Investigations
Support evidence collection, handling, reporting, forensics, eDiscovery, and investigation requirements with appropriate authority.
- Lesson
- d7-lesson
- Practice pool
- d7-questions
- Application
- cissp-s08
Operate investigations, monitoring, configuration, change, incidents, vulnerability management, recovery, continuity, physical security, and personnel safety.
Support evidence collection, handling, reporting, forensics, eDiscovery, and investigation requirements with appropriate authority.
Design and operate logging, event management, threat intelligence, behavior analytics, ingress/egress monitoring, and continuous control monitoring.
Establish baselines, inventories, hardening, versioning, drift control, approved exceptions, and configuration evidence.
Apply need-to-know, least privilege, separation, job rotation, service levels, privileged operations, and resource lifecycle controls.
Protect media, systems, facilities, data, keys, credentials, hardware, and operational resources through their lifecycle.
Prepare, detect, respond, mitigate, report, recover, remediate, learn, and coordinate communications for incidents.
Operate firewalls, intrusion systems, whitelisting/blacklisting, sandboxing, antimalware, machine learning, and related controls.
Discover, assess, prioritize, test, remediate, verify, accept, and monitor vulnerabilities and patches based on risk.
Assess, authorize, test, schedule, communicate, implement, validate, document, and roll back operational changes.
Select alternate sites, backups, resilience, restoration, communications, suppliers, and recovery approaches from business requirements.
Execute response, personnel, communications, assessment, restoration, salvage, failback, and return-to-normal activities.
Use tabletop, walkthrough, simulation, parallel, and full-interruption methods with safe objectives and corrective action.
Maintain business continuity plans, dependencies, alternate processes, communication, exercises, measures, and improvement.
Operate facility access, monitoring, environmental, visitor, asset, restricted-area, and emergency physical controls.
Protect people through travel, lone-worker, duress, emergency, evacuation, communications, and safety procedures.
Operations turns policy and architecture into controlled daily behavior. The senior-practitioner mindset is authority and safety first, preserve evidence, stabilize business impact, use reversible action, restore trusted operation, then remove root cause and improve.
Operational controls need owners, runbooks, service objectives, access, tools, evidence, exceptions, exercises, and feedback. A control that is configured but not monitored, tested, or maintained will decay.
| Objectives | Decision focus |
|---|---|
| 7.1–7.2 Investigations, logging, and monitoring | Collect and protect evidence under appropriate authority; turn logs, intelligence, analytics, and monitoring into owned decisions |
| 7.3–7.5 Configuration, operations concepts, resource protection | Maintain inventories, baselines, least privilege, separation, service levels, and lifecycle protection |
| 7.6–7.9 Incidents, controls, vulnerability/patch, change | Prepare, detect, contain, recover, prevent, prioritize, authorize, test, deploy, verify, and roll back |
| 7.10–7.13 Recovery, disaster recovery, testing, continuity | Translate business impact into strategies, plans, exercises, communications, restoration, and improvement |
| 7.14–7.15 Physical security and personnel safety | Operate facility and emergency controls with protection of people as the first priority |
Determine investigation type, authority, privacy limits, legal or regulatory involvement, and evidence requirements before collection. Preserve original evidence and work from controlled copies. Record collector, source, time, method, integrity, transfers, storage, and access. Coordinate with legal, HR, law enforcement, regulators, insurers, or suppliers through approved processes.
For digital forensics, consider volatility and order of collection, but do not perform an unsafe or unauthorized action to follow a generic order. Time synchronization, system state, memory, processes, network connections, logs, storage, cloud control-plane records, snapshots, backups, identity events, and external providers may contribute. Cloud and SaaS evidence depends on service capabilities and shared responsibility.
eDiscovery concerns identification, preservation, collection, processing, review, and production under legal authority. A litigation hold can suspend normal deletion. Security teams support preservation and technical collection; counsel directs legal decisions.
Define events from response questions. Collect identity, endpoint, network, DNS, application, cloud, data, physical, and control-plane evidence as needed. Protect integrity, access, time, retention, and privacy. Normalize carefully while retaining original records or durable references. Correlate principal, asset, action, data, time, and outcome.
