Which item is NOT typically captured within the initial hour for a cyber incident?

Study for the NERC Reliability Standards Time Requirements. Prepare with flashcards and multiple choice questions, each with insights and explanations. Ace your exam with confidence!

Multiple Choice

Which item is NOT typically captured within the initial hour for a cyber incident?

Explanation:
In the initial hour after a cyber incident, the priority is to establish quick situational awareness and contain the impact. You capture discovery time to know when the event began, identify which BES areas are affected to gauge scope, and log initial containment actions taken to prevent further spread. A final root-cause analysis, which digs into why the incident happened and what systemic fixes are needed, requires deeper investigation, data collection, and analysis beyond the immediate response, so it isn’t typically captured in that first hour.

In the initial hour after a cyber incident, the priority is to establish quick situational awareness and contain the impact. You capture discovery time to know when the event began, identify which BES areas are affected to gauge scope, and log initial containment actions taken to prevent further spread. A final root-cause analysis, which digs into why the incident happened and what systemic fixes are needed, requires deeper investigation, data collection, and analysis beyond the immediate response, so it isn’t typically captured in that first hour.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy