官术网_书友最值得收藏!

Preparation

The ability to acquire network-based evidence is largely dependent on the preparations that are undertaken by an organization prior to an incident. Without some critical components of a proper infrastructure security program, key pieces of evidence will not be available for incident responders in a timely manner. The result is that evidence may be lost as the CSIRT members hunt down critical pieces of information. In terms of preparation, organizations can aid the CSIRT by having proper network documentation, up-to-date configurations of network devices, and a central log management solution in place.

Aside from the technical preparation for network evidence collection, CSIRT personnel need to be aware of any legal or regulatory issues in regards to collecting network evidence. CSIRT personnel need to be aware that capturing network traffic can be considered an invasion of privacy absent any other policy. Therefore, the legal representative of the CSIRT should ensure that all employees of the organization understand that their use of the information system can be monitored. This should be expressly stated in policies prior to any evidence collection that may take place.

主站蜘蛛池模板: 加查县| 三穗县| 寻甸| 营山县| 安多县| 雅江县| 于田县| 武定县| 宕昌县| 兰坪| 古蔺县| 镇远县| 宜黄县| 林西县| 德钦县| 绥化市| 乌鲁木齐市| 广灵县| 岚皋县| 绥棱县| 都兰县| 缙云县| 甘洛县| 肥东县| 天台县| 龙海市| 宜川县| 鄂伦春自治旗| 长治县| 桐城市| 林甸县| 黄浦区| 招远市| 博白县| 尖扎县| 吉木萨尔县| 若羌县| 会理县| 广东省| 喜德县| 德化县|