Incident Response
By
Kenneth R. van Wyk,
Richard Forno
August 2001
Pages: 234
| Table of Contents
| Index
| Sample Chapter
| Colophon
Table of Contents
-
Chapter 1 What Is Incident Response?
-
Real-Life Incidents
-
What Is an Incident?
-
About the Bad Guys
-
What Is Incident Response?
-
Risk Assessment and Incident Response
-
Development of Incident Response Efforts
-
Are You Ready? Are You Willing?
-
Chapter 2 Incident Response Teams
-
Who Should Do It?
-
Public Resource Teams
-
Internal Teams
-
Commercial Teams
-
Vendor Teams
-
Ad Hoc Teams
-
Forum of Incident Response and Security Teams (FIRST)
-
Now Who Should Do It?
-
Chapter 3 Planning the Incident Response Program
-
Establishing the Incident Response Program
-
Internal Versus External
-
Types of Incidents
-
Who Are the Clients?
-
Summary
-
Chapter 4 Mission and Capabilities
-
Roles and Responsibilities
-
Staffing and Training
-
Involving the Critical Players
-
List of Contacts
-
Setting Up a Hotline
-
Establishing Procedures
-
Awareness and Advertising
-
Fire Drills
-
Issues and Pitfalls
-
Chapter 5 State of the Hack
-
The Moving Target
-
Keeping Up with Attack Profiles
-
Training
-
Chapter 6 Incident Response Operations
-
We've Been Hit -- Now What?
-
Incident Response Processes
-
While Under Pressure
-
Chapter 7 Tools of the Trade
-
What's Out There?
-
Network-Based Tools
-
Network Monitors and Protocol Analyzers
-
Network-Based Intrusion Detection Systems
-
Network Vulnerability Scanners
-
Other Essential Network-Based Tools
-
Host-Based Tools
-
Communications
-
Encryption
-
Removable Storage Media
-
The Incident Kit
-
If We Ruled the World
-
Chapter 8 Resources
-
Security Information on the Web
-
Incident Response Team Resources
-
Commercial Incident ResponseService Providers
-
Antivirus Products
-
Mailing Lists and Newsgroups
-
U.S. Government Resources
-
Training, Conferences, and Certification Programs
-
Legal Resources
-
Appendix A FIRST
-
FIRST Statement of Mission and Strategic Goals
-
FIRST Member Team Information
-
Appendix B Sample Incident Report
-
Incident Chronology
-
Law Enforcement Coordination
-
Damage Assessment
-
Management Review
-
Colophon
Return to Incident Response