11.07.2015 Views

SIEM for ITIL Incident Response - Part 2 - AlienVault

SIEM for ITIL Incident Response - Part 2 - AlienVault

SIEM for ITIL Incident Response - Part 2 - AlienVault

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

173 – DEFINEDAt this stage, <strong>Incident</strong> <strong>Response</strong> has begun to be fundamentally aligned to businessprocesses, evolving away from a functional fixation on security vulnerabilities and attackstowards a larger view of operational fulfillment of the enterprise, and services offerings beginto reflect this.Detection• Intrusion Detection1) All services from stage 1+2• Compliance Management1) All services from stage 1+2Remediation• Disaster Recovery1) Validation of Restoration <strong>for</strong> Compromised Systems.2) Identification of compromised intellectual property.• Business Continuity1) All services from stage 1+22) Continuous Improvement of Security Controls Configuration3) Directed remediation of exposures created by business operationsMetrics• Security Posture1) All services from stage 1+2• Resourcing1) Gap Analysis of Security Controls Effectiveness.Intelligence1) All services from stage 1+22) Trends in Targeting of specific business units.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!