Pratica di Shadowing: Incident Management Process: A Step by Step guide - Impara a parlare inglese con i video

Creazione lezione...
1
hi team welcome to my session on coffee with prab
2
and today we're going to discuss about incident management process this is a very important topic
3
if you're preparing for the cissp exam or other ic square
4
or isaka copshia ec council exams and all that along with
5
that this topic is highly asked in a interview jobs like jrc sock
6
and all that i received a lot of feedback prab can you make a video on
7
that so i thought let me make a video on this team if you're new to the channel, do subscribe to my YouTube channel
8
and click on the bell icon to make sure you should not miss my similar kind of videos in the future.
9
My name is Prabh Nayar, for more information you can refer to my LinkedIn profile.
10
So without wasting time, let's start with the first part.
11
Hello everyone, my name is Prabh Nayar and I am working as Chief Instructor at Infosec
12
So when we're talking about incident management process, incident management process is basically divided into the four stages.
13
They have four stages.
14
The first part or first stage is called as a preparation.
15
The second part called as a detection and analysis.
16
The third step or third stage is called as a containment eradication and recovery.
17
And the fourth stage or fourth step is called as a post incident activity.
18
So these are the four steps we have or four stages we have.
19
So when we're talking about incident management process, the ultimate goal of the incident management process is to reduce the impact.
20
Always remember but before going to understand the stages in detail let's understand what is incident
21
so if you go by the definition incident is any series of activity
22
which impact the organization in negative manner that is called as an incident
23
and every incident is an event
24
but not every event is an incident let me explain you let me understand the thinner difference between the event
25
and incident i have a session i have to start a session by 6 30
26
and i i trigger an app
27
and app open initiated at 6 30 we start a session by 6 30
28
which is basically run as per the business objective
29
that is a event but app doesn't trigger till 6 30 trigger by 6 40
30
or fail to continue it impact my cia then it become an incident
31
because here we breach the sla that is the thin line difference event
32
and incident you are attending
33
so your parents make you full makeup shake up you make
34
you ready to attend one marriage event you're going with this impression you are threatening one marriage event
35
and later on you got to know your marriage got fixed in
36
that event then it has become an incident for you now you understand
37
so every incident is an event but not every event is an incident
38
so let's start with the first part
39
which is basically called as a stage one preparation in a
40
stage one the first step is called as a policy any
41
kind of a system you are introducing in the organization any
42
kind of a system you are introducing in the organization okay you need a policy for
43
that okay policy basically help me to establish the governance policy
44
talk about the scoping policy basically talk about the structure policy
45
basically talk about the responsibility matrix policy talk about the authority
46
and all that so it is created by the information security manager
47
which talk about why we need an instant management system in the organization
48
and it is basically approved by the senior management
49
so once we have a policy in place the second thing
50
what we do is we create a team we form the team
51
which is called as a c s i r t team
52
centralized security incident response team after having an incident response team we'll basically develop the plan
53
because it is very important to have a plan it is very important to have a procedure in place
54
so example like i am the incident management lead
55
and i am the one who created a plan now i am basically having off in my absence
56
if any incident happen according to the plan how to respond to the incident it will be easy
57
that is why we need to have a good detailed plan
58
and their associated procedures once you have a plan then you basically based on
59
that you procure the tools like we have a threat intel
60
we have a sim we have ids we have antivirus
61
because these are the solutions we have
62
which give the indication of an incident along with
63
that one One more thing you need to consider is called
64
as a train your employees by the security awareness trainings
65
because they are considered as the first layer of indication of incident and last layer of defense.
66
So we train them about what is security, why security is important, what is their responsibility towards the organization and how you measure the awareness training is.
67
Like example, before awareness training, the people reported 70 incidents but after awareness training people reported 150 incidents.
68
So that shows the good indicator of the security awareness training.
69
Because now people are much aware about, okay, this is the incident, this is the symptom, this is the symptoms and all that.
70
That is a different story when they report an incident.
71
It is not necessary, it's a true incident.
72
But it is a good they have reported.
73
So a good success factor of awareness training is increase in an incident report and decrease in a security violation.
74
Okay, increase in an incident report and decrease in a security violation.
75
So that is something we've done in the preparation stage.
76
Second stage is called as a detection and analysis.
77
So here one of the user has reported me a virus.
78
There is a virus in my system.
79
There was an attack.
