Shadowing Practice: Incident Management Process: A Step by Step guide - Learn English Speaking with Video

Les maken...
1
hi team welcome to my session on coffee with prab
2
and today we're going to discuss about incident management process this is a very important topic
3
if you're preparing for the cissp exam or other ic square
4
or isaka copshia ec council exams and all that along with
5
that this topic is highly asked in a interview jobs like jrc sock
6
and all that i received a lot of feedback prab can you make a video on
7
that so i thought let me make a video on this team if you're new to the channel, do subscribe to my YouTube channel
8
and click on the bell icon to make sure you should not miss my similar kind of videos in the future.
9
My name is Prabh Nayar, for more information you can refer to my LinkedIn profile.
10
So without wasting time, let's start with the first part.
11
Hello everyone, my name is Prabh Nayar and I am working as Chief Instructor at Infosec
12
So when we're talking about incident management process, incident management process is basically divided into the four stages.
13
They have four stages.
14
The first part or first stage is called as a preparation.
15
The second part called as a detection and analysis.
16
The third step or third stage is called as a containment eradication and recovery.
17
And the fourth stage or fourth step is called as a post incident activity.
18
So these are the four steps we have or four stages we have.
19
So when we're talking about incident management process, the ultimate goal of the incident management process is to reduce the impact.
20
Always remember but before going to understand the stages in detail let's understand what is incident
21
so if you go by the definition incident is any series of activity
22
which impact the organization in negative manner that is called as an incident
23
and every incident is an event
24
but not every event is an incident let me explain you let me understand the thinner difference between the event
25
and incident i have a session i have to start a session by 6 30
26
and i i trigger an app
27
and app open initiated at 6 30 we start a session by 6 30
28
which is basically run as per the business objective
29
that is a event but app doesn't trigger till 6 30 trigger by 6 40
30
or fail to continue it impact my cia then it become an incident
31
because here we breach the sla that is the thin line difference event
32
and incident you are attending
33
so your parents make you full makeup shake up you make
34
you ready to attend one marriage event you're going with this impression you are threatening one marriage event
35
and later on you got to know your marriage got fixed in
36
that event then it has become an incident for you now you understand
37
so every incident is an event but not every event is an incident
38
so let's start with the first part
39
which is basically called as a stage one preparation in a
40
stage one the first step is called as a policy any
41
kind of a system you are introducing in the organization any
42
kind of a system you are introducing in the organization okay you need a policy for
43
that okay policy basically help me to establish the governance policy
44
talk about the scoping policy basically talk about the structure policy
45
basically talk about the responsibility matrix policy talk about the authority
46
and all that so it is created by the information security manager
47
which talk about why we need an instant management system in the organization
48
and it is basically approved by the senior management
49
so once we have a policy in place the second thing
50
what we do is we create a team we form the team
51
which is called as a c s i r t team
52
centralized security incident response team after having an incident response team we'll basically develop the plan
53
because it is very important to have a plan it is very important to have a procedure in place
54
so example like i am the incident management lead
55
and i am the one who created a plan now i am basically having off in my absence
56
if any incident happen according to the plan how to respond to the incident it will be easy
57
that is why we need to have a good detailed plan
58
and their associated procedures once you have a plan then you basically based on
59
that you procure the tools like we have a threat intel
60
we have a sim we have ids we have antivirus
61
because these are the solutions we have
62
which give the indication of an incident along with
63
that one One more thing you need to consider is called
64
as a train your employees by the security awareness trainings
65
because they are considered as the first layer of indication of incident and last layer of defense.
66
So we train them about what is security, why security is important, what is their responsibility towards the organization and how you measure the awareness training is.
67
Like example, before awareness training, the people reported 70 incidents but after awareness training people reported 150 incidents.
68
So that shows the good indicator of the security awareness training.
69
Because now people are much aware about, okay, this is the incident, this is the symptom, this is the symptoms and all that.
70
That is a different story when they report an incident.
71
It is not necessary, it's a true incident.
72
But it is a good they have reported.
73
So a good success factor of awareness training is increase in an incident report and decrease in a security violation.
74
Okay, increase in an incident report and decrease in a security violation.
75
So that is something we've done in the preparation stage.
76
Second stage is called as a detection and analysis.
77
So here one of the user has reported me a virus.
78
There is a virus in my system.
79
There was an attack.
80
There was a breach in my system.
81
So he has reported me.
82
As I said, it is not necessary.
83
Whatever he report, it is true.
84
It can be false positive also.
85
So in order to confirm and validate, I will call.
86
I will ask some details. And after
87
that, I will start initiating a documentation documentation is a very important part of the incident management process
88
because it has helped me to build the governance
89
