Instiq

5Security Policies and Procedures

Practice questions →Glossary →
  • 5.1Security management concepts

    Covers asset management to know what you protect, configuration management to keep an approved state, MDM to govern mobile devices, patch management to close known flaws, and vulnerability management to continuously assess and prioritize weaknesses—framed as the operational judgment of "which management process addresses this risk."

  • 5.2Incident response based on NIST SP800-61

    Covers the elements an incident response (IR) plan should contain and the NIST SP800-61 lifecycle (preparation / detection and analysis / containment, eradication, and recovery / post-incident activity), so you can map "which phase this event is in and what to do next."

  • 5.3Stakeholders and digital forensics

    Covers mapping an organization's stakeholders to NIST IR categories (and the maturity view of CMMC), and what NIST SP800-86 specifies—order of evidence collection (most volatile first), data integrity, data preservation, and volatile data collection—framed as the judgment of "how to collect evidence correctly without destroying it."

  • 5.4Network and server profiling

    Covers profiling—establishing a normal-state baseline to spot anomalies from deviations—through the elements of network profiling (total throughput, session duration, ports used, critical asset address space) and server profiling (listening ports, logged-in users/service accounts, running processes/tasks, applications).

  • 5.5Protected data, intrusion models, and SOC metrics

    Covers identifying protected data in a network (PII, PHI, PSI, and intellectual property (IP)), the Cyber Kill Chain and Diamond Model for viewing intrusions by stage/element, and SOC metrics (time to detect/contain/respond/control) that measure response speed—framed as the judgment of "how to classify this event and where to improve."