80
There was a breach in my system.
81
So he has reported me.
82
As I said, it is not necessary.
83
Whatever he report, it is true.
84
It can be false positive also.
85
So in order to confirm and validate, I will call.
86
I will ask some details. And after
87
that, I will start initiating a documentation documentation is a very important part of the incident management process
88
because it has helped me to build the governance
89
so once you have a documentation you will prioritize the incident
90
because you receive multiple ticket it is not possible for you as a human being to report all the incident
91
and manage all the incident respond to all the incidents
92
so you will do the one factor here
93
which is called as the urgency and impact same like during a covid time
94
when we have a mass patients in the hospital it is difficult for the doctor to handle each
95
and every patient on an individual level
96
so what they did they did the urgency impact analysis
97
and identify which patient is critical and according to
98
that they have treat the patient same thing happened here also
99
we have a multiple tickets it is very difficult for us to manage the tickets
100
so what we did is we privatize and we check the urgency impact like
101
which is which incident is basically urgent which required urgent treatment
102
if i don't treat them what is the impact so
103
that is how we basically did the impact privatization and according to
104
that we have notified the respective owners now example like this is a security breach
105
and as for the regulatory requirement we need to report the
106
breach to the government in 72 hours like in gdpr we
107
have a reporting breach is 72 hours in india we have a six hours
108
so we have to report this speech according to this timeline
109
so this activity is part of a detection
110
and analysis now next is called as a containment the stage three
111
which is called as a containment eradication
112
and recovery containment is all about limiting the impact eradication is all about removing a threat from a system
113
and recoveries restore the system back to the production so
114
when we document containment eradication recovery the first part we are
115
doing is we are reporting detailed reporting we are doing we're
116
preparing a containment strategy how to containment the virus example system was infected with the virus we know
117
that we confirm that isolate a system from the network
118
that is my first priority isolate a system from the network
119
that is my first priority that is the first thing we do in a part of a containment
120
seem like you know when we have found some covet symptoms
121
and all that we isolate the person immediately from the family right the same thing happened here
122
so system was infected with the virus the system is hacked better is isolate a system from the network
123
that is a temporary best solution then we try to remove all the threat from a system like
124
if the system was infected with the virus remove the virus
125
from the system okay then we did do the detailed reporting
126
and notify my senior manager or manager
127
because sometime what happened restoring a system removing something installing something required a lot of cost
128
if you required budgetary approval you will notify and
129
because sometime what happened when you isolate it impact the availability
130
so we need to see the business impact analysis
131
so we'll review the BIA to understand which business is critical is the process
132
which is running on this IT is critical or not
133
and according to that we perform the recovery where i restore the system back to the production
134
here one thing we need to notice is
135
when we're restoring a system back to the production we have to restore within a defined mtd rt
136
and rpo and as per the sla
137
so now i'm assuming the system was restored as per the
138
bia there is no breach of sla now let me learn
139
how this happened what is the reason of this is event
140
why this happened how this happened this is called as a problem management process
141
which we are doing in a fourth stage
142
which is called as a post incident activity now thin line difference between the problem management
143
and incident management is incident management ultimate goal is reduce the impact
144
and problem management ultimate goal is to track the root cause okay
145
so that is the difference we have between the problem management
146
and incident management
147
so in the problem management we're doing rca root cause analysis
148
where we identify why this happened example system was infected with the virus so we identifying how this virus happened
149
What is the reason of this attack?
150
Why this was successful?
151
What are the parameters from which it was penetrated to the network?
152
So that is what the RCA will be doing.
153
Just to make sure this incident should not happen again in the future to avoid the repetition.
154
And then finally we'll document what we have learned from this particular entire event or incident.
155
And if we find any kind of gaps in our procedure, we update the gaps according to the change management process.
156
So summary is that first step is preparation, second is detection and analysis.
157
The third step is basically containment eradication recovery.
158
Fourth step is called as a post incident activity.
159
So if you find this video useful, if you find this video informative, do share in the network and do let me know in the comment box what is the next video shall I make,
160
because I am making more interactive videos in 2023.
161
And if you still not subscribe to my channel, do subscribe to my youtube channel
162
and click on the bell icon to make sure you should not miss our future videos on a similar topic.

