CySA+ · Domain 4
Reporting and Communication
About 16% of the exam
Who needs to hear what
- Executive
- risk, cost and decisions needed
- Board
- trend and exposure, not detail
- System owner
- what to fix, by when
- Legal and privacy
- obligations and disclosure exposure
- Communications
- customer and press messaging
- Regulator
- facts within the deadline
- Customers
- impact and what to do
- Technical teams
- the detail and the evidence
The vulnerability report
- State the vulnerability and affected hosts
- Give a risk score with context
- Show trend against the previous period
- Name an owner for each action
- Flag recurring findings explicitly
- Separate confirmed from unvalidated findings
- Recommend one clear mitigation each
Metrics that get quoted
- MTTD
- first activity until detection
- MTTR
- respond or remediate, say which
- Alert response time
- queue until analyst pickup
- Top ten findings
- what to fix first
- Critical and zero-day
- how many remain open
- SLO attainment
- percentage inside the target
- Recurrence
- findings that came back
- Scan coverage
- share of the estate assessed
Inhibitors to remediation
- Legacy system
- no patch, cannot be replaced
- Proprietary system
- the vendor forbids modification
- Business interruption
- the fix stops production
- Degraded functionality
- the patch breaks a feature
- MOU or SLA
- agreement limits the change window
- Governance
- approval slower than the risk
- Cost
- no budget in this cycle
Writing the incident report
Executive summary
- One page, plain language
- What happened and the impact
- Whether data was affected
- Current status and next step
- Decisions being asked for
The narrative
- Who, what, when, where, why
- Timeline with the timezone stated
- Scope: systems, accounts, data
- Detection source and dwell time
- Keep fact apart from assessment
Evidence and next steps
- Reference evidence rather than pasting everything
- State a confidence level per conclusion
- Recommendations with owners and dates
- Preserve the report under legal hold
Executives want impact and decisions while engineers want artifacts, so write both audiences into one document with clear sections
Declaration and escalation
- Declare early rather than late
- Severity decides who gets woken
- Escalate when scope exceeds the team
- Bring in counsel before notifying anyone
- Use out-of-band channels when compromised
- Log every decision and its time
Regulatory and legal reporting
- GDPR
- 72 hours to the supervisory authority
- Sector rules
- health, finance and payments differ
- Customer notice
- what happened and what to do
- Law enforcement
- may delay public disclosure
- Insurer
- notify inside the policy terms
- Contractual duty
- customers may demand prompt notice
- Evidence
- regulators ask for the timeline
Action plans
- Configuration management
- fix the setting, not the symptom
- Patching
- with test, window and rollback
- Compensating control
- when patching is impossible now
- Awareness training
- when the gap is behavioral
- Business change
- retire or replace the system
- Exception
- documented, owned and time-bound
Root cause and lessons learned
- Reconstruct the timeline
- Ask why repeatedly
- Name contributing factors
- Agree actions
- Assign owners
- Verify completion
- Distinguish the trigger from the cause
- Contributing factors need their own actions
- A blameless review gets honest answers
- Verify the action actually happened
Compliance reporting
- SOC 2 Type I
- design at a point in time
- SOC 2 Type II
- effectiveness across a period
- PCI DSS
- quarterly scans by approved vendors
- ISO 27001
- certified management system, defined scope
- HIPAA
- administrative, physical, technical safeguards
- Design versus operation
- built right versus actually working
- Evidence
- collect continuously, not at audit
Rapid recall
- Executive summary
- impact and decisions only
- Timeline
- with a stated timezone
- Scope
- systems, accounts and data
- Confidence
- how sure the assessment is
- SLO
- the target you promised
- Recurrence
- the fix did not hold
- Legal hold
- stop deleting anything relevant
Reference strip: audiences, content, metrics, obligations
Audiences
- Board and executives
- System and business owners
- Legal, privacy, communications
- Regulators, customers, insurers
Report content
- Executive summary and impact
- Timeline, scope, root cause
- Evidence references and confidence
- Recommendations with owners and dates
Metrics
- MTTD, MTTR, alert response time
- Mean time to remediate and SLO attainment
- Open criticals and zero-days
- Coverage, density, recurrence
Inhibitors
- Legacy and proprietary systems
- Business interruption and degradation
- Contractual and governance constraints
- Budget and resourcing limits
Obligations
- Breach notification deadlines
- Sector regulators and standards
- Law enforcement coordination
- Contractual and insurer notice
Quick exam traps
- Trap: Executives want the full technical detail
- Trap: A high scan count proves the program is working
- Trap: Reporting can wait until remediation is complete
- Trap: Attribution belongs in the executive summary
- Trap: SOC 2 Type I and Type II prove the same thing
- Trap: Mean time to respond and to remediate are interchangeable
- Trap: Lessons learned actions close themselves
cybercertprep.com · original revision sheet written from the public body of knowledge