1
1

00:00:00,090  -->  00:00:01,470
<v ->In this section of the course</v>
2

2

00:00:01,470  -->  00:00:03,030
we're going to continue our discussion
3

3

00:00:03,030  -->  00:00:04,980
of incident responses by focusing
4

4

00:00:04,980  -->  00:00:07,800
on the next phase of the incident response process,
5

5

00:00:07,800  -->  00:00:10,110
the detection and analysis phase.
6

6

00:00:10,110  -->  00:00:12,180
Now we're going to be focused on continuing our coverage
7

7

00:00:12,180  -->  00:00:14,340
of Domain three, Incident Response Management,
8

8

00:00:14,340  -->  00:00:15,720
in this section of the course,
9

9

00:00:15,720  -->  00:00:18,840
and specifically focusing on Objective 3.2.
10

10

00:00:18,840  -->  00:00:21,660
Objective 3.2 states that given a scenario
11

11

00:00:21,660  -->  00:00:24,450
you must be able to perform incident response activities.
12

12

00:00:24,450  -->  00:00:26,370
Here we'll specifically be focusing
13

13

00:00:26,370  -->  00:00:29,370
on the concept of an impact analysis during the detection
14

14

00:00:29,370  -->  00:00:32,160
and analysis phase of your incident response.
15

15

00:00:32,160  -->  00:00:34,380
Now as we begin to go through this section of the course
16

16

00:00:34,380  -->  00:00:35,213
we're going to start out
17

17

00:00:35,213  -->  00:00:36,960
with a concept known as the OODA Loop.
18

18

00:00:36,960  -->  00:00:40,530
This stands for the observe, orient, decide, and act cycle
19

19

00:00:40,530  -->  00:00:41,730
and it's going to be a great framework
20

20

00:00:41,730  -->  00:00:44,700
for us to use during the detection and analysis phase.
21

21

00:00:44,700  -->  00:00:47,160
Next we're going to be talking about defensive capabilities
22

22

00:00:47,160  -->  00:00:49,170
and different courses of actions that are available
23

23

00:00:49,170  -->  00:00:52,260
for us to use as we're working as incident responders.
24

24

00:00:52,260  -->  00:00:55,200
Then we're going to talk specifically about incident detection
25

25

00:00:55,200  -->  00:00:57,043
and analysis and how they're performed and how
26

26

00:00:57,043  -->  00:00:58,860
we can use that information
27

27

00:00:58,860  -->  00:01:00,540
to conduct an impact analysis
28

28

00:01:00,540  -->  00:01:01,710
to determine the true risk
29

29

00:01:01,710  -->  00:01:04,020
of the event that we're trying to respond against.
30

30

00:01:04,020  -->  00:01:05,790
After that, we'll cover the methods used
31

31

00:01:05,790  -->  00:01:07,650
to conduct incident classification
32

32

00:01:07,650  -->  00:01:08,730
as well as the different factors
33

33

00:01:08,730  -->  00:01:10,620
that are going to be used to classify them.
34

34

00:01:10,620  -->  00:01:13,020
Finally, we'll take a short quiz to see what you learned
35

35

00:01:13,020  -->  00:01:14,220
during this section of the course
36

36

00:01:14,220  -->  00:01:15,990
and we'll review those quiz questions
37

37

00:01:15,990  -->  00:01:16,980
to ensure you're can explain
38

38

00:01:16,980  -->  00:01:18,630
why the right answers were right.
39

39

00:01:18,630  -->  00:01:20,400
So let's continue our discussions
40

40

00:01:20,400  -->  00:01:22,950
on incident responses by moving into the detection
41

41

00:01:22,950  -->  00:01:25,400
and analysis phase in this section of the course.
