Security Incident Response Criteria: A Practitioner's Perspective

George Grispos,William Bradley Glisson,Tim Storer
DOI: https://doi.org/10.48550/arXiv.1508.02526
2015-08-11
Abstract:Industrial reports indicate that security incidents continue to inflict large financial losses on organizations. Researchers and industrial analysts contend that there are fundamental problems with existing security incident response process solutions. This paper presents the Security Incident Response Criteria (SIRC) which can be applied to a variety of security incident response approaches. The criteria are derived from empirical data based on in-depth interviews conducted within a Global Fortune 500 organization and supporting literature. The research contribution of this paper is twofold. First, the criteria presented in this paper can be used to evaluate existing security incident response solutions and second, as a guide, to support future security incident response improvement initiatives.
Cryptography and Security,Computers and Society
What problem does this paper attempt to address?