11.07.2015 Views

SIEM for ITIL Incident Response - Part 2 - AlienVault

SIEM for ITIL Incident Response - Part 2 - AlienVault

SIEM for ITIL Incident Response - Part 2 - AlienVault

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2ForewordIn the previous installation of this series, we took a short overview of the current status of <strong>Incident</strong><strong>Response</strong> workflows and conjectured on possible models <strong>for</strong> maturity evolution of the ComputerSecurity <strong>Incident</strong> <strong>Response</strong> service model.This series of documents centers on the following assertions.• The current status quo <strong>for</strong> effective Computer Security <strong>Incident</strong> <strong>Response</strong>is actually a very immature service model in comparison to other ServiceDomains within In<strong>for</strong>mation Technology in the Enterprise.• Evolving IR into a more mature service model, will produce largequantities of valuable data <strong>for</strong> business intelligence and metrics.• The in<strong>for</strong>mation necessary to build this more mature model, does notactually create additional ongoing workload <strong>for</strong> <strong>Incident</strong> <strong>Response</strong> Teams,but actually acts as a <strong>for</strong>ce-multiplier to make existing work more effectiveand efficient.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!