CIRT Management: Continuous process improvement

Opinion
Feb 15, 20074 mins

* Retain the knowledge gained through analysis of incidents

This is another in an occasional series of articles looking at computer incident response team (CIRT) management. In my last column, I discussed the importance of root-cause analysis. Today I’d like to present arguments in favor of systematic dissemination throughout the organization of the knowledge gained through incident postmortem and root-cause analysis.

In my previous columns, I have referred to the National Institute of Standards and Technology _Computer Security Incident Handling Guide_ by Tim Grance, Karen Kent and Brian Kim. This free, 148-page text is clearly written and packed with practical, useful information and suggestions for anyone wanting to design, implement, manage, and improve their CIRT.

On page 3-23, the authors make a series of recommendations on how to capitalize on the knowledge gained through systematic analysis of incidents. I am commenting briefly on each of their suggestions (shown in quotation marks).

* “Reports from these meetings are good material for training new team members by showing them how more experienced team members respond to incidents.”

The incident reports that were used for discussion in the analytic meetings should be made available, perhaps as appendices, in a single report document so that all of the information about a specific incident or series of incidents can be accessed at one time. In what follows, such a dossier is referred to as the “follow-up report.”

* “Another important post-incident activity is creating a follow-up report for each incident, which can be quite valuable for future use.”

The general principle is that without documentation, we lose the opportunity for increasing institutional knowledge. If we don’t record what we have learned, transmission depends on luck: the haphazard contacts of people who need to know something with those who can help. Without documentation and efficient indexing, information transferred becomes an inefficient, random process of querying and guesswork. Informal knowledge sometimes remains limited to a few people or even a single individual; without these key resources, the information is unavailable. If the holders of undocumented information leave the organization their knowledge is usually lost to the group.

* “First, the report provides a reference that can be used to assist in handling similar incidents.”

Why waste time reinventing solutions that have already been found? Why make the same errors and cause the same problems that have already been located and that could be avoided?

* “Creating a formal chronology of events (including timestamped information such as log data from systems) is important for legal reasons, as is creating a monetary estimate of the amount of damage the incident caused in terms of any loss of software and files, hardware damage, and staffing costs (including restoring services).”

One of the most important kinds of information for managing security is cost estimates. Rational allocation of resources depends on knowing how often problems occur and how much they cost so that we can reasonably spend appropriate money in the form of equipment and the time of our employees or consultants to prevent such problems.

* “This estimate may become the basis for subsequent prosecution activity by entities such as the U.S. Attorney General’s office.”

Estimates of monetary consequences are also essential for civil torts in the calculation of restitution.

* “Follow-up reports should be kept for a period of time as specified in record retention policies.”

As the authors discuss in another section and as I will discuss in my next article, historical records become increasingly useful as they provide a statistical base for analyzing and predicting phenomena. The costs of saving such report data (which have relatively small volumes) have dropped to virtually nothing, given the huge digital storage capacities of today’s archival media and their extremely low cost.

Editor’s Note: Check out Networkworld.com’s latest feature, Microsoft Subnet

Every day, our editors scour the Web to collect the most interesting and important Microsoft-related blogs, news, discussion forums and security alerts and present them to you on one page. At Microsoft Subnet, readers can create their own blogs and comment on the Microsoft news and issues of the day.