IT Security Vulnerability and Incident Response Management

W.H.M. Hafkamp

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    28 Downloads (Pure)

    Abstract

    This paper summarises the results of a Dutch PhD research project on IT security vulnerability and incident response management, which is supervised by the University of Twente in the Netherlands and which is currently in its final stage. Vulnerabilities are ‘failures or weaknesses in computer (application) system design, implementation or operation which can be exploited to violate the security policy defined for that system’. Incidents are defined as ‘events that have actual or potentially adverse effects on computer or network operations resulting in fraud, waste or abuse, compromise of information or loss or damage of property of information’. Hacking, denial-of-service attacks and computer viruses are examples of such events. The research project identifies a number of shortcomings in IT service management processes which affect the speed and quality of IT security vulnerability and incident response processes in enterprises. To shorten the lifecycle of vulnerabilities organizations should implement three basic process elements: (1) filtering and analyzing of vulnerability announcements and alerts, (2) prioritizing of vulnerability response activities and (3) scanning of infrastructure components. Each of these steps can be related to specific IT service management processes and to IT security incident management in particular. Using checklists, procedures and dedicated response capabilities, IT organizations are able to faster detect and respond to incidents.
    Original languageEnglish
    Title of host publicationISSE 2006 — Securing Electronic Busines Processes
    Subtitle of host publicationHighlights of the Information Security Solutions Europe 2006 Conference
    EditorsSachar Paulus, Norbert Pohlman, Helmut Reimer
    Place of PublicationWiesbaden
    PublisherVieweg
    Pages387-395
    Number of pages9
    ISBN (Print)978-3-8348-0213-2
    DOIs
    Publication statusPublished - Oct 2006
    EventInformation Security Solutions Europe Conference, ISSE 2006 - Rome, Italy
    Duration: 10 Oct 200612 Oct 2006

    Conference

    ConferenceInformation Security Solutions Europe Conference, ISSE 2006
    Abbreviated titleISSE
    CountryItaly
    CityRome
    Period10/10/0612/10/06

    Keywords

    • Intrusion detection system
    • Security vulnerability
    • Security incident
    • Incident management
    • Incident response

    Fingerprint Dive into the research topics of 'IT Security Vulnerability and Incident Response Management'. Together they form a unique fingerprint.

  • Cite this

    Hafkamp, W. H. M. (2006). IT Security Vulnerability and Incident Response Management. In S. Paulus, N. Pohlman, & H. Reimer (Eds.), ISSE 2006 — Securing Electronic Busines Processes: Highlights of the Information Security Solutions Europe 2006 Conference (pp. 387-395). Wiesbaden: Vieweg. https://doi.org/10.1007/978-3-8348-9195-2_41