ABDURROZAK
ABDURROZAK.MY.ID // EBOOK

BAB 20 - SECURITY ANALYST

DARI DETEKSI SAMPAI RESPON
12 SUB-BAB ~110 MENIT BACA FASE 4 - PRAKTIK LEVEL: LANJUT

PENGANTAR BAB

Selamat datang di bab terakhir yang akan membawa Anda ke dunia Security Analyst - peran kunci dalam pertahanan siber organisasi. Security analyst adalah "mata dan telinga" organisasi yang memantau, mendeteksi, dan merespons ancaman keamanan 24/7.

Menurut Ponemon Institute 2023, organisasi dengan SOC (Security Operations Center) yang matang dapat mengurangi waktu deteksi insiden hingga 70% dan mengurangi dampak insiden hingga 60%. Ini menunjukkan betapa pentingnya peran security analyst dalam organisasi modern.

Bab ini akan membawa Anda melalui seluruh workflow security analyst - dari monitoring, log collection, log analysis, incident identification, incident response, threat analysis, hingga dokumentasi dan pelaporan.

277
HARI RATA-RATA DETEKSI
IBM 2023
70%
REDUKSI DETEKSI DENGAN SOC
Ponemon 2023
60%
REDUKSI DAMPAK DENGAN SOC
Ponemon 2023
$4.45M
RATA-RATA BIAYA BREACH
IBM 2023
TUJUAN PEMBELAJARAN
  • Memahami peran dan tanggung jawab security analyst
  • Memahami cara kerja Security Operations Center (SOC)
  • Membedakan security event dan security alert
  • Memahami proses security monitoring
  • Mengumpulkan log dari berbagai sumber
  • Menganalisis log untuk mendeteksi anomali
  • Mengidentifikasi Indicator of Compromise (IOC)
  • Melakukan incident identification
  • Melakukan incident response
  • Melakukan threat analysis
  • Mendokumentasikan incident
  • Menulis security incident report
20.1

PENGERTIAN SECURITY ANALYST

Apa itu Security Analyst?

Security Analyst adalah profesional yang bertanggung jawab untuk memantau, mendeteksi, menganalisis, dan merespons insiden keamanan dalam organisasi. Mereka adalah "garda terdepan" dalam pertahanan siber organisasi.

DEFINISI

"A security analyst is a cybersecurity professional who monitors, detects, analyzes, and responds to cybersecurity incidents to protect an organization's information systems and data."

Peran dan Tanggung Jawab

TANGGUNG JAWABDESKRIPSI
Monitoring Memantau sistem dan jaringan 24/7 untuk mendeteksi anomali
Detection Mendeteksi security events dan alerts
Analysis Menganalisis events untuk menentukan apakah itu incident
Response Merespons incidents sesuai prosedur
Documentation Mendokumentasikan semua aktivitas dan findings
Reporting Membuat laporan untuk management dan stakeholders
Improvement Merekomendasikan perbaikan untuk security posture

Tier Levels

TIERROLETANGGUNG JAWAB
Tier 1 Security Analyst (Junior) Triaging alerts, initial analysis, escalation
Tier 2 Security Analyst (Senior) Deep analysis, incident response, threat hunting
Tier 3 Security Engineer/Threat Hunter Advanced threat hunting, threat hunting, malware analysis
Tier 4 SOC Manager/Lead Management, strategy, coordination

Skills dan Certifications

Technical Skills:

  • SIEM - Splunk, QRadar, ArcSight, ELK
  • Log Analysis - Log parsing, correlation
  • Network Analysis - Wireshark, tcpdump
  • Incident Response - Incident handling procedures
  • Threat Intelligence - Threat hunting, IOC analysis

Certifications:

  • CompTIA Security+ - Entry level
  • CompTIA CySA+ - Cybersecurity Analyst
  • GIAC GCIH - Incident Handler
  • GIAC GCIA - Intrusion Analyst
  • EC-Council CDSA - Certified Defensive Security Analyst
ANALOGI: SECURITY ANALYST = SATPAM + DETEKTIF
  • Monitoring = satpam yang mengawasi CCTV 24/7
  • Detection = satpam yang melihat aktivitas mencurigakan
  • Analysis = detektif yang menganalisis apakah itu ancaman nyata
  • Response = satpam yang merespons ancaman
  • Documentation = detektif yang mendokumentasikan investigasi
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • SANS - SEC450: Security Operations and Incident Analysis
  • CompTIA - CySA+ Certification Guide
20.2

SECURITY OPERATIONS CENTER

Apa itu SOC?

Security Operations Center (SOC) adalah pusat komando yang bertanggung jawab untuk memantau, mendeteksi, menganalisis, dan merespons insiden keamanan 24/7. SOC adalah "jantung" dari operasi keamanan organisasi.

DEFINISI

"A Security Operations Center (SOC) is a centralized unit that deals with security issues on an organizational and technical level. A SOC includes the people, processes, and technology required to monitor, detect, and respond to security incidents."

ANIMASI: SOC STRUCTURE
SOC MANAGER Tier 4 TIER 3 Threat Hunter TIER 2 Senior Analyst TIER 1 Junior Analyst SIEM EDR IDS/IPS Firewall

SOC Tools

TOOLFUNGSICONTOH
SIEM Security Information and Event Management Splunk, QRadar, ArcSight, ELK
EDR Endpoint Detection and Response CrowdStrike, Carbon Black, SentinelOne
IDS/IPS Intrusion Detection/Prevention System Snort, Suricata, Palo Alto
Firewall Network firewall Palo Alto, Fortinet, Cisco
Log Management Log collection and management Splunk, ELK, Graylog
Threat Intelligence Threat intelligence platform MISP, ThreatConnect, Anomali

SOC Best Practices

SOC BEST PRACTICES
  • 24/7 monitoring - monitoring non-stop
  • Clear procedures - prosedur yang jelas
  • Automation - otomatisasi untuk efisiensi
  • Threat intelligence - integrasi threat intelligence
  • Continuous improvement - perbaikan berkelanjutan
  • Training - training berkelanjutan untuk analyst
  • Metrics - metrik untuk mengukur kinerja
ANALOGI: SOC = MENARA PENGAWAS
  • SOC = menara pengawas yang mengawasi seluruh area
  • Analyst = pengawas yang mengawasi monitor
  • Tools = CCTV dan sensor
  • Procedures = SOP untuk merespons ancaman
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • SANS - SEC450: Security Operations and Incident Analysis
  • SOC-CMM - SOC Capability Maturity Model
20.3

SECURITY EVENT & ALERT

Event vs Alert

Penting untuk membedakan antara security event dan security alert:

ASPEKSECURITY EVENTSECURITY ALERT
Definisi Setiap aktivitas yang terjadi dalam sistem Event yang terdeteksi sebagai potensi ancaman
Severity Bervariasi (info, low, medium, high) Medium, high, critical
Action Required Tidak selalu Ya, perlu investigasi
Contoh User login, file access, network connection Failed login attempts, malware detection
ANIMASI: EVENT vs ALERT
EVENTS All activities login, access, etc Filter ALERTS Suspicious events need investigation Investigate INCIDENTS Confirmed threats

Jenis Security Events

JENISDESKRIPSICONTOH
Authentication Events Login attempts, password changes Successful login, failed login
File Access Events File access, modification, deletion File read, file write, file delete
Network Events Network connections, traffic Connection established, connection blocked
System Events System changes, updates System started, service started
Application Events Application activities Application started, error occurred

Jenis Security Alerts

JENISSEVERITYCONTOH
Brute Force High Multiple failed login attempts
Malware Detection Critical Malware detected on endpoint
Intrusion Detection High Intrusion attempt detected
Data Exfiltration Critical Large data transfer to external
Policy Violation Medium Policy violation detected

Best Practices

EVENT & ALERT BEST PRACTICES
  • Clear definitions - definisi yang jelas untuk event dan alert
  • Proper tuning - tuning untuk mengurangi false positives
  • Proper correlation - korelasi events untuk mendeteksi patterns
  • Proper prioritization - prioritas berdasarkan severity
  • Proper documentation - dokumentasi semua alerts
ANALOGI: EVENTS & ALERTS
  • Events = semua aktivitas di gedung (orang masuk, keluar, dll)
  • Alerts = alarm yang berbunyi karena aktivitas mencurigakan
  • Incidents = ancaman yang terkonfirmasi
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • SANS - SEC450: Security Operations and Incident Analysis
20.4

SECURITY MONITORING

Apa itu Security Monitoring?

Security monitoring adalah proses memantau sistem dan jaringan secara continuous untuk mendeteksi anomali dan potensi ancaman. Ini adalah aktivitas utama SOC.

Monitoring Sources

SUMBERDESKRIPSICONTOH
Network Traffic Network traffic logs Firewall logs, IDS/IPS logs
Endpoint Logs Endpoint activity logs Windows Event Logs, Syslog
Application Logs Application activity logs Web server logs, database logs
Security Tools Security tool alerts EDR alerts, SIEM alerts

Monitoring Tools

TOOLFUNGSICONTOH
SIEM Security Information and Event Management Splunk, QRadar, ArcSight, ELK
EDR Endpoint Detection and Response CrowdStrike, Carbon Black, SentinelOne
NIDS/NIPS Network Intrusion Detection/Prevention Snort, Suricata
Network Analysis Network traffic analysis Wireshark, tcpdump

Best Practices

MONITORING BEST PRACTICES
  • Comprehensive coverage - cakupan yang komprehensif
  • Proper correlation - korelasi events dari berbagai sumber
  • Proper tuning - tuning untuk mengurangi false positives
  • Proper prioritization - prioritas berdasarkan severity
  • Continuous monitoring - monitoring 24/7
  • Automation - otomatisasi untuk efisiensi
ANALOGI: MONITORING = CCTV
  • Monitoring = CCTV yang mengawasi seluruh area
  • Sources = kamera CCTV di berbagai lokasi
  • Tools = monitor dan sistem perekam
  • Analyst = satpam yang mengawasi monitor
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • SANS - SEC450: Security Operations and Incident Analysis
20.5

LOG COLLECTION

Apa itu Log Collection?

Log collection adalah proses mengumpulkan log dari berbagai sumber untuk dianalisis. Log collection adalah langkah pertama dalam security monitoring dan incident response.

Log Sources

SUMBERDESKRIPSICONTOH
Windows Event Logs Windows system and application logs Security, System, Application
Linux Syslog Linux system logs /var/log/syslog, /var/log/auth.log
Firewall Logs Firewall activity logs Firewall allow/deny logs
IDS/IPS Logs Intrusion detection/prevention logs Snort alerts, Suricata alerts
Web Server Logs Web server activity logs Apache access/error logs
Application Logs Application activity logs Application logs, database logs

Log Collection Tools

TOOLFUNGSICONTOH
Syslog Linux log forwarding rsyslog, syslog-ng
WinEventLog Windows log forwarding Windows Event Forwarding
Filebeat Log file forwarding Filebeat, Fluentd
SIEM Agents SIEM log collection agents Splunk Universal Forwarder

Log Collection Examples

Log Collection Examples
# Linux syslog configuration
# /etc/rsyslog.conf
*.* @@siem-server:514

# Windows Event Forwarding
# Configure Windows Event Collector
wecutil qc
wecutil cs subscription.xml

# Filebeat configuration
# /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
  paths:
    - /var/log/*.log
output.logstash:
  hosts: ["logstash-server:5044"]

# Splunk Universal Forwarder
# /opt/splunkforwarder/etc/system/local/inputs.conf
[monitor:///var/log/]
disabled = false
index = main

Best Practices

LOG COLLECTION BEST PRACTICES
  • Comprehensive coverage - kumpulkan log dari semua sumber
  • Proper configuration - konfigurasi yang benar
  • Secure transmission - transmisi yang aman (TLS)
  • Proper storage - penyimpanan yang aman
  • Proper retention - retensi yang sesuai dengan kebijakan
  • Proper rotation - rotasi log untuk manajemen storage
ANALOGI: LOG COLLECTION = PENGUMPULAN BUKTI
  • Log collection = pengumpulan bukti dari TKP
  • Sources = sumber bukti (CCTV, saksi, dll)
  • Tools = alat untuk mengumpulkan bukti
  • Storage = penyimpanan bukti yang aman
REFERENSI
  • NIST SP 800-92 - Guide to Computer Security Log Management
  • SANS - SEC450: Security Operations and Incident Analysis
20.6

LOG ANALYSIS

Apa itu Log Analysis?

Log analysis adalah proses menganalisis log untuk mendeteksi anomali, pola, dan potensi ancaman. Log analysis adalah aktivitas inti dari security analyst.