Security information and event management can aggregate and correlate; orchestration and automation can route or act; behavior analytics can identify deviations; threat intelligence can add context. None eliminates validation and ownership. Evaluate intelligence source, timeliness, relevance, confidence, and permitted use. Indicators expire; behaviors and adversary methods can provide more durable hypotheses.
Tune detections with false-positive and false-negative analysis. Suppression needs owner and expiry. Measure coverage, delivery, alert quality, time to triage, time to contain, and recurring blind spots. Avoid logging secrets and sensitive content without purpose and controls.
Maintain hardware, software, cloud, network, data, identity, certificate, key, supplier, and owner inventories. Establish secure baselines, version configuration, detect drift, authorize exceptions, and reconcile actual state. Hardening includes removing defaults, disabling unnecessary services, least privilege, patching, secure protocols, logging, backup, and support status.
Apply need to know, least privilege, separation of duties, job rotation where appropriate, mandatory leave for certain fraud risks, two-person control for high-impact action, and service-level agreements. Protect privileged operations and maintenance tools. Track media, keys, devices, spare parts, licenses, and end-of-life resources.
Job scheduling, batch processing, backups, and automation need identity, input validation, dependencies, failure handling, evidence, and ownership. Protect scripts and pipelines as production code. Capacity, quotas, certificates, and support expiry are operational risks.
Prepare roles, communications, access, evidence, playbooks, suppliers, exercises, and recovery. Detect and analyze to validate event, scope assets and identities, assess business impact, and prioritize. Contain with the least destructive effective action. Eradicate persistence and enabling weaknesses. Recover from known-good state, validate integrity and monitoring, obtain business acceptance, and track lessons.
Communication must be accurate, authorized, audience-appropriate, and timely. Maintain one decision log and distinguish confirmed facts, hypotheses, and unknowns. Legal and executive owners decide external notification under applicable requirements.
Preventive and detective technologies—firewalls, IDS/IPS, allow/deny lists, endpoint protection, sandboxing, antimalware, analytics, and machine learning—have scope and failure modes. Layer them with identity, configuration, patching, awareness, monitoring, and response.
Discover assets and vulnerabilities, validate exposure, prioritize from exploitability, asset criticality, data, access path, threat activity, compensating controls, and business impact. Select remediation, mitigation, acceptance, or removal. Test changes, schedule by risk and operations, deploy, verify, and monitor. Exceptions need owner, rationale, compensating control, expiry, and review.
Patch management is a controlled change process, not merely installation. Address dependencies, backups, compatibility, rollback, emergency approval, and verification. A patch can fail to deploy, fail to remove exposure, or create new business impact.
Change management records request, impact, risk, affected configuration, security review, test, approval, schedule, communication, implementation, validation, rollback, and documentation. Standard changes are pre-authorized within defined conditions. Emergency change accelerates process but still requires authority, evidence, validation, and retrospective review. Detect unauthorized change.
Business continuity sustains critical products and processes. Disaster recovery restores technology and facilities that support them. Use BIA-derived priorities, RTO, RPO, maximum tolerable disruption, dependencies, people, suppliers, alternate work methods, and communications.
Recovery options include backups, alternate sites, redundancy, replication, spare equipment, manual processes, cloud capacity, reciprocal arrangements where credible, and third-party services. Hot, warm, and cold site labels describe readiness and cost but do not prove objectives. Protect recovery data and credentials from the same incident as production.
During disaster response, protect people, declare through authority, communicate, assess damage, activate strategies, restore in business priority, validate, operate in contingency, salvage safely, fail back deliberately, and return to normal. Test through checklist, tabletop, walkthrough, simulation, parallel processing, or full interruption as risk permits. Every exercise needs objectives, safety, evidence, corrective action, owner, and retest.
Operate layered facility access, visitor management, surveillance, alarms, guards, locks, barriers, lighting, power, cooling, fire detection and suppression, water protection, emergency power, equipment protection, and restricted areas. Keep logs and test emergency systems. Coordinate cyber and physical monitoring.
Personnel safety overrides asset protection. Plan evacuation, shelter, emergency communication, duress, lone work, travel, medical response, muster, and responder access. Do not require an employee to preserve equipment or evidence at unreasonable personal risk.
A privileged account behaves anomalously during a production change while a regional storm threatens the primary facility.