RE: Incident Handling

"Brad Bemis" <[email protected]> Mon, 7 Jul 2003 09:24:26 -0700
Newsgroups gmane.comp.security.incident-handling
Message-ID <AE46D0386422BF4FA18E1A9FB67161A004D07FCC@GOAEVS01.abf.ad.airborne.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Here is a list of resources that I came up with while researching for =
the
development of my companies Incident Response Plan.  It should be
relatively thorough:


Computer Security Incident Response Planning - Information Resource List =


Websites

 SEI:  Handbook for Computer Security Incident Response Teams
http://www.sei.cmu.edu/pub/documents/98.reports/pdf/98hb001.pdf

CERT/CC:  Computer Security Incident Response=20
http://www.cert.org/csirts/=20

CERT/CC:  Responding to Intrusions
http://www.cert.org/security-improvement/modules/m06.html=20

AuCERT:  Forming an Incident Response Team=20
http://www.auscert.org.au/render.html?it=3D2252&cid=3D1920=20

SANS:  S.C.O.R.E
http://www.sans.org/score/

SANS Reading Room:  Incident Handling
http://www.sans.org/rr/incident/  =20

SANS Forum: Incident Handling and Hacker Exploits Forum
http://forum.sans.org/discus/messages/79/79.html?1047450013=20

NIST SP 800-3:  Establishing a Computer Security Incident Response
Capability
http://csrc.nist.gov/publications/nistpubs/800-3/800-3.pdf=20

CIAC:  Incident Reporting Procedures
http://www.ciac.org/ciac/CIAC_incident_reporting_procs.html

FIRST:  Forum of Incident Response and Security Teams
http://www.first.org/=20

IETF:  RFC 2196 - The Site Security Handbook (Chapter 5)
http://www.ietf.org/rfc/rfc2196.txt?number=3D2196

IETF:  RFC 2350 - Expectations for Computer Security Incident Response
http://www.ietf.org/rfc/rfc2350.txt=20

CIO:  CyberThreat Response and Reporting Guidelines
http://www.cio.com/research/security/incident_response.pdf =20

ISS:  Computer Security Incident Response Planning
http://documents.iss.net/whitepapers/csirplanning.pdf =20

Incident Response: Managing Security at Microsoft
http://www.microsoft.com/technet/treeview/default.asp?url=3D/technet/itso=
lutio
ns/msit/security/msirsec.asp



Books

SANS:  Computer Security Incident Handling: Step-by-Step
http://store.sans.org/store_item.php?item=3D62

New Riders:  Incident Response - A Strategic Guide to Handling System =
and
Network Security Breaches by E. Eugene Schultz and Russell Shumway
ISBN: 1578702569

McGraw-Hill: Incident Response - Investigating Computer Crime by Chris
Prosise and Kevin Mandia
ISBN: 0072131829

Addison-Wesley: Computer Forensics - Incident Response Essentials by =
Warren
Kruse and Jay Heiser
ISBN: 0201707195

O'reilly:  Incident Response by Kenneth R. van Wyk and Richard Forno
ISBN: 0596001304

Addison-Wesley: The CERT Guide to System and Network Security Practices =
by
Julia H. Allen
ISBN: 020173723X

Hacker's Challenge: Test Your Incident Response Skills Using 20 =
Scenarios
by Mike Schiffman
ISBN: 0072193840




- - Brad Bemis=20




- -----Original Message-----
From: satya arigela [mailto:[email protected]]
Sent: Friday, July 04, 2003 12:17 AM
To: [email protected]
Subject: Incident Handling




Hi,



Cau u please give some useful sites which provide information on =
Incident=20

response / management.



BestRegards

satya



-----BEGIN PGP SIGNATURE-----
Comment: KeyID: 0xB8F26ADD
Comment: Fingerprint: 6E1C D617 CD65 A203 7FD5  4C68 90E7 39F4 B8F2 6ADD

iQA/AwUBPwmeupDnOfS48mrdEQJp6gCg5rh8Zdzd9rKJLkgnTaUEg5yHTWgAoLr+
gv327UP1uXvTuS6sfO1vNFGJ
=3DBP7R
-----END PGP SIGNATURE-----