05/15/2012 | Incident Response & Investigations
The Incident Response and Planning track at the IANS Twin Cities and New York Metro Forums built on ideas presented earlier in the quarter. Marcus Ranum offered delegates his thoughts around how to better prepare for and thwart an incident. Like at the Mid-Atlantic Forum, Twin Cities and New York delegates wanted to discuss with peers ways they and their teams can break down what
05/08/2012 | Incident Response & Investigations
Compromised computers are a fact of life for all organizations, but not all compromises are equal. If a representative of a United States law enforcement or military intelligence agency visited your office to report a targeted incident, what would you do? In this presentation, Mandiant Chief Security Officer Richard Bejtlich presented this question to the audience and guided them
05/08/2012 | Incident Response & Investigations
View this short video to see what you can expect when you attend the Incident Response & Planning track at IANS' Information Security Forums!
03/29/2012 | Incident Response & Investigations
The Incident Response and Planning track at the IANS Mid-Atlantic Information Security Forum was led by Faculty members Marcus Ranum and John Galda. The track was designed to encourage delegates to think more strategically about their incident response plans and capabilities. Adversaries are leveraging any and all resources available, and this Forum track walked participants
03/13/2012 | Incident Response & Investigations
IANS clients frequently ask about best practices in building a malware response plan. The primary request is for recommendations on how to go about making the right decisions about how and when to proceed, and at what point they should begin a forensics investigation or have a third-party step in to conduct an investigation on their behalf. The following document outlines a few of
03/05/2012 | Incident Response & Investigations
Event correlation is one of the trickier information security topics: everyone knows they want it, the vendors want to provide it, but nobody seems to understand exactly what it means. This document will provide an introduction to some of the things about which security professionals should start thinking before they embark on their event correlation strategy.
02/15/2012 | Incident Response & Investigations
Incident response is a top topic on the mind of IANS' clients. Every major organization knows that suspicious activity occurs on their network. The key, though, lies in how to best handle the "interesting" items as they are uncovered. This document outlines some basic techniques for managing incidents and creating a plan for process improvement.
02/10/2012 | Incident Response & Investigations
IANS Faculty Marcus Ranum shares a preview of what delegates can expect to experience during the incident response and planning track at IANS' upcoming Information Security Forums.