Isaca Certified Information Systems Auditor CISA Question # 329 Topic 33 Discussion
CISA Exam Topic 33 Question 329 Discussion:
Question #: 329
Topic #: 33
The operations team of an organization has reported an IS security attack Which of the following should be the FIRST step for the security incident response team?
The first step for the security incident response team after an IS security attack is reported is to perform a damage assessment. This involves identifying the scope, impact and root cause of the incident, as well as collecting and preserving evidence for further analysis and investigation. Reporting results to management, documenting lessons learned and prioritizing resources for corrective action are important steps, but they should be done after the damage assessment is completed. References: CISA Review Manual (DigitalVersion), Chapter 6, Section 6.31
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit