首页> 外文会议>IFIP TC 11 International conference on information security and privacy >Understanding Collaborative Challenges in IT Security Preparedness Exercises
【24h】

Understanding Collaborative Challenges in IT Security Preparedness Exercises

机译:了解IT安全准备练习中的协同挑战

获取原文

摘要

IT security preparedness exercises allow for practical collaborative training, which in turn leads to improved response capabilities to information security incidents for an organization. However, such exercises are not commonly performed in the electric power industry. We have observed a tabletop exercise as performed by three organizations with the aim of understanding challenges of performing such exercises. We argue that challenges met during exercises could affect the response process during a real incident as well, and by improving the exercises the response capabilities would be strengthened accordingly. We found that the response team must be carefully selected to include the right competences and all parties that would be involved in a real incident response process, such as technical, managerial, and business responsible. Further, the main goal of the exercise needs to be well understood among the whole team and the facilitator needs to ensure a certain time pressure to increase the value of the exercise, and both the exercise and existing procedures need to be reviewed. Finally, there are many ways to conduct preparedness exercises. Therefore, organizations need to both optimize current exercise practices and experiment with new ones.
机译:IT安全准备练习允许实际协作培训,这反过来导致改善组织信息安全事件的响应能力。然而,这种练习通常在电力行业中不常见。我们已经观察到三个组织执行的桌面练习,目的是了解执行此类练习的挑战。我们认为,在练习期间遇到的挑战可能会影响真正的事件期间的响应过程,通过改善锻炼,将相应加强响应能力。我们发现,响应小组必须仔细选择,包括合适的能力和所有缔约方将参与真正的事件响应过程,例如技术,管理和业务负责。此外,锻炼需求的主要目标得到很好的整个团队和主持人的需求之一理解为保证一定的时间压力,以增加锻炼的价值,既锻炼和现有的程序需要进行审查。最后,有很多方法可以进行准备练习。因此,组织需要优化当前的运动实践和与新的实践进行实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号