Topic Covered:
7.1 Understand and support investigations
- Evidence collection and handling (e.g., chain of custody, interviewing)
- Investigative techniques (e.g., root-cause analysis, incident handling)
- Reporting and documenting
- Digital forensics (e.g., media, network, software and embedded devices)
7.2 Understand requirements for investigation types
- Operational
- Regulatory
- Criminal
- Electronic discovery (eDiscovery)
- Civil
7.3 Conduct logging and monitoring activities
- Intrusion detection and prevention
- Egress monitoring (e.g., data loss prevention, steganography, watermarking)
- Security information and event management
- Continuous monitoring
7.4 Secure the provisioning of resources
- Asset inventory (e.g., hardware, software)
- Cloud assets (e.g., services, VMs, storage, networks)
- Configuration management
- Physical assets
- Applications (e.g., workloads or private clouds, web services, software as a
service)
- Virtual assets (e.g., software-defined network, virtual SAN, guest operating
systems)
7.5 Understand and apply foundational security operations concepts
- Need-to-know/least privilege (e.g., entitlement, aggregation, transitive trust)
- Job rotation
- Separation of duties and responsibilities
- Information lifecycle
- Monitor special privileges (e.g., operators, administrators)
- Service-level agreements
7.6 Employ resource protection techniques
- Media management
- Hardware and software asset management
7.7 Conduct incident management
- Detection
- Recovery
- Response
- Remediation
- Mitigation
- Lessons learned
- Reporting
7.8 Operate and maintain preventative measures
- Firewalls
- Sandboxing
- Intrusion detection and prevention systems
- Honeypots/Honeynets
- Whitelisting/Blacklisting
- Anti-malware
- Third-party security services
7.9 Implement and support patch and vulnerability management
7.10 Participate in and understand change management processes (e.g., versioning,
baselining,
security impact analysis)
7.11 Implement recovery strategies
- Backup storage strategies (e.g., offsite storage, electronic vaulting, tape
rotation)
- Multiple processing sites (e.g., operationally redundant systems)
- Recovery site strategies
- System resilience, high availability, quality of service, and fault tolerance
7.12 Implement disaster recovery processes
- Response
- Assessment
- Personnel
- Restoration
- Communications
- Training and awareness
7.13 Test disaster recovery plans
- Read-through
- Parallel
- Walkthrough
- Full interruption
- Simulation
7.14 Participate in business continuity planning and exercises
7.15 Implement and manage physical security
- Perimeter (e.g., access control and monitoring)
- Internal security (e.g., escort requirements/visitor control, keys and locks)
7.16 Participate in addressing personnel safety concerns (e.g., duress, travel,
monitoring)