A MANAGEMENT MODEL FOR BUILDING A COMPUTER SECURITY INCIDENT RESPONSE CAPABILITY

被引:1
|
作者
Mooi, Roderick D. [1 ,2 ]
Botha, Reinhardt A. [2 ]
机构
[1] CSIR, Meraka Inst, Pretoria, South Africa
[2] Nelson Mandela Metropolitan Univ, Sch ICT, Ctr Res Informat & Comp Secur, Pretoria, South Africa
来源
SAIEE AFRICA RESEARCH JOURNAL | 2016年 / 107卷 / 02期
关键词
CSIRT; CERT; establishing requirements; building; incident response team; cyber security team; security operations centre; information security capability; management model;
D O I
10.23919/SAIEE.2016.8531544
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Although there are numerous guides available for establishing a computer security incident response capability, there appears to be no underlying management model that brings them all together. This paper aims to address the problem by developing a management model for establishing a Computer Security Incident Response Team (CSIRT). A design science-based approach has been selected for the overall project. However, the current paper reports on the first three activities in design science research: identifying the problem, listing solution objectives, and designing and developing a model. A comprehensive literature review serves two purposes: to confirm the problem and to provide a structured way of revealing the requirement areas. Following the uncovering of the requirement areas, CSIRT business requirements and services are introduced, before exploring the relationships between the areas using argumentation. This culminates in the development of the management model in two parts: a strategic view and a tactical view. The strategic view comprises the business requirements and "higher" level decisions - the environment, constituency and funding considerations - that need to be made when establishing a CSIRT. The tactical view follows by presenting the "how" considerations. Together, these two views provide an holistic model for establishing a CSIRT by parties interested in doing so.
引用
收藏
页码:78 / 91
页数:14
相关论文
共 50 条
  • [1] Prerequisites for building a computer security incident response capability
    Mooi, Roderick
    Botha, Reinhardt A.
    [J]. 2015 INFORMATION SECURITY FOR SOUTH AFRICA - PROCEEDINGS OF THE ISSA 2015 CONFERENCE, 2015,
  • [2] Should corporate management include a Computer Forensics and Incident Response capability into realigned Information Security Principles?
    Wright, Paul
    [J]. INTERNATIONAL REVIEW OF INFORMATION ETHICS, 2009, 10 : 15 - 22
  • [3] On Computer Security Incident Response Teams
    Horne, Bill
    [J]. IEEE SECURITY & PRIVACY, 2014, 12 (05) : 13 - 15
  • [4] Testing your computer security incident response plan
    Markey, Steve
    [J]. ISACA Journal, 2012, 2
  • [5] Computer Security Incident Response Team Development and Evolution
    Ruefl, Robin
    Dorofee, Audrey
    Mundie, David
    Householder, Allen D.
    Murray, Michael
    Perl, Samuel J.
    [J]. IEEE SECURITY & PRIVACY, 2014, 12 (05) : 16 - 26
  • [6] Security incident response: rethinking risk management
    Alberts, C
    Dorofee, A
    [J]. CARS 2004: COMPUTER ASSISTED RADIOLOGY AND SURGERY, PROCEEDINGS, 2004, 1268 : 141 - 146
  • [7] DSS for computer security incident response applying CBR and collaborative response
    Kim, Huy Kang
    Im, Kwang Hyuk
    Park, Sang Chan
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2010, 37 (01) : 852 - 870
  • [8] A Structured Approach to Guide the Development of Incident Management Capability for Security and Privacy
    Tello-Oquendo, Luis
    Tapia, Freddy
    Fuertes, Walter
    Andrade, Roberto
    Samaniego Erazo, Nicolay
    Torres, Jenny
    Cadena, Alyssa
    [J]. PROCEEDINGS OF THE 21ST INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS (ICEIS 2019), VOL 2, 2019, : 328 - 336
  • [9] Context for the SA NREN Computer Security Incident Response Team
    Mooi, Roderick
    Botha, Reinhardt A.
    [J]. 2016 IST-AFRICA WEEK CONFERENCE, 2016,
  • [10] Computer Security Incident Response Team Effectiveness: A Needs Assessment
    Van der Kleij, Rick
    Kleinhuis, Geert
    Young, Heather
    [J]. FRONTIERS IN PSYCHOLOGY, 2017, 8