I think FIPS 199 is the right answer here. That document covers security categorization standards, which would be useful for determining the impact level of a threat.
This is a tricky one. I'm tempted to say the SIEM alert, since that's what triggered the incident response. But I think the phishing email is the more fundamental detail to include. I'll have to weigh the options carefully.
Hmm, I'm not totally sure about this one. I think it might be A, the suggested volume of data to collect, but I'm not 100% certain. I'll have to think it through carefully.
Huey
6 months agoKatina
6 months agoLai
6 months agoSkye
6 months agoGerald
6 months agoJeannetta
7 months agoLucina
7 months agoNoel
7 months agoKizzy
7 months agoMuriel
7 months agoSena
7 months agoVi
7 months agoLillian
7 months ago