Log Analysis Techniques

TEKNIKDESKRIPSICONTOH
Pattern Matching Mencari pola tertentu dalam log Mencari failed login attempts
Anomaly Detection Mendeteksi anomali dalam log Deteksi unusual traffic patterns
Correlation Mengkorelasikan events dari berbagai sumber Korelasi firewall dan IDS logs
Statistical Analysis Analisis statistik dari log Analisis traffic patterns

Log Analysis Tools

TOOLFUNGSICONTOH
SIEM Security Information and Event Management Splunk, QRadar, ArcSight, ELK
Log Analysis Log analysis tools Splunk, ELK, Graylog
Command Line Command line log analysis grep, awk, sed

Log Analysis Examples

Log Analysis Examples
# Search for failed login attempts
$ grep "Failed password" /var/log/auth.log

# Search for successful login attempts
$ grep "Accepted password" /var/log/auth.log

# Search for specific IP
$ grep "192.168.1.100" /var/log/auth.log

# Count failed login attempts per IP
$ grep "Failed password" /var/log/auth.log | \
    awk '{print $(NF-3)}' | sort | uniq -c | sort -nr

# Search for specific time range
$ grep "Sep  9" /var/log/auth.log | grep "Failed password"

# Search for multiple patterns
$ grep -E "Failed password|Invalid user" /var/log/auth.log

# Count events per hour
$ grep "Failed password" /var/log/auth.log | \
    awk '{print $3}' | cut -d: -f1 | sort | uniq -c

Best Practices

LOG ANALYSIS BEST PRACTICES
  • Proper filtering - filtering yang tepat untuk mengurangi noise
  • Proper correlation - korelasi events dari berbagai sumber
  • Proper prioritization - prioritas berdasarkan severity
  • Proper documentation - dokumentasi semua findings
  • Continuous improvement - perbaikan berkelanjutan
ANALOGI: LOG ANALYSIS = ANALISIS BUKTI
  • Log analysis = analisis bukti dari TKP
  • Filtering = memilah bukti yang relevan
  • Correlation = menghubungkan berbagai bukti
  • Prioritization = memprioritaskan bukti yang paling penting
REFERENSI
  • NIST SP 800-92 - Guide to Computer Security Log Management
  • SANS - SEC450: Security Operations and Incident Analysis
20.7

INDICATOR OF COMPROMISE

Apa itu IOC?

Indicator of Compromise (IOC) adalah artefak yang menunjukkan bahwa sistem telah dikompromikan. IOC digunakan untuk mendeteksi dan merespons insiden keamanan.

DEFINISI

"An Indicator of Compromise (IOC) is an artifact observed on a network or in an operating system that with high confidence indicates a computer intrusion."

Jenis IOC

JENISDESKRIPSICONTOH
File Hash Hash dari file malicious MD5, SHA1, SHA256 hash
IP Address IP address yang malicious C2 server IP, malicious IP
Domain Domain yang malicious Malicious domain, C2 domain
URL URL yang malicious Malicious URL, phishing URL
Email Email yang malicious Phishing email, malicious email
Registry Key Registry key yang malicious Malicious registry key
File Name Nama file yang malicious Malicious file name
Mutex Mutex yang dibuat oleh malware Malicious mutex

IOC Sources

SUMBERDESKRIPSICONTOH
Threat Intelligence Feeds Threat intelligence feeds AlienVault OTX, Abuse.ch
Threat Intelligence Platforms Threat intelligence platforms MISP, ThreatConnect, Anomali
Incident Response IOC dari incident response IOC dari incident investigation
Threat Hunting IOC dari threat hunting IOC dari threat hunting investigation

Best Practices

IOC BEST PRACTICES
  • Proper validation - validasi IOC sebelum digunakan
  • Proper context - konteks yang tepat untuk IOC
  • Proper sharing - sharing IOC dengan komunitas
  • Proper integration - integrasi IOC dengan security tools
  • Continuous update - update IOC secara berkala
ANALOGI: IOC = SIDIK JARI PENJAHAT
  • IOC = sidik jari penjahat di TKP
  • Threat Intelligence = database sidik jari penjahat
  • Detection = mencocokkan sidik jari di TKP dengan database
  • Response = menangkap penjahat berdasarkan sidik jari
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • MITRE - ATT&CK Framework
  • MISP - Malware Information Sharing Platform
20.8

INCIDENT IDENTIFICATION

Apa itu Incident Identification?

Incident identification adalah proses mengidentifikasi dan mengkonfirmasi bahwa sebuah event adalah insiden keamanan. Ini adalah langkah pertama dalam incident response.

