AssuranceSecurityGovernanceMembers & LeadersProfessionals & PractitionersStudents & EducatorsExhibitors & Advertisers
CISM Certification
 Requirements
 Code of Professional Ethics
 Exam
  Registration
  Bulletin of Information
  Preparation
  Content Areas
 Exam Review Courses
 Application & Maintenance
 Exam Item Writer Program
 CISM in the News
 FAQ
Education & Conferences
Professional Resources
Downloads
Bookstore
Membership
My ISACA
Career Centre
Print this page


Response Management

Develop and manage a capability to respond to and recover from disruptive and destructive information security events.

Tasks

  • Develop and implement processes for detecting, identifying and analyzing security related events.
  • Develop response and recovery plans including organizing, training and equipping the teams.
  • Ensure periodic testing of the response and recovery plans where appropriate.
  • Ensure the execution of response and recovery plans as required.
  • Establish procedures for documenting an event as a basis for subsequent action, including forensics when necessary.
  • Manage post-event reviews to identify causes and corrective actions.

Knowledge Statements

  • Knowledge of the components of an incident response capability
  • Knowledge of information security emergency management practices (for example, production change control activities, development of computer emergency response team)
  • Knowledge of disaster recovery planning and business recovery processes
  • Knowledge of disaster recovery testing for infrastructure and critical business applications
  • Knowledge of escalation processes for effective security management
  • Knowledge of intrusion detection policies and processes
  • Knowledge of help desk processes for identifying security incidents reported by users and distinguishing them from other issues dealt with the help desks
  • Knowledge of the notification process in managing security incidents and recovery: (for example, automated notice and recovery mechanisms for example in response to virus alerts in a real-time fashion)
  • Knowledge of the requirements for collecting and presenting evidence; rules for evidence, admissibility of evidence, quality and completeness of evidence
  • Knowledge of post-incident reviews and follow-up procedures
Assurance | Security | Governance
Members & Leaders | Professionals & Practitioners | Students & Educators | Exhibitors & Advertisers
Info Request | Join | Bookstore | My ISACA | About ISACA
Home | Site Map | Shopping Cart | Logout | Contact Us

Terms Of Use | Privacy Policy | IP Guidelines
© 2006 Information Systems Audit and Control Association (ISACA) All rights reserved.
3701 Algonquin Road, Suite 1010, Rolling Meadows, Illinois 60008 USA