• DocumentCode
    1923597
  • Title

    Integrated Security Incident Management -- Concepts and Real-World Experiences

  • Author

    Metzger, Stefan ; Hommel, Wolfgang ; Reiser, Helmut

  • Author_Institution
    Leibniz Supercomput. Centre, Munich, Germany
  • fYear
    2011
  • fDate
    10-12 May 2011
  • Firstpage
    107
  • Lastpage
    121
  • Abstract
    We present a holistic, process-oriented approach to ISO/IEC 27001 compliant security incident management that integrates multiple state-of-the-art security tools and has been applied to a real-world scenario very successfully for one year so far. The computer security incident response team, CSIRT, is enabled to correlate IT security related events across multiple communication channels and thus to classify any incidents consistently. Depending on an incident´s classification, manual intervention or even fully automated reaction steps can be triggered, this starts with simple email notifications of system and network administrators, and scales up to quarantining compromised systems and sub networks automatically. A formally specified security incident response (SIR) process serves as the basis that clearly defines responsibilities, workflows, and interfaces. It has been designed to enable quick reactions to IT security events in a very resource-conserving manner.
  • Keywords
    IEC standards; ISO standards; Internet; computer interfaces; computer network security; electronic mail; telecommunication channels; ISO/IEC 27001; IT security related events; classification; computer security incident response team; email notifications; fully automated reaction steps; integrated security incident management; interfaces; manual intervention; multiple communication channels; network administrators; state-of-the-art security tools; Electronic mail; Internet; Intrusion detection; Malware; Monitoring; Postal services; ISO/IEC 27001; IT service management; computer security incident response team; intrusion detection; network abuse;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IT Security Incident Management and IT Forensics (IMF), 2011 Sixth International Conference on
  • Conference_Location
    Stuttgart
  • Print_ISBN
    978-1-4577-0146-7
  • Type

    conf

  • DOI
    10.1109/IMF.2011.15
  • Filename
    5931116