so once you have a documentation you will prioritize the incident
90
because you receive multiple ticket it is not possible for you as a human being to report all the incident
91
and manage all the incident respond to all the incidents
92
so you will do the one factor here
93
which is called as the urgency and impact same like during a covid time
94
when we have a mass patients in the hospital it is difficult for the doctor to handle each
95
and every patient on an individual level
96
so what they did they did the urgency impact analysis
97
and identify which patient is critical and according to
98
that they have treat the patient same thing happened here also
99
we have a multiple tickets it is very difficult for us to manage the tickets
100
so what we did is we privatize and we check the urgency impact like
101
which is which incident is basically urgent which required urgent treatment
102
if i don't treat them what is the impact so
103
that is how we basically did the impact privatization and according to
104
that we have notified the respective owners now example like this is a security breach
105
and as for the regulatory requirement we need to report the
106
breach to the government in 72 hours like in gdpr we
107
have a reporting breach is 72 hours in india we have a six hours
108
so we have to report this speech according to this timeline
109
so this activity is part of a detection
110
and analysis now next is called as a containment the stage three
111
which is called as a containment eradication
112
and recovery containment is all about limiting the impact eradication is all about removing a threat from a system
113
and recoveries restore the system back to the production so
114
when we document containment eradication recovery the first part we are
115
doing is we are reporting detailed reporting we are doing we're
116
preparing a containment strategy how to containment the virus example system was infected with the virus we know
117
that we confirm that isolate a system from the network
118
that is my first priority isolate a system from the network
119
that is my first priority that is the first thing we do in a part of a containment
120
seem like you know when we have found some covet symptoms
121
and all that we isolate the person immediately from the family right the same thing happened here
122
so system was infected with the virus the system is hacked better is isolate a system from the network
123
that is a temporary best solution then we try to remove all the threat from a system like
124
if the system was infected with the virus remove the virus
125
from the system okay then we did do the detailed reporting
126
and notify my senior manager or manager
127
because sometime what happened restoring a system removing something installing something required a lot of cost
128
if you required budgetary approval you will notify and
129
because sometime what happened when you isolate it impact the availability
130
so we need to see the business impact analysis
131
so we'll review the BIA to understand which business is critical is the process
132
which is running on this IT is critical or not
133
and according to that we perform the recovery where i restore the system back to the production
134
here one thing we need to notice is
135
when we're restoring a system back to the production we have to restore within a defined mtd rt
136
and rpo and as per the sla
137
so now i'm assuming the system was restored as per the
138
bia there is no breach of sla now let me learn
139
how this happened what is the reason of this is event
140
why this happened how this happened this is called as a problem management process
141
which we are doing in a fourth stage
142
which is called as a post incident activity now thin line difference between the problem management
143
and incident management is incident management ultimate goal is reduce the impact
144
and problem management ultimate goal is to track the root cause okay
145
so that is the difference we have between the problem management
146
and incident management
147
so in the problem management we're doing rca root cause analysis
148
where we identify why this happened example system was infected with the virus so we identifying how this virus happened
149
What is the reason of this attack?
150
Why this was successful?
151
What are the parameters from which it was penetrated to the network?
152
So that is what the RCA will be doing.
153
Just to make sure this incident should not happen again in the future to avoid the repetition.
154
And then finally we'll document what we have learned from this particular entire event or incident.
155
And if we find any kind of gaps in our procedure, we update the gaps according to the change management process.
156
So summary is that first step is preparation, second is detection and analysis.
157
The third step is basically containment eradication recovery.
158
Fourth step is called as a post incident activity.
159
So if you find this video useful, if you find this video informative, do share in the network and do let me know in the comment box what is the next video shall I make,
160
because I am making more interactive videos in 2023.
161
And if you still not subscribe to my channel, do subscribe to my youtube channel
162
and click on the bell icon to make sure you should not miss our future videos on a similar topic.

Over deze les

Wat is de Shadowing-techniek?

Shadowing is een wetenschappelijk onderbouwde taalleermethode die oorspronkelijk is ontwikkeld voor professionele tolkentraining en gepopulariseerd door polyglot Dr. Alexander Arguelles. De methode is eenvoudig maar krachtig: je luistert naar native Engelse audio en herhaalt het onmiddellijk hardop — als een schaduw die de spreker volgt met slechts 1–2 seconden vertraging. In tegenstelling tot passief luisteren of grammaticadrills, dwingt shadowing je hersenen en mondspieren om echte spraakpatronen tegelijkertijd te verwerken en te reproduceren. Onderzoek toont aan dat het de uitspraaknauwkeurigheid, intonatie, ritme, verbonden spraak, luisterbegrip en spreekvaardigheid aanzienlijk verbetert — waardoor het een van de meest effectieve methoden is voor IELTS Speaking-voorbereiding en echte Engelse communicatie.

Shadowing-techniek: lees de volledige stap-voor-stap-gids →