← All ISO 27000 Foundation Certification Flashcard Decks

Information Security Incident Management Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Security Incident Management flashcards as text
  1. What is the purpose of an incident communication plan in information security?

    Answer: To define how, when, and to whom information about incidents is communicated

    An incident communication plan defines who must be notified, what information to share, when to communicate, and through which channels, covering both internal and external stakeholders.

  2. What does 'dwell time' refer to in the context of information security incidents?

    Answer: The period an attacker remains undetected within a compromised system

    Dwell time is the period between when an attacker first gains access to a system and when the breach is detected; shorter dwell time generally means less damage.

  3. Which concept best describes 'lessons learned' in incident management?

    Answer: A structured post-incident review to identify improvements in prevention and response

    Lessons learned is a post-incident review process where the organization examines what happened, evaluates the response, and identifies actionable improvements to prevent or better handle future incidents.

  4. According to ISO 27000, what is a 'threat' in information security?

    Answer: A potential cause of an unwanted incident that may result in harm to assets

    ISO 27000 defines a threat as a potential cause of an unwanted incident which may result in harm to a system or organization — it is a potential, not necessarily realized, source of harm.

  5. What is the key difference between reactive and proactive incident management approaches?

    Answer: Proactive management involves threat hunting before incidents occur; reactive management responds after detection

    Proactive incident management involves activities like threat hunting to find threats before they cause incidents, while reactive management activates response procedures after an incident is detected.

  6. What role does forensic analysis play in information security incident management?

    Answer: It collects and analyzes digital evidence to understand how an incident occurred

    Forensic analysis involves the systematic collection and examination of digital evidence to determine the cause, scope, and method of an incident, supporting remediation efforts and potential legal proceedings.

  7. What is the relationship between information security incident management and business continuity planning?

    Answer: Major security incidents may trigger business continuity plans, making them complementary

    Information security incident management and business continuity are complementary: when an incident is severe enough to disrupt operations, the business continuity plan is activated, and together they ensure organizational resilience.