SGC Job Analysis Questionnaire - R2G18 - Incident Response

 

 

You have completed 0% of this survey
0%
100%

For the role of Incident Response in the Smartgrid Cybersecurity environment, please indicate how frequently each task below would be performed by a person at the listed level of expertise, and how important is it that this task be completed by a person with the listed level of expertise.
*Understand how to run wireshark and tcpdump (Task ID: R2-9348)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Understand the selected SEIM tool. (Task ID: R2-9150)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Understand the work effort required to plug the solution in to custom or specific software and hardware. (Task ID: R2-9293)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Verify that all systems are logging to a central location. (Task ID: R2-9111)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Analyze available logs and note gaps and time periods (Task ID: R2-9103)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Analyze system logs for NTP synchronization anomaly messages (Task ID: R2-9420)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Attend staff and planning meetings to stay on top of policy and procedure developments (Task ID: R2-9594)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Configure your security log management tool to sort and filter data in a manner that us best suited for the event being analyzed. (Task ID: R2-9104)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Implement a DS/NTP capability for environments where a secure connection to a root time stamp authority is required (Task ID: R2-9428)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Maintain change management records for systems that are are operated. (Task ID: R2-9531)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Maintain log file storage and archive older events. (Task ID: R2-9108)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Update database of device configurations upon changes to configurations. (Task ID: R2-9527)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Verify NTP server is utilizing UTC format to avoid time zone issues (Task ID: R2-9421)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Decide where to install security monitoring solutions such that the overall expense is minimized and the coverage is maximized (Task ID: R2-9359)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)