<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CC question in selfpaced training is confusing. in CC Group</title>
    <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55193#M37</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;&amp;nbsp;Great diagram but is this really a concept that we would expect someone with little to no experience to understand????&lt;/P&gt;</description>
    <pubDate>Tue, 15 Nov 2022 23:21:07 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2022-11-15T23:21:07Z</dc:date>
    <item>
      <title>CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55175#M34</link>
      <description>&lt;P&gt;#spolier - this refers to a sample test question in the CC training#&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The incident response video question suggests that when the incident response team establish that the user is known and that the activity discovered is benign then the incident response should stop.&amp;nbsp; &amp;nbsp;However, i think this is inaccurate as i would expect (and the previous training slides suggest) the responders to carry out a brief retrospective of the incident.&amp;nbsp; &amp;nbsp;I would also like to see if the responders could suggest ways in which such 'false positives' could be removed from the alerting process, thus making the team more efficient overall.&amp;nbsp; &amp;nbsp;So in my mind the answer is that the response continues to a conclusion and hence does not stop...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;welcome any thoughts on that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE: its only a guide question - not an exam - so its not vital...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 08:53:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55175#M34</guid>
      <dc:creator>RichA69</dc:creator>
      <dc:date>2022-11-15T08:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55177#M35</link>
      <description>&lt;P&gt;Possibly.&amp;nbsp; It depends how you scope RS.IM.&amp;nbsp; A reduction in false positives could be seen as an improvement, but equally it could be done as part of an improvement in detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 13:21:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55177#M35</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2022-11-15T13:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55181#M36</link>
      <description>&lt;P&gt;Technically, the security event shouldn't have been declared an incident. So, the incident process should be immediately stopped and moved to &lt;STRONG&gt;post-incident activities&lt;/STRONG&gt; for process improvement, aka adjust tooling to fix false positives. The test won't get this detailed though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tmekelburg1_0-1668521199085.png" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/6608i1AA772FE22175C16/image-size/large?v=v2&amp;amp;px=999" role="button" title="tmekelburg1_0-1668521199085.png" alt="tmekelburg1_0-1668521199085.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 14:14:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55181#M36</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2022-11-15T14:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55193#M37</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;&amp;nbsp;Great diagram but is this really a concept that we would expect someone with little to no experience to understand????&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 23:21:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55193#M37</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-11-15T23:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55198#M38</link>
      <description>&lt;P&gt;If you take an simple ISO 27035 perspective, that are a great many security events, which get filtered down into the few that are actual incidents.&amp;nbsp; So if something has been incorrectly called as an incident it should be possible to close it later due to the mistake.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 09:25:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55198#M38</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2022-11-16T09:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55201#M39</link>
      <description>&lt;P&gt;So on that (really good) diagram should there be a section prior to 'declare incident' that says 'initial triage of security event' to determine whether it is really an incident at all???&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 11:36:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55201#M39</guid>
      <dc:creator>RichA69</dc:creator>
      <dc:date>2022-11-16T11:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55202#M40</link>
      <description>Hey, what's the source of your diagram? Thanks</description>
      <pubDate>Wed, 16 Nov 2022 13:48:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55202#M40</guid>
      <dc:creator>liudvikas</dc:creator>
      <dc:date>2022-11-16T13:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: CC question in selfpaced training is confusing.</title>
      <link>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55204#M41</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/320317701"&gt;@RichA69&lt;/a&gt;&amp;nbsp;Yeah, you could. This diagram is just showing the IR phases and what feeds into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;No, but it was easier for me to describe and show in the diagram how it's all connected. The main thing for the OP to know, related to the test, is to stop the IR process if it's not an incident.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1245028837"&gt;@liudvikas&lt;/a&gt;&amp;nbsp;&lt;A href="https://www.cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf" target="_self"&gt;https://www.cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:56:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Group/CC-question-in-selfpaced-training-is-confusing/m-p/55204#M41</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2022-11-16T13:56:46Z</dc:date>
    </item>
  </channel>
</rss>