Incident Types

TYPEDESKRIPSICONTOH
Malware Malware infection Virus, worm, trojan, ransomware
Intrusion Unauthorized access Unauthorized access, privilege escalation
Data Breach Data exfiltration Data exfiltration, data leak
Denial of Service Service disruption DDoS attack, service disruption
Insider Threat Insider threat Insider threat, malicious insider
ANIMASI: INCIDENT IDENTIFICATION PROCESS
EVENTS All events Analyze ALERTS Suspicious events Confirm INCIDENTS Confirmed

Best Practices

INCIDENT IDENTIFICATION BEST PRACTICES
  • Clear procedures - prosedur yang jelas untuk identifikasi
  • Proper tools - tools yang tepat untuk identifikasi
  • Proper training - training untuk analyst
  • Proper documentation - dokumentasi semua findings
  • Proper escalation - eskalasi yang tepat
ANALOGI: INCIDENT IDENTIFICATION = DIAGNOSIS DOKTER
  • Events = gejala pasien
  • Alerts = gejala yang mencurigakan
  • Incidents = diagnosis yang dikonfirmasi
  • Analyst = dokter yang mendiagnosis
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • SANS - SEC450: Security Operations and Incident Analysis
20.9

INCIDENT RESPONSE

Apa itu Incident Response?

Incident response adalah proses merespons insiden keamanan untuk meminimalkan dampak dan memulihkan sistem. Incident response adalah aktivitas inti dari security analyst.

Incident Response Phases

PHASEDESKRIPSIAKTIVITAS
Preparation Persiapan untuk incident response Develop procedures, train team
Detection & Analysis Deteksi dan analisis insiden Detect incident, analyze incident
Containment Mengandung insiden Isolate affected systems
Eradication Menghapus ancaman Remove malware, patch vulnerabilities
Recovery Memulihkan sistem Restore systems, restore data
Post-Incident Setelah insiden Lessons learned, improve procedures
ANIMASI: INCIDENT RESPONSE PHASES
PREPARE Prepare DETECT Detect CONTAIN Contain ERADICATE Eradicate RECOVER Recover POST Lessons

Best Practices

INCIDENT RESPONSE BEST PRACTICES
  • Clear procedures - prosedur yang jelas
  • Proper training - training untuk team
  • Proper tools - tools yang tepat
  • Proper communication - komunikasi yang tepat
  • Proper documentation - dokumentasi yang tepat
  • Continuous improvement - perbaikan berkelanjutan
ANALOGI: INCIDENT RESPONSE = PEMADAM KEBAKARAN
  • Preparation = pelatihan pemadam kebakaran
  • Detection = alarm kebakaran berbunyi
  • Containment = mengandung kebakaran
  • Eradication = memadamkan api
  • Recovery = memulihkan bangunan
  • Post-Incident = evaluasi dan perbaikan
REFERENSI
  • NIST SP 800-61 - Computer Security Incident Handling Guide
  • SANS - SEC450: Security Operations and Incident Analysis
20.10

THREAT ANALYSIS

Apa itu Threat Analysis?

Threat analysis adalah proses menganalisis ancaman untuk memahami karakteristik, kemampuan, dan motivasi threat actor. Threat analysis membantu organisasi untuk mempersiapkan diri terhadap ancaman.

Threat Analysis Components

KOMPONENDESKRIPSICONTOH
Threat Actor Siapa yang melakukan serangan APT groups, cybercriminals
Threat Capability Kemampuan threat actor Tools, techniques, procedures
Threat Motivation Motivasi threat actor Financial, espionage, hacktivism
Threat Target Target threat actor Industri, organisasi, individu

Threat Intelligence Sources

  • AlienVault OTX, Abuse.ch
  • SUMBERDESKRIPSICONTOH
    Open Source Open source threat intelligence
    Commercial Commercial threat intelligence Mandiant, CrowdStrike, Recorded Future
    Government Government threat intelligence CISA, NCSC, BSSN
    Community Community threat intelligence MISP, threat sharing communities

    Best Practices

    THREAT ANALYSIS BEST PRACTICES
    • Proper sources - sumber yang tepat
    • Proper analysis - analisis yang tepat
    • Proper sharing - sharing dengan komunitas
    • Proper integration - integrasi dengan security tools
    • Continuous update - update secara berkala
    ANALOGI: THREAT ANALYSIS = INTELIJEN MILITER
    • Threat analysis = intelijen militer tentang musuh
    • Threat actor = musuh yang akan menyerang
    • Threat capability = kemampuan senjata musuh
    • Threat motivation = motivasi musuh
    • Threat target = target musuh
    REFERENSI
    • MITRE - ATT&CK Framework
    • NIST SP 800-61 - Computer Security Incident Handling Guide
    • MISP - Malware Information Sharing Platform
    20.11

    INCIDENT DOCUMENTATION

    Apa itu Incident Documentation?

