Rethinking Security Incident Response: The Integration of Agile Principles

George Grispos,William Bradley Glisson,Tim Storer
DOI: https://doi.org/10.48550/arXiv.1408.2431
2014-08-11
Cryptography and Security
Abstract:In today's globally networked environment, information security incidents can inflict staggering financial losses on organizations. Industry reports indicate that fundamental problems exist with the application of current linear plan-driven security incident response approaches being applied in many organizations. Researchers argue that traditional approaches value containment and eradication over incident learning. While previous security incident response research focused on best practice development, linear plan-driven approaches and the technical aspects of security incident response, very little research investigates the integration of agile principles and practices into the security incident response process. This paper proposes that the integration of disciplined agile principles and practices into the security incident response process is a practical solution to strengthening an organization's security incident response posture.
What problem does this paper attempt to address?