Abstract

Incidence response and handling has become quite a crucial, indispensible constituent of information technology security management, as it provides an organised way of handling the aftermaths of a security breach. It presents an organisation’s reaction to illegitimate and unacceptable exploits on its assets or infrastructure. The goal must be to successfully neutralise the incident, such that damages are significantly reduced with attendant reduction in recovery time and costs. To achieve this, several approaches and methodologies proposed have been reviewed with a view to identifying essential processes. What is needed is referred to as incident capability mingled with collaborations. This defines a shift from response to management of computer security incidents in anointer relationship manner that foster collaboration through the exchange and sharing of incidence management details among several distinct organizations. Key step-up aspects centre on issues of enforcing and assuring trust and privacy. A viable collaborative incident response approach must be able to proffer both proactive and reactive mechanisms that are management-oriented and incorporating all required techniques and procedures.

Highlights

  • Our contemporary society has witnessed a tremendous rise in cyber incidents

  • Incidence response and handling has become quite a crucial, indispensible constituent of information technology security management, as it provides an organised way of handling the aftermaths of a security breach

  • The goal must be to successfully neutralise the incident, such that damages are significantly reduced with attendant reduction in recovery time and costs

Read more

Summary

A Comparative Assessment of Computer Security Incidence Handling

(1) Victor Carvalho, Polytechnic Institute of Cávado and Ave, Portuguese Catholic University and Lusiada University, Portugal. Reviewers: (1) Anonymous, Polytechnic University of Valencia, Spain. (2) Shuai Tao, Information and Engineering College, Dalian University, China.

Introduction
Related Works
Stepwise Forensic Approach
Security Coordination Model
Common Process Model for Incident Response and Computer Forensics
State-of-the-Art Incidence Response
Palantir
Cyber Forensics Incident Response Approach
Incidence Response Approach
Cerebro: A Platform for Collaborative Incident Response and Investigation
Analysis and Discussions
Preparation
Recovery
Incident Response Fissures
Greater Focus on Prevention at the Expense of Monitoring and Response
Weakly Structured Escalation Options
Excesses of the Wrong Kind of Information Too Early
Insufficiency of the Right Kind of Information Too Late
Knowledge-less Response
Findings
Conclusions and Future Work

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.