Investigations
Support evidence collection, handling, reporting, forensics, eDiscovery, and investigation requirements with appropriate authority.
- Lesson
- d7-lesson
- Practice pool
- d7-questions
- Application
- cissp-s08
Operate investigations, monitoring, configuration, change, incidents, vulnerability management, recovery, continuity, physical security, and personnel safety.
Support evidence collection, handling, reporting, forensics, eDiscovery, and investigation requirements with appropriate authority.
Design and operate logging, event management, threat intelligence, behavior analytics, ingress/egress monitoring, and continuous control monitoring.
Establish baselines, inventories, hardening, versioning, drift control, approved exceptions, and configuration evidence.
Apply need-to-know, least privilege, separation, job rotation, service levels, privileged operations, and resource lifecycle controls.
Protect media, systems, facilities, data, keys, credentials, hardware, and operational resources through their lifecycle.
Prepare, detect, respond, mitigate, report, recover, remediate, learn, and coordinate communications for incidents.
Operate firewalls, intrusion systems, whitelisting/blacklisting, sandboxing, antimalware, machine learning, and related controls.
Discover, assess, prioritize, test, remediate, verify, accept, and monitor vulnerabilities and patches based on risk.
Assess, authorize, test, schedule, communicate, implement, validate, document, and roll back operational changes.
Select alternate sites, backups, resilience, restoration, communications, suppliers, and recovery approaches from business requirements.
Execute response, personnel, communications, assessment, restoration, salvage, failback, and return-to-normal activities.
Use tabletop, walkthrough, simulation, parallel, and full-interruption methods with safe objectives and corrective action.
Maintain business continuity plans, dependencies, alternate processes, communication, exercises, measures, and improvement.
Operate facility access, monitoring, environmental, visitor, asset, restricted-area, and emergency physical controls.
Protect people through travel, lone-worker, duress, emergency, evacuation, communications, and safety procedures.
Security operations joins logging, investigations, configuration, privileged work, resource protection, incidents, detection, vulnerability management, change, recovery, continuity, physical security, and personnel safety.
Prepare investigation authority and evidence handling before events. Build time-consistent logging, monitoring, intelligence, behavior, ingress/egress, and control-health visibility. Protect baselines, inventories, configuration, media, keys, credentials, systems, and facilities through their lifecycle.
Incident management prepares, detects, analyzes, contains, eradicates, recovers, communicates, reports, and improves. Preserve safety, evidence, reversibility, and business continuity. Vulnerability and patch management prioritizes exploitability, exposure, asset value, control context, testing, remediation, exceptions, verification, and monitoring. Change management authorizes, tests, schedules, communicates, implements, validates, documents, and rolls back.
Recovery strategy comes from business priorities and dependencies. Test backups, alternate sites, communications, personnel, suppliers, restoration, reconciliation, failback, and return to normal. Exercises produce corrective actions. During physical emergencies, personnel safety precedes asset protection.
Order the first actions for a privileged-account incident during a regional facility emergency. Explain authority, safety, evidence, containment, communication, continuity, restoration, and lessons learned.