Security Management and Incident Handling and Response

Recent resources tagged with Security Management and Incident Handling and Response.

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Incident Response Tracker: Centralized Monitoring, Distributed Response

Added by the EDUCAUSE Librarian
Title:Incident Response Tracker: Centralized Monitoring, Distributed Response (ID: SEC08063)
Author(s):Martin Manjak (University at Albany, SUNY)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

With a mixture of centralized and local IT service providers, higher ed presents unique challenges to effective incident response. The University at Albany has developed a web-based incident management and reporting tool that provides immediate sharing of incident information with local responders and real-time incident response functionality (e.g., switch port control).

View this resource:

Incident Response from the Ground Up

Added by the EDUCAUSE Librarian
Title:Incident Response from the Ground Up (ID: NCP08071)
Author(s):Adam Goldstein (Dartmouth College) and Ellen L. Young (Dartmouth College)
Origin:Presented at NERCOMP Conferences (03/10/2008)
Type:Presentations/Speeches
Abstract:

Recognizing that an incident response policy is only as good as the procedures that support it, Dartmouth College developed its approach to incident response from the bottom up. This session will highlight the advantages of establishing procedures first and policy second when it comes to incident response planning.

View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource:

Data Breaches in Higher Education: From Concern to Action

Added by the EDUCAUSE Librarian
Title:Data Breaches in Higher Education: From Concern to Action (ID: ERM08111)
Author(s):Peter M. Siegel (University of California, Davis)
Origin:EDUCAUSE Review Articles (01/18/2008)
Type:Articles, Papers, and Reports
Abstract:

"When is higher education going to get serious about safeguarding the private information of students,
faculty, and staff?"

View this resource:

Final Report of the 2007 Cybersecurity Summit

Added by the EDUCAUSE Librarian
Title:Final Report of the 2007 Cybersecurity Summit (ID: CYB0701)
Origin:Contributed by the Security Task Force, Presented at Cybersecurity Summit (11/30/2007)
Type:Articles, Papers, and Reports
Abstract:

This is the final report for the 2007 NSF Cybersecurity Summit, held February 22 & 23rd, 2007, in Arlington, VA.

View this resource:

Some Frontiers of Security Work

Added by the EDUCAUSE Librarian
Title:Some Frontiers of Security Work (ID: EDU07115)
Author(s):Joseph E. St Sauver (University of Oregon)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

The higher education community faces increasingly difficult issues of security in a networked world, compounded by the demands of advanced applications. Performance requirements (high bandwidth, end-to-end transparency, new protocols) are essential for the academic mission and innovation, but are not easily accommodated in current approaches to network security. The Salsa group is forging new frontiers to address these issues.

View this resource:

Information Security: Zero to 60 in 10 Years

Added by the EDUCAUSE Librarian
Title:Information Security: Zero to 60 in 10 Years (ID: EDU07251)
Author(s):Howard Muffler (Embry-Riddle Aeronautical University) and Joseph Progar (Embry-Riddle Aeronautical University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

The focus on information security at Embry-Riddle Aeronautical University, as in many institutions, has evolved gradually over a number of years. Beginning with what can best be described as ad hoc initiatives driven by afterthought oversight, the university's focus on information security is maturing into a formalized, integrated business component and directive.

View this resource:

Stop, Drop, and Roll: Prevent and Douse Cyber Incidents

Added by the EDUCAUSE Librarian
Title:Stop, Drop, and Roll: Prevent and Douse Cyber Incidents (ID: EDU07210)
Author(s):Cedric Bennett (Stanford University), Susan A. Blair (University of Florida), and Kathleen Roberts (iSecure Solutions)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Presenting two best-practice models for cyber incidents: To prevent cyber incidents, learn how to use an uncomplicated cyber risk assessment to help you focus your institution's limited resources. When an incident occurs, know how to douse the effect of breach events when notification is required.

View this resource:

Incident Management Capability Metrics

Added by the EDUCAUSE Librarian
Title:Incident Management Capability Metrics (ID: CSD5144)
Source:CERT
Abstract:

The CERT CSIRT Development Team has introduced a method to evaluate and improve an organization's capability for managing computer security incidents. This method uses a set of incident management best practices defined in a set of metrics called the Incident Management Capability Metrics. These metrics provide organizations a baseline against which they can benchmark their current incident management processes or services.

The metrics questions explore different aspects of incident management activities. These questions are grouped into four basic functional categories:

  • Protect
  • Detect
  • Respond
  • Sustain

The results from an evaluation using the metrics will help an organization determine the maturity of its incident management capability regardless of organization type or sector (commercial, academic, government, etc.).

View this resource: