Phase B and C – sample questions 

Phase B is now breaking down the overall procedure into implementation. Using the RASCI matrix, we understand who is doing what, but now we need to know how we are going to do that. We need to set the base for this cyber intelligence capability between the services. I've added a few preliminary questions to answer that can later be used as targets to clear the first iteration of phase B.

Where do we roll this out first?

  • Security awareness:
    • Who are the stakeholders?
    • What information do you put in the security awareness communications that will call users to action?
    • How and when do we communicate an incident or event?
  • IT help desk:
    • How do we add customized fields to indicate a potential security incident?
    • How do we communicate this to IT security-continuous monitoring?
  • Continuous monitoring:
    • How do we incorporate IT help desk tickets that are assigned to us for action?
    • What are we defining as an incident or event?

The ultimate goal here is to be able to gather information and have it distributed across the applicable teams and stakeholders.

Once these lines of communication have been established, we can move on to phase C. This phase is about passing the specific information that is required to make a decision.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
13.58.121.8