ヘルプ デスクの技術者が、会社の CRM の資格情報を誤ってクリア テキストで従業員の個人の電子メール アカウントに送信してしまいました。次に、技術者は適切なプロセスと従業員の会社の電子メールを使用して従業員のアカウントをリセットし、インシデントをセキュリティ チームに通知しました。インシデント対応手順に従って、セキュリティ チームは次のうちどれを実行する必要がありますか?
正解:C
The security team should perform postmortem data correlation next after receiving notification of the incident from the help desk technician. Postmortem data correlation is an activity that involves analyzing data from various sources (such as logs, alerts, reports, etc.) to identify root causes, impacts, indicators of compromise (IoCs), lessons learned, and recommendations for improvement after an incident3. Postmortem data correlation can help the security team to:
Determine how the incident occurred and how it was detected and resolved Assess the scope and severity of the incident and its effects on confidentiality, integrity, and availability Identify any gaps or weaknesses in security controls or processes that contributed to the incident Develop action plans or remediation strategies to prevent recurrence or mitigate future incidents