Using a Common Language for Computer Security Incident Information

John Douglas Howard · 2012

This chapter discusses use of a common language for computer security incident information. A computer security incident is some set of events that involves an attack or series of attacks at one or more sites. Dealing with these incidents is inevitable for individuals and organizations at all levels of computer security. A major part of dealing with these incidents is recording and receiving incident information, which almost always is in the form of relatively unstructured text files. Over time, these files can end up containing a large quantity of very valuable information. Unfortunately, the unstructured form of the information often makes incident information difficult to manage and use. This chapter discusses the efforts to develop and propose a method to handle several unstructured computer security incident records. It presents a tool—the common language for computer security incident information—designed to help individuals and organizations record, understand, and share computer security incident information. The chapter discusses two parts of this tool and also outlines some practical ways to use the common language.

Read the paper · More papers on PaperTik