16.04.2014 Views

vPLfv

vPLfv

vPLfv

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

List of Tables<br />

Table 1 Review of Incident Management Processes from Various Publications. 20<br />

Table 2: Detect Events Workflow Example ......................................................... 32<br />

Table 3: Key to Incident Management Process Map Symbols ............................ 42<br />

Table 4: Incident Management Workflow Description Information Categories..... 47<br />

Table 5: Incident Management Handoff Description Information Categories....... 48<br />

Table 6: PC: Prepare/Sustain/Improve Workflow Description.............................. 58<br />

Table 7:<br />

Table 8:<br />

Handoff from Any Activity Inside or Outside CSIRT Process to PC:<br />

Prepare/Sustain/Improve ...................................................................... 70<br />

Handoff from PC: Prepare/Sustain/Improve to<br />

PI: Protect Infrastructure ....................................................................... 74<br />

Table 9: PI: Protect Infrastructure Workflow Description ..................................... 82<br />

Table 10:<br />

Handoff from Any Activity Inside or Outside CSIRT Process to<br />

PI: Protect Infrastructure ....................................................................... 88<br />

Table 11: Handoff from PI: Protect Infrastructure to D: Detect Events .................. 92<br />

Table 12: D: Detect Events Workflow Description............................................... 100<br />

Table 13: Handoff from Any Activity Inside or Outside of the Organization to D:<br />

Detect Events ..................................................................................... 106<br />

Table 14: Handoff from D: Detect Events to T: Triage Events.............................. 110<br />

Table 15: T: Triage Events Workflow Description ................................................ 118<br />

Table 16: Handoff from T: Triage Events to R: Respond ..................................... 124<br />

Table 17: R: Respond Workflow Description....................................................... 134<br />

Table 18: Handoff from R: Respond to PC: Prepare/Sustain/Improve................. 142<br />

CMU/SEI-2004-TR-015<br />

vii

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!