate appropriate resources and set response priorities
Classifying incidents by type and severity enables organizations to prioritize response efforts and allocate the right level of resources, ensuring critical incidents receive immediate attention.