02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

mission, 51, 74, 77, 84, 90, 93, 98, 105,<br />

124, 129<br />

mission statement, 51<br />

misuse <strong>of</strong> resources, 11<br />

models, 15, 53, 69, 72, 89, 99, 107, 108,<br />

137<br />

monitoring<br />

IDS, 68, 70<br />

<strong>of</strong> network and system logs, 68<br />

Morris Worm, 17<br />

MSSPs, 16, 44, 46, 51, 55, 99<br />

multi-layered security strategy, 1<br />

mutual assistance, 117<br />

Mx-CERT, 30, 31<br />

MyCERT, 29, 55, 56<br />

NASA, 19, 21<br />

NASA ARC CNSRT, 21<br />

National Autonomus University <strong>of</strong><br />

Mexico, 31<br />

National <strong>Computer</strong> <strong>Security</strong> Center, 18<br />

National Cyber <strong>Security</strong> Division, 34<br />

National Hurricane Preparedness Center,<br />

97<br />

National Institute <strong>of</strong> Justice, 115<br />

National Institute <strong>of</strong> Standards and<br />

Technology. See NIST<br />

national research networks, 22, 44<br />

National <strong>Security</strong> Agency, 18, 79<br />

Naval <strong>Computer</strong> <strong>Incident</strong> <strong>Response</strong> Team<br />

(NAVCIRT), 21<br />

NBSO, 30, 31<br />

Nebraska, <strong>State</strong> <strong>of</strong>, 85<br />

network<br />

activity, 125<br />

administrators, 5<br />

monitoring programs, 88<br />

sensors, 88<br />

services, 17<br />

sniffer programs, 109<br />

surveillance techniques, 130<br />

New South Wales Police, 82<br />

New Technologies Inc. (NTI), 159<br />

NIC BR <strong>Security</strong> Office - Brazilian<br />

<strong>Computer</strong> Emergency <strong>Response</strong><br />

Team, 30<br />

Nimda worm, 114<br />

NIST, 19, 20, 21, 83, 161, 163<br />

NIST Contingency Planning Guide for<br />

Information Technology Systems, 131<br />

NIST Special Publication 800-34, 153<br />

NITC, 92<br />

no authority, 53<br />

non-disclosure agreements, 75, 77, 106<br />

notification lists, 112<br />

NT/2000, 101<br />

number <strong>of</strong> incidents, 104<br />

Office <strong>of</strong> Critical Infrastructure Protection<br />

and Emergency Preparedness<br />

(OCIPEP), 33<br />

<strong>of</strong>f-<strong>the</strong>-shelf recording products, 94<br />

OILZ, 20, 21<br />

operational coordination, 135<br />

operational guidance, 74<br />

Oracle, 94<br />

organizational models. See models<br />

Organizational Models for CSIRTs, 5, 6,<br />

16, 65<br />

organizational structure, 49, 135<br />

orientation, <strong>of</strong> new employees, 77<br />

Ottawa, 33<br />

outsourcing, 65, 75, 101<br />

parent organization funding, 55<br />

part-time staff, 72<br />

penetration testing, 68, 75<br />

perpetrators, 105<br />

personnel. See staff<br />

Pethia, Richard D., 20<br />

PGP, 105<br />

PH-CERT, 29<br />

Philippine <strong>Computer</strong> Emergency<br />

<strong>Response</strong> <strong>Teams</strong>, 29<br />

PHP, 125<br />

pitfalls, 48<br />

plan <strong>of</strong> action, 14<br />

platform specialists, 73, 75<br />

point <strong>of</strong> contact, 24, 28, 85, 117<br />

policies and procedures, 47, 59, 75, 83,<br />

84, 86, 98, 108, 112, 115, 124, 127,<br />

134, 179<br />

policy attributes, 109<br />

policy design and implementation, 108<br />

polymorphic tools, 111<br />

postmortem, 83<br />

post-secondary education institutions, 49<br />

practices, 82<br />

preparation/protection, 83, 86, 133<br />

PRESECURE, 159<br />

Presidential Decision Directive 63, 173<br />

Pretty Good Privacy, 105<br />

prioritizing<br />

activities, 106, 129<br />

incidents, 95<br />

268 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!