Главная
Study mode:
on
1
Introduction
2
Proactive defenses dont always work
3
Are you ready
4
Industry Standards
5
Response Ready Infrastructure
6
snort alert
7
answering questions
8
you need people
9
Incident Response Processes
10
Technical Controls Defenses
11
NIST 861
12
What Log Should We Collect
13
Indicators
14
Hostbased indicators
15
Asset inventory
16
Port scans
17
Analysis tools
18
Network detection
19
Privileges
20
Visibility
21
Blocking
22
Endpoint
23
Communications
24
Access Controls
25
San CSC
Description:
Explore the concept of Response Ready Infrastructure in this BSides Cincinnati 2015 conference talk. Learn why proactive defenses aren't always sufficient and how to prepare for potential security incidents. Discover industry standards, incident response processes, and technical control defenses. Gain insights into the NIST 861 framework, essential log collection practices, and various indicators to monitor. Examine host-based indicators, asset inventory management, port scanning techniques, and analysis tools. Delve into network detection strategies, privilege management, visibility enhancement, and blocking mechanisms. Understand the importance of endpoint security, communications protocols, and access controls. Acquