Incident Management Capability Metrics Version 0.1

Abstract

Successful management of incidents that threaten an organization's cyber security is a complex endeavor. Frequently an organization's primary focus on the response aspects of security incidents results in its failure to manage incidents beyond simply reacting to threatening events. The metrics presented in this document are intended to provide a baseline or benchmark of incident management practices. The incident management functions provided in a series of questions and indicators define the actual benchmark. The questions explore different aspects of incident management activities for protecting, defending, and sustaining an organization's computing environment in addition to conducting appropriate response actions. This benchmark can be used by an organization to assess how its current incident management capability is defined, managed, measured, and improved. This will help assure the system owners, data owners, and operators that their incident management services are being delivered with a high standard of quality and success, and within acceptable levels of risk.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Apr 01, 2007
Accession Number
ADA468688

Entities

People

  • Audrey Dorofee
  • Georgia Killcrece
  • Mark Zajicek
  • Robin Ruefle

Tags

Communities of Interest

  • Cyber
  • Engineered Resilient Systems
  • Human Systems

DTIC Thesaurus Topics

  • Anti-Virus Software
  • Business Administration
  • Communication Channels
  • Computer Network Security
  • Computer Networks
  • Computer Programming
  • Computer Security Software
  • Computers
  • Control Systems
  • Cybersecurity
  • Data Analysis
  • Information Exchange
  • Information Systems
  • Management Personnel
  • Mobile Phones
  • Network Protocols
  • Organizational Structure

Readers

  • Emergency Management and Homeland Security.
  • Enterprise Information Systems Architecture and Joint Command Capability Interoperability Support.
  • Instructional Design and Training Evaluation.

Technology Areas

  • Cyber