Vocabolario e note di pronuncia per questa lezione

Questa lezione di conversazione di livello C1 si basa sul video “Incident Management Process: A Step by Step guide”. Le parole che ritornano più spesso: incident, management, stage, impact, event. Questo video contiene 162 frasi e 1992 parole da ripetere con lo shadowing. Il parlato dura 10:29. Chi parla va veloce, circa 190 parole al minuto: aspettati suoni legati e ridotti. Il 85% delle parole rientra nelle 3.000 più comuni dell’inglese; conviene studiare le altre prima di iniziare.

Vocaboli chiave di questo video

Le 15 parole più avanzate del video, con pronuncia e significato:

ParolaPronunciaSignificato
containment sostantivo/kənˈteɪnmənt/contenimento
eradication sostantivoeradicazione, sradicamento
isolate verbo/ˈaɪ.sə.leɪt/isolare
infect verbo/ɪnˈfɛkt/contagiare, infettare
detection sostantivo/dɪˈtɛk.ʃən/identificazione, investigazione
urgency sostantivo/ˈɜː.d͡ʒən.si/urgenza, urgenze
symptom sostantivo/ˈsɪm(p)təm/sintomo
notify verbo/ˈnoʊtɪfaɪ/notificare
subscribe verbo/səbˈskɹaɪb/abbonarsi
initiate verbo/ɪˈnɪʃ.i.eɪt/iniziare
indication sostantivo/ɪndɪˈkeɪʃən/indicazione
governance sostantivo/ˈɡʌvəɹnəns/governo, amministrazione
privatization sostantivo/ˌpɹaɪvətaɪˈzeɪʃən/privatizzazione
privatize verbo/ˈpɹaɪvətaɪz/privatizzare
procure verbo/pɹəˈkjʊɹ/procurare, approvvigionare

I phrasal verb che sentirai

ParolaSignificato
shake up verbostressare

La grammatica di questo video

Le strutture che chi parla usa di più, con le parole esatte del video:

StrutturaNel video
Forma passiva be + participio passato — conta ciò che accade, non chi lo fais called · is created · are considered
Present perfect have/has + participio passato — un’azione passata che conta ancora adessohas become · have reported · we've done

Pronuncia a cui fare attenzione

Chi parla usa 16 contrazioni e forme ridotte, come we're, we'll, you're. Pronunciale nella forma breve, così come le senti.

  • I suoni “sh” e “zh”: detection /dɪˈtɛk.ʃən/, documentation /ˌdɑkjəmɛnˈteɪʃən/, initiate /ɪˈnɪʃ.i.eɪt/, indication /ɪndɪˈkeɪʃən/, privatization /ˌpɹaɪvətaɪˈzeɪʃən/
  • Parole lunghe — attenzione all’accento: documentation /ˌdɑkjəmɛnˈteɪʃən/, initiate /ɪˈnɪʃ.i.eɪt/, indication /ɪndɪˈkeɪʃən/, antivirus /ˈantɪvʌɪrəs/, budgetary /ˈbʌd͡ʒ.əˌtɛɹ.i/

I suoni difficili per chi parla italiano:

  • Consonante finale — senza aggiungere una vocale dopo: containment /kənˈteɪnmənt/, isolate /ˈaɪ.sə.leɪt/, infect /ɪnˈfɛkt/, subscribe /səbˈskɹaɪb/, initiate /ɪˈnɪʃ.i.eɪt/
  • /æ/ — più aperta della “e”: validate /ˈvæl.ɪ.deɪt/, parameter /pəˈɹæm.ə.tɚ/, interactive /ˌɪn.tɚˈæk.tɪv/

Come esercitarsi con questo video

  1. Ascolta tutto il video una volta senza parlare e annota le parole che non conosci.
  2. Inizia a velocità 0,75×, fai shadowing frase per frase e torna alla velocità normale quando diventa facile.
  3. Registrati e confronta con l’originale, facendo attenzione a parole come containment, eradication, isolate.

Cos'è la tecnica dello Shadowing?

Shadowing è una tecnica di apprendimento delle lingue supportata da studi scientifici, originariamente sviluppata per la formazione dei traduttori professionisti e resa popolare dal poliglotta Dr. Alexander Arguelles. Il metodo è semplice ma potente: ascolti un audio in inglese di madrelingua e lo ripeti immediatamente ad alta voce — come un'ombra che segue il parlante con un ritardo di solo 1–2 secondi. A differenza dell'ascolto passivo o degli esercizi di grammatica, lo shadowing costringe il tuo cervello e i muscoli della bocca a elaborare e riprodurre simultaneamente i modelli di discorso reale. La ricerca dimostra che migliora significativamente la precisione della pronuncia, l'intonazione, il ritmo, il discorso connesso, la comprensione dell'ascolto e la fluidità del parlato — rendendolo uno dei metodi più efficaci per la preparazione alla prova di speaking dell'IELTS e per la comunicazione reale in inglese.

Tecnica dello shadowing: leggi la guida completa passo dopo passo →