官术网_书友最值得收藏!

Preparation

The ability to acquire network-based evidence is largely dependent on the preparations that are undertaken by an organization prior to an incident. Without some critical components of a proper infrastructure security program, key pieces of evidence will not be available for incident responders in a timely manner. The result is that evidence may be lost as the CSIRT members hunt down critical pieces of information. In terms of preparation, organizations can aid the CSIRT by having proper network documentation, up-to-date configurations of network devices, and a central log management solution in place.

Aside from the technical preparation for network evidence collection, CSIRT personnel need to be aware of any legal or regulatory issues in regards to collecting network evidence. CSIRT personnel need to be aware that capturing network traffic can be considered an invasion of privacy absent any other policy. Therefore, the legal representative of the CSIRT should ensure that all employees of the organization understand that their use of the information system can be monitored. This should be expressly stated in policies prior to any evidence collection that may take place.

主站蜘蛛池模板: 运城市| 平度市| 仪征市| 阳曲县| 麻阳| 岳阳县| 安庆市| 怀仁县| 进贤县| 达拉特旗| 姜堰市| 湟源县| 伊春市| 廊坊市| 屏边| 开江县| 岱山县| 南投县| 广州市| 沈阳市| 凤山县| 定陶县| 滦平县| 海南省| 蛟河市| 英超| 东兴市| 云安县| 维西| 开原市| 夏津县| 西吉县| 仪征市| 赣州市| 蒙城县| 盐边县| 特克斯县| 宜兰市| 泗水县| 景洪市| 华坪县|