+ All Categories
Home > Documents > 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright...

1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright...

Date post: 21-Jan-2016
Category:
Upload: ella-butler
View: 214 times
Download: 1 times
Share this document with a friend
Popular Tags:
10
1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.
Transcript
Page 1: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

1

Effective Incident Response

Presented by Greg Hedrick, Manager of Security Services

Copyright Purdue University 2007. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

Page 2: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

2

Effective Incident Response

Why start a formal program?

Definition of an IT Incident

The Process

Infrastructure Requirements

Communications Channels

Notable Items

Page 3: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

3

Why start a formal program?

Manage Communications

Proactive Opportunities

Awareness Opportunities

Regulatory Compliance

Standardize Procedures

Identify System Owners

Page 4: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

4

Definition of an IT Incident

Purdue Policy Definition• Any event involving University IT Resources which

• violates Indiana state or U.S. federal law, or • violates regulatory requirements which Purdue is

obligated to honor, or • violates Purdue University policies, or • is determined to be harmful to the security and

privacy of University data, or IT Resources associated with, students, faculty, staff, and/or the general public, or

• is construed as harassment, or • involves the unexpected disruption of University

services.

Page 5: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

5

The Process

Page 6: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

6

The ProcessData Exposure Example

Page 7: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

7

Infrastructure Requirements

People

Tools

Policy

Documented Procedures

Page 8: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

8

Communication Channels

Secure Wiki

Policy

Presentations / Training

Trusted Community

Procedures

Mailing Lists

Monthly Reports

Page 9: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

9

Notable Items

Clearly define “investigable” events Dedicate staff to the process Define “incident” carefully Clearly define roles and responsibilities Establish policy, procedures, training

and infrastructure in parallel Be prepared immediately for

management reporting

Page 10: 1 Effective Incident Response Presented by Greg Hedrick, Manager of Security Services Copyright Purdue University 2007. This work is the intellectual property.

10

Questions?

http://www.purdue.edu/securepurdue/steam/about.cfm

Greg [email protected]


Recommended