Title :
Operationalizing the coordinated incident handling model
Author :
Daley, Rose ; Millar, Thomas ; Osorno, Marcos
Author_Institution :
Appl. Phys. Lab., Johns Hopkins Univ., Laurel, MD, USA
Abstract :
Cyber threats are becoming increasingly sophisticated and subtle, making them even harder to detect and contain, and the number of critical, often simultaneous cyber incidents continues to rise at an alarming rate. In this environment, coordinated incident handling across a variety of organizations and incidents is essential for effective response. Current approaches use linear processes developed to handle single incidents with little attention paid to simultaneous or complex attacks encompassing many incidents, to coordination with other organizations, or the ability to scale to the size necessary for large, cross-cutting incidents. We have developed a coordination model for cyber incident management that provides enough structure to enable cooperative operations, but is sufficiently abstract to enable the organizational autonomy and customization essential for effective response for all types of organizations. It is easily understood, straightforward to apply, and versatile enough to overlay on existing organizational processes and structures, both for small, local activities as well as large, cross-organizational ones. This model will enable faster recognition and more rapid escalation of important cyber incidents as well as improving knowledge about such incidents for organizational peers across the community, further enhancing their local response capabilities.
Keywords :
groupware; organisational aspects; peer-to-peer computing; security of data; cooperative operation; coordinated incident handling model; customization; cyber incident management; cyber threats; large cross-organizational activities; local response capabilities; organizational autonomy; organizational peers; organizational process; organizational structure; Computational modeling; Computer security; Decision making; Monitoring; Organizations; Standards organizations;
Conference_Titel :
Technologies for Homeland Security (HST), 2011 IEEE International Conference on
Conference_Location :
Waltham, MA
Print_ISBN :
978-1-4577-1375-0
DOI :
10.1109/THS.2011.6107886