4.การจัดการสถานการณ์ที่ไม่พึงประสงค์/การบริหารอุบัติการณ์
(Incident Management)
4.0 CBK Competency Area Description:
Refers to knowledge and understanding of the process to prepare and prevent, detect, contain, eradicate, and recover, and the ability to apply lessons learned from incidents impacting the mission of an organization.
4.1 Task Statements: Manage
4.1.1 Coordinate with stakeholders to establish the incident management program.
4.1.2 Establish relationships between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies, vendors, and public relations professionals).
4.1.3 Acquire and manage resources, including financial resources, for incident management functions.
4.1.4 Ensure coordination between the incident response team and the security administration and technical support teams.
4.1.5 Apply lessons learned from information security incidents to improve incident management processes and procedures
4.1.6 Ensure that appropriate changes and improvement action are implemented as required.
4.1.7 Establish an incident management measurement program.
4.2 Task Statements: Design
4.2.1 Develop the incident management policy, based on standards and procedures for the organization.
4.2.2 Identify services that the incident response team should provide.
4.2.3 Create incident response plans in accordance with security policies and organizational goals.
4.2.4 Develop procedures for performing incident handling and reporting.
4.2.5 Create incident response exercises and penetration testing activities.
4.2.6 Develop specific processes for collecting and protecting forensic evidence during incident response.
4.2.7 Specify incident response staffing and training requirements
4.2.8 Establish an incident management measurement program.
4.3 Task Statements: Implement
4.3.1 Apply response actions in reaction to security incidents, in accordance with established policies, plans, and procedures.
4.3.2 Respond to and report incidents.
4.3.3 Assist in collecting, processing, and preserving evidence according to standards, procedures, directives, policies, regulations, and laws (statutes).
4.3.5 Execute incident response plans.
4.3.6 Execute penetration testing activities and incidence response exercises.
4.3.7 Ensure lessons learned from incidents are collected in a timely manner, and are incorporated into plan reviews
4.3.8 Collect, analyze and report incident management measures
4.3.9 Coordinate, integrate, and lead team responses with internal and external groups according to applicable policies and procedures.
4.4 Task Statements: Evaluate
4.4.1 Assess the efficiency and effectiveness of incident response program activities, and make improvement recommendations
4.4.2 Examine the effectiveness of penetration testing and incident response test, training, and exercises.
4.4.3 Assess the effectiveness of communications between the incident response team and related internal and external organizations, and implement changes where appropriate
4.4.4 Identify incident management improvement actions based on assessments of the effectiveness of incident management procedures.
4.5 Knowledge Statements, Key /terms And Concepts:
• Computer Security
• Information Stakeholder
• Escalation Procedures
• Information System
• Incident Handling
• Intrusion
• Incident Records
• Measures
• Incident Response
• Personally Identifiable Information (PII)
• Information Assurance Posture
• Information Security Policy
• Reconstitution of System
• Risk
• System Compromise
• Risk Assessment
• Threat Motivation
• Risk Management
• Unauthorized Access
• Security Alerts
• Vulnerability
• Security Incident