Re: Incident Identification Checklist
"Ian Kelly" <[email protected]> Thu, 19 Sep 2002 21:46:16 +0100
| Newsgroups | gmane.comp.security.incident-handling |
|---|---|
| Message-ID | <005f01c2601d$a43bdd60$e8d87ad5@tiny> |
There are quite a lot of resources on the Internet to help your research, I've listed some of the ones I've looked at in the past below. Definition of an incident will vary depending on your corporate policy but I think most organisations will have a core set of mutual incident types. You should make a decision about whether you do your own forensic analysis of incidents or get third parties to do it on your behalf. The CERT Coordination Center has resources for computer security incident response teams including incident handling at http://www.cert.org/csirts/. FedCIRC has some reports in incident response and reporting in their document area at http://www.fedcirc.gov/. SecurityUnit has lots of documents on incident response in its Publications section at http://www.securityunit.com/pubs/index.htm. The SANS Institute(http://www.sans.org) has an Incident Handling/Forensics section in the Reading Room. You may have to register to access the area but it is free. SearchSecurity has a section on incident response in the Security Management section at http://searchsecurity.techtarget.com/bestWebLinks/ Hope this helps. Ian. e2chameleon Information Security Resource. http://e2chameleon.users.btopenworld.com http://www.e2chameleon.btinternet.co.uk/ ----- Original Message ----- From: "Davide Grangia" <[email protected]> To: <[email protected]> Sent: Wednesday, September 18, 2002 1:27 PM Subject: Incident Identification Checklist > I am researching security incident identification checklist or criteria, to > establish if an event is a security incident or not. > > Regards, David > > > _________________________________________________________________ > Chiacchiera con gli amici online, prova MSN Messenger: > http://messenger.msn.it >