SGC Job Analysis Questionnaire - R2G37 - Incident Response
You have completed 0% of this survey
0%
100%
For the role of Incident Response in the Smartgrid Cybersecurity environment, please indicate how frequently each task below would be performed by a person at the listed level of expertise, and how important is it that this task be completed by a person with the listed level of expertise.
*
Identify sources for information regarding attacks, exploit capability and tools, and newly discovered vulnerabilities. (Task ID: R2-9215)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Review ICS-Cert, NERC and other source reports of attacks and develop understanding of how the threats actually work against specific vulnerabilities (Task ID: R2-9346)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Subscribe to appropriate industry security mailing lists (Task ID: R2-9211)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Subscribe to intelligence services and open source information subscriptions to be awRe of events (Task ID: R2-9219)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Subscribe to various information sharing portals relevant to the content. (Task ID: R2-9222)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Subscribe to vulnerability feeds and maintain information sharing subscriptions. (Task ID: R2-9316)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Verify assessment tool outputs contain all necessary data elements for vulnerability analysis and risk determination (Task ID: R2-9608)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Prioritize vulnerability scan results. (Task ID: R2-9492)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Analyze vulnerabilities to determine risk based on how you have deployed the technology and the likelihood for exploitation (Task ID: R2-9600)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Develop contract language that requires your technology vendors and service providers to provide information about vulnerabilities and threats to the technology you purchase (Task ID: R2-9243)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Map newly discovered vulnerabilities to equipment and vendors to track compliance. (Task ID: R2-9816)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Hire independent third-party auditor to assess/audit toolset coverage and effectiveness (Task ID: R2-9759)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Maintain a table of attack techniques that align with your deployed technology and business processes (Task ID: R2-9602)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)
*
Implement a honeypot and research the attacks it collects. (Task ID: R2-9253)
Frequency
Importance
Never
Rarely
Sometimes
Often
Always
Unimportant
Low
Moderately
Very
Extremely
Novice (Apprentice)
Intermediate (Journeyman)
Expert
(Master)