Integrated Security Incident Management -- Concepts and Real-World Experiences

We present a holistic, process-oriented approach to ISO/IEC 27001 compliant security incident management that integrates multiple state-of-the-art security tools and has been applied to a real-world scenario very successfully for one year so far. The computer security incident response team, CSIRT,...

Full description

Saved in:
Bibliographic Details
Published in:2011 Sixth International Conference on IT Security Incident Management and IT Forensics pp. 107 - 121
Main Authors: Metzger, S., Hommel, W., Reiser, H.
Format: Conference Proceeding
Language:English
Published: IEEE 01-05-2011
Subjects:
Online Access:Get full text
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:We present a holistic, process-oriented approach to ISO/IEC 27001 compliant security incident management that integrates multiple state-of-the-art security tools and has been applied to a real-world scenario very successfully for one year so far. The computer security incident response team, CSIRT, is enabled to correlate IT security related events across multiple communication channels and thus to classify any incidents consistently. Depending on an incident's classification, manual intervention or even fully automated reaction steps can be triggered, this starts with simple email notifications of system and network administrators, and scales up to quarantining compromised systems and sub networks automatically. A formally specified security incident response (SIR) process serves as the basis that clearly defines responsibilities, workflows, and interfaces. It has been designed to enable quick reactions to IT security events in a very resource-conserving manner.
ISBN:9781457701467
1457701464
DOI:10.1109/IMF.2011.15