    Incident documentation adalah proses mendokumentasikan semua aktivitas dan findings selama incident response. Dokumentasi yang baik sangat penting untuk audit, legal, dan improvement.

    Documentation Components

    KOMPONENDESKRIPSICONTOH
    Incident Details Detail insiden Incident ID, timestamp, severity
    Timeline Timeline insiden Timeline of events
    Findings Findings dari investigasi IOCs, attack vectors
    Actions Taken Tindakan yang diambil Containment, eradication, recovery
    Lessons Learned Pelajaran yang dipelajari Lessons learned, recommendations

    Best Practices

    DOCUMENTATION BEST PRACTICES
    • Clear structure - struktur yang jelas
    • Complete information - informasi lengkap
    • Accurate information - informasi yang akurat
    • Proper formatting - formatting yang tepat
    • Proper storage - penyimpanan yang aman
    ANALOGI: DOCUMENTATION = LAPORAN POLISI
    • Documentation = laporan polisi tentang kejahatan
    • Timeline = kronologi kejadian
    • Findings = bukti yang ditemukan
    • Actions taken = tindakan yang diambil polisi
    • Lessons learned = pelajaran untuk masa depan
    REFERENSI
    • NIST SP 800-61 - Computer Security Incident Handling Guide
    • SANS - SEC450: Security Operations and Incident Analysis
    20.12

    SECURITY INCIDENT REPORT

    Apa itu Security Incident Report?

    Security incident report adalah laporan formal tentang insiden keamanan yang terjadi. Laporan ini digunakan untuk komunikasi dengan management, stakeholders, dan untuk dokumentasi.

    Report Components

    KOMPONENDESKRIPSI
    Executive Summary Ringkasan eksekutif untuk management
    Incident Details Detail insiden
    Timeline Timeline insiden
    Findings Findings dari investigasi
    Impact Assessment Penilaian dampak
    Actions Taken Tindakan yang diambil
    Recommendations Rekomendasi untuk perbaikan
    Lessons Learned Pelajaran yang dipelajari

    Report Template

    Security Incident Report Template
    # SECURITY INCIDENT REPORT
    
    # Executive Summary
    On [date], a [severity] security incident was detected...
    
    # Incident Details
    Incident ID: [ID]
    Date/Time: [date/time]
    Severity: [severity]
    Affected Systems: [systems]
    
    # Timeline
    [date/time] - [event]
    [date/time] - [event]
    
    # Findings
    [findings]
    
    # Impact Assessment
    [impact assessment]
    
    # Actions Taken
    [actions taken]
    
    # Recommendations
    [recommendations]
    
    # Lessons Learned
    [lessons learned]

    Best Practices

    REPORT BEST PRACTICES
    • Clear structure - struktur yang jelas
    • Complete information - informasi lengkap
    • Accurate information - informasi yang akurat
    • Proper formatting - formatting yang tepat
    • Proper distribution - distribusi yang tepat
    ANALOGI: REPORT = LAPORAN RESMI
    • Report = laporan resmi tentang insiden
    • Executive summary = ringkasan untuk management
    • Details = detail untuk technical team
    • Recommendations = rekomendasi untuk perbaikan
    REFERENSI
    • NIST SP 800-61 - Computer Security Incident Handling Guide
    • SANS - SEC450: Security Operations and Incident Analysis
    Q

    DIAGNOSTIK KOMPETENSI

    Uji pemahaman Anda tentang Bab 20! Target minimal: 70% untuk menyelesaikan Fase 4.

    PETUNJUK
    • Total 10 pertanyaan pilihan ganda
    • Klik opsi untuk menjawab - feedback langsung
    • Benar = HIJAU, salah = MAGENTA
    • Penjelasan muncul setelah menjawab
    • Klik "LIHAT HASIL AKHIR" untuk skor final
    SKOR ANDA
    0/ 10
    -

    -

    REFERENSI BAB 20 SECARA KESELURUHAN
    • NIST SP 800-61 - Computer Security Incident Handling Guide
    • NIST SP 800-92 - Guide to Computer Security Log Management
    • SANS - SEC450: Security Operations and Incident Analysis
    • MITRE - ATT&CK Framework
    • MISP - Malware Information Sharing Platform
    ABDURROZAK.MY.ID // JARINGAN SOSIAL