Preparation, detection, and analysis: the diagnostic work of IT security incident response
نویسندگان
چکیده
Purpose – The purpose of this paper is to examine security incident response practices of information technology (IT) security practitioners as a diagnostic work process, including the preparation phase, detection, and analysis of anomalies. Design/methodology/approach – The data set consisted of 16 semi-structured interviews with IT security practitioners from seven organizational types (e.g. academic, government, and private). The interviews were analyzed using qualitative description with constant comparison and inductive analysis of the data to analyze diagnostic work during security incident response. Findings – The analysis shows that security incident response is a highly collaborative activity, which may involve practitioners developing their own tools to perform specific tasks. The results also show that diagnosis during incident response is complicated by practitioners’ need to rely on tacit knowledge, as well as usability issues with security tools. Research limitations/implications – Owing to the nature of semi-structured interviews, not all participants discussed security incident response at the same level of detail. More data are required to generalize and refine the findings. Originality/value – The contribution of the work is twofold. First, using empirical data, the paper analyzes and describes the tasks, skills, strategies, and tools that security practitioners use to diagnose security incidents. The findings enhance the research community’s understanding of the diagnostic work during security incident response. Second, the paper identifies opportunities for future research directions related to improving security tools.
منابع مشابه
Towards Understanding Diagnostic Work During the Detection and Investigation of Security Incidents
This study investigates how security practitioners perform diagnostic work during the identification of security incidents. Based on empirical data from 16 interviews with security practitioners, we identify the tasks, skills, strategies and tools that security practitioners use to diagnose security incidents. Our analysis shows that diagnosis is a highly collaborative activity, which may invol...
متن کاملTowards Agile Industrial Control Systems Incident Response
The integration of Industrial Control Systems (ICS) with IT systems has increased the ICS’ exposure to cyber threats. We have seen a tremendous increase in the number of security incidents happened to ICS in the past five years. This requires the ICS to provide effective incident response capabilities to counteract security attacks. Previous research on ICS incident response has been focusing o...
متن کاملDetection of extra-cardiac hypermetabolic foci by [18F]FDG PET/CT in case of infective endocarditis and post antibiotic therapy response assessment
The diagnosis of prosthetic valve endocarditis continues to present a diagnostic challenge, due to the lower sensitivity of the modified Duke criteria and a higher percentage of negative or inconclusive echocardiography results. Diagnostic delay might result in significant morbidity/mortality. Imaging modalities like 2-[18F]fluoro-2-deoxy-D-glucose positron emission tomography/comput...
متن کاملHospitals Readiness in Response to COVID-19 Pandemic in Mazandaran Province, Iran 2020
Background and purpose: Hospitals are one of the vital pillars of the health system. Hospital preparedness in epidemics is a dynamic, complex and multidimensional process that shows the developed capacities and capabilities of the hospital in predicting, reducing the effects, resistance, response, and recovery in the face of biological events. The aim of this study was to investigate the readin...
متن کاملBest Practices in Computer Network Defense: Incident Detection and Response
" The book identifies the state-of-the-art tools and processes being used for cyber defense and highlights gaps in the technology. It presents the best practice of industry and government for incident detection and reponse and examines indicators and metrics for progress along the security continuum. "-Belfer Center (Harvard Kennedy School) The cyber security of vital infrastructure and service...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Inf. Manag. Comput. Security
دوره 18 شماره
صفحات -
تاریخ انتشار 2010