Cyber Security Awareness Month 2008 - Summary and Links
On behalf of the volunteer handlers of the SANS Internet Storm Center, I'd like to pass along our deep appreciation to all of the readers who sent in hundreds of comments and ideas during the past month! As promised, below is an index to all of the Cyber Security Awareness Month diaries that were published over the past several weeks. You can also find the daily subjects by searching on the keyword "Awareness2008" in our diary archive. Because we chose to focus on the six steps of incident handling, we went a bit longer than 31 days to allow for the inclusion of step six, Lessons Learned. So as a bonus this year you get 34 days rather than 31!
Here is the schedule that we followed:
Preparation: October 1-4
Identification: October 5-11
Containment: October 12-18
Eradication: October 19-25
Recovery: October 26-31
Lessons Learned: November 1-3
We are working on producing a full document that has all of the submissions (cleaned up, reformatted, and sanitized if needed) that were received. As you can imagine it will be a while before it's ready for downloading due to the volume of information that was sent to us. If you have any final thoughts or want to add some additional tips to the subjects, please send send them to us via our contact form.
1. Preparation
1 Policies, Management Support, and User Awareness
2 Building a Response Team
3 Building Checklists
4 What Goes Into a Response Kit
2. Identification
5 Events versus Incidents
6 Network-based Intrusion Detection Systems
7 Host-based Intrusion Detection Systems
8 Global Incident Awareness
9 Log and Audit Analysis
10 Using Your Help Desk to Identify Security Incidents
11 Other Methods of Identifying an Incident
3. Containment
12 Gathering Evidence That Can be Used in Court
13 Containment on Production Systems Such as a Web Server
14 Containing a Personal IdentityTheft Incident
15 Containing the Damage From a Lost or Stolen Laptop
16 Containing a Malware Outbreak
17 Containing a DNS Hijacking
18 Containing Other Incidents
4. Eradication
19 Forensic Analysis Tools - What Happened?
20 Eradicating a Rootkit
21 Removing Bots, Keyloggers, and Spyware
22 Wiping Disks and Media
23 Turning off Unused Services
24 Cleaning Email Servers and Clients
25 Finding and Removing Hidden Files and Directories
5. Recovery
26 Restoring Systems From Backups
27 Validation via Vulnerability Scanning
28 Avoiding Finger Pointing and the Blame Game
29 Should I Switch Software Vendors?
30 Applying Patches and Updates
31 Legal Awareness (Regulatory, Statutory, etc.)
6. Lessons Learned (November)
1 (32) What Should I Make Public?
2 (33) Working With Management to Improve Processes
3 (34) Feeding The Lessons Learned Back to the Preparation Phase
Marcus H. Sachs
Director, SANS Internet Storm Center
Comments