SIPES - Security Incident Policy Enforcement
System by Rob J Meijer
and Rick Tucker
This document addresses the main
problems in current incident response handling procedures. It outlines how a
tighter integration of risk assessment, technical security measures, and
incident response policies can lead to more effective incident handling. The
case is also made to expand the designition of incidents to include any event
that might affect the security state of a software product or an
infra-structural component. Finally, the document advocates implementation and
standardization of an information exchange format that integrates security
event, security policy, and event handling tracing information in a way that
respects the needs posed by the required stochastic modeling of risk.
If you are interested in helping with this
project please contact us at
sipes<at>isecom.org
www.sf.net/projects/sipes/
Download:
| Size
Date Time Name
|
Canada |
Spain |
USA |
| 185096
Nov 21 20:12 sipes_goal_0.3.1.pdf.................. |
 |
 |
 |