Resources for Incident Handling

Opinion
Nov 24, 20081 min

Security incident handling, after many years of exposure, is still one of those ‘sticky’ subjects that can get any organization in a lot of trouble. Other than phreaking and other switch or voicemail-related mischief, the rather isolated telecommunications networks of yesterday aren’t nearly as susceptible to the coordinated attacks that plague servers, routers, and UC and IP-PBX platforms these days. Of course, you need your system to be somewhat visible in order to maintain effective connectivity to endpoints and peers, but just how “visible”? We’ve discussed security for these systems in the past, but the pure cases of “incident handling” bring their own set of questions and problems. Our friends over at the SANS Internet Storm Center recently featured a few very good resources on their SANS ISC Handler’s Diary page. In particular, they mentioned 2 Cheat Sheets For Incident Handling. Check out these wonderful resources, and start asking the incident handling questions now. Preventative planning saves potential disaster later!