Discovery, Reporting, & Initial Inquiry
Containment
Clearing & Sanitization
Return of Asset
Wildcard
100

How do we know if a Data Spill has occurred?

Determination needs to be made by SMEs and customer.

100

Contaminated assets must be secured here when not being worked on.

ISSM Safe

100

To properly check a mobile device for contamination, it must first be placed in:

Airplane

100

SSDs must be turned in to this section for destruction

CSMM

100
DSRG stands for what?

Data Spill Response Guide

200

Classified information is governed by:

Security Classification Guides (SCGs)

200

______ must be reviewed and sanitized first, before moving on to check the local drive.

Outlook/emails
200

BCWipe can only be used on this type of drive.

HDD

200

Temporary use can be allowed with these types of drives:

SSD and HHD

200

When communicating the details of a Data Spill, the details are no longer considered: _______

classified

300

The initial report to DCSA must be sent by who?

The site FSO
300

The name of the team who removes offending emails from the server.

Rmail clean team

300

Temporary use is denied if:

the scope of the spill is not yet defined (ie, issues and emails are still being identified)

300

The transfer of data off of an SSD with DXC must be done in the presence of:

the affected user/a cleared individual

300

The newly appointed Lead Data Spill Responder for RMD

Mike McNeil
400

A common root cause of spills, when two pieces of unclassified information become classified together.

Data Aggregation

400

Identifying all impacted _____ is critical to proper containment.

Users

400

Upon sanitizing the user's Outlook, their email database must be:

compacted

400

A full report to DCSA must be provided within how many days of the spill conclusion?

14

400

What version of the DSRG are we approved to use?

v.6

500

DCSA must be notified within how many hours of the spill's occurence?

72

500

The first two steps in physically/logically containing a spill are:

Disconnection and Controlled Custody

500

BCWIPE wiping scheme must be set to how many passes?

3


500

What kind of entry must be submit immediatly after the return of the assets?

Perspective

500

The two related controls for classified spills.

IR-9 Information Spillage Response

IR-9(1) ISR / Responsible Personnel

M
e
n
u