I think FIPS 199 is the right answer here. That document covers security categorization standards, which would be useful for determining the impact level of a threat.
This is a tricky one. I'm tempted to say the SIEM alert, since that's what triggered the incident response. But I think the phishing email is the more fundamental detail to include. I'll have to weigh the options carefully.
Hmm, I'm not totally sure about this one. I think it might be A, the suggested volume of data to collect, but I'm not 100% certain. I'll have to think it through carefully.
Huey
4 months agoKatina
4 months agoLai
4 months agoSkye
4 months agoGerald
4 months agoJeannetta
5 months agoLucina
5 months agoNoel
5 months agoKizzy
5 months agoMuriel
5 months agoSena
5 months agoVi
5 months agoLillian
5 months ago