Investigation: The process of systematically examining a security incident or anomaly to understand its nature, cause, and impact. This can involve analyzing system logs, network traffic, user activity records, and other evidence. Investigations are a critical part of incident response, helping to mitigate current threats, understand their origins, prevent future incidents, and comply with legal and regulatory requirements for incident reporting and analysis.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D5: Security Program Management and Oversight | SSCP D4: Incident Response and Recovery
Related Articles:
- Frequently Asked Questions FAQ CISSP, CISM, CC | ThorTeaches.com FAQGet answers to Frequently Asked Questions for your CISSP, CISM, & CC study. Learn how to study right, materials to use, tips and tricks, sales, and much more | ThorTeaches.com
- Glossary: Write blocker
- Glossary: Video and audio recording tools
- Glossary: Threat monitoring
- Glossary: Root cause analysis
- Glossary: Reporting in investigations
- Glossary: Network-Based IDS (NIDS)/Network-Based IPS (NIPS)
- Glossary: Legal holds in data retention
- Glossary: ISO 27043
- Glossary: ISO 27041