Title :
Integrated Security Incident Management -- Concepts and Real-World Experiences
Author :
Metzger, Stefan ; Hommel, Wolfgang ; Reiser, Helmut
Author_Institution :
Leibniz Supercomput. Centre, Munich, Germany
Abstract :
We present a holistic, process-oriented approach to ISO/IEC 27001 compliant security incident management that integrates multiple state-of-the-art security tools and has been applied to a real-world scenario very successfully for one year so far. The computer security incident response team, CSIRT, is enabled to correlate IT security related events across multiple communication channels and thus to classify any incidents consistently. Depending on an incident´s classification, manual intervention or even fully automated reaction steps can be triggered, this starts with simple email notifications of system and network administrators, and scales up to quarantining compromised systems and sub networks automatically. A formally specified security incident response (SIR) process serves as the basis that clearly defines responsibilities, workflows, and interfaces. It has been designed to enable quick reactions to IT security events in a very resource-conserving manner.
Keywords :
IEC standards; ISO standards; Internet; computer interfaces; computer network security; electronic mail; telecommunication channels; ISO/IEC 27001; IT security related events; classification; computer security incident response team; email notifications; fully automated reaction steps; integrated security incident management; interfaces; manual intervention; multiple communication channels; network administrators; state-of-the-art security tools; Electronic mail; Internet; Intrusion detection; Malware; Monitoring; Postal services; ISO/IEC 27001; IT service management; computer security incident response team; intrusion detection; network abuse;
Conference_Titel :
IT Security Incident Management and IT Forensics (IMF), 2011 Sixth International Conference on
Conference_Location :
Stuttgart
Print_ISBN :
978-1-4577-0146-7
DOI :
10.1109/IMF.2011.15