Management of Information Security, Fourth Edition 3-5
1. Introduce the incident response plan (IR plan) as a plan designed to deal with the
effects of an unexpected event, and note that incident response planning (IRP) involves
4. List the key components of a typical IR policy that are recommended by NIST, such as
the statement of management commitment and purpose / objectives of the policy.
5. Discuss the characteristics of an event that make up an information security incident:
a. It is directed against information assets
b. It has a realistic chance of success
c. It threatens confidentiality / integrity / availability of information resources and
assets
6. Point out that incident response is a reactive measure, rather than a preventive one.
7. Explain how an organization’s IR plan is created by a CISO or IT manager, and note
10. Discuss incident classification as the process of examining an incident, or incident
candidate, to determine if it qualifies as a genuine incident. Note that this determination
is made by the IR team.
11. Provide some examples of candidates that would not qualify as incidents, such as
overloaded networks, computers, or servers.
12. List some of the indicators of an actual incident:
a. Presence of unfamiliar files
13. In comparison, list some probable indicators of an actual incident:
a. Activities at unexpected times
14. Explain that the following list consists of definite indicators of an incident:
a. Use of dormant accounts
15. Note that when the following actual incidents are confirmed, the corresponding IR must
be immediately activated: