Computer Security Incident Response Team Effectiveness: A Needs Assessment

Computer Security Incident Response Team Effectiveness: A Needs Assessment
复制标题

计算机安全事件响应团队的有效性:需求评估

DOI:
--
复制
发表时间:
2017
影响因子:
3.8
通讯作者:
Heather Young
Heather Young
中科院分区:
心理学3区
文献类型:
--
作者:
Rick van der Kleij;G. Kleinhuis;Heather Young

文献摘要

被引文献

相似文献

计算机安全事件响应团队 (CSIRT) 在需要时响应计算机安全事件。这些团队的失败可能会对经济和国家安全产生深远的影响。 CSIRT 通常必须在时间有限的环境中与其他团队密切合作,进行临时工作。可以说,在这些工作条件下,CSIRT 可能会遇到问题。我们进行了需求评估,看看这个论点在多大程度上成立。我们构建了一个事件响应需求模型,以帮助确定需要改进的领域。我们设想了一个由四个评估类别组成的模型:组织、团队、个人和工具。其核心思想是,问题和需求都可以具有组织、团队、个人或技术起源或这些级别的组合。为了收集数据,我们进行了文献综述。这导致了一份全面的挑战和需求列表,这些挑战和需求可能分别阻碍或提高 CSIRT 的性能。然后,与五个公共和私营部门荷兰 CSIRT 的团队协调员和团队成员进行了半结构化深度访谈,将这些发现落实到实践中,并确定当前和期望的事件处理实践之间的差距。本文介绍了我们的需求评估结果,最后讨论了事件响应性能问题的潜在解决方案。
Computer security incident response teams (CSIRTs) respond to a computer security incident when the need arises. Failure of these teams can have far-reaching effects for the economy and national security. CSIRTs often have to work on an ad hoc basis, in close cooperation with other teams, and in time constrained environments. It could be argued that under these working conditions CSIRTs would be likely to encounter problems. A needs assessment was done to see to which extent this argument holds true. We constructed an incident response needs model to assist in identifying areas that require improvement. We envisioned a model consisting of four assessment categories: Organization, Team, Individual and Instrumental. Central to this is the idea that both problems and needs can have an organizational, team, individual, or technical origin or a combination of these levels. To gather data we conducted a literature review. This resulted in a comprehensive list of challenges and needs that could hinder or improve, respectively, the performance of CSIRTs. Then, semi-structured in depth interviews were held with team coordinators and team members of five public and private sector Dutch CSIRTs to ground these findings in practice and to identify gaps between current and desired incident handling practices. This paper presents the findings of our needs assessment and ends with a discussion of potential solutions to problems with performance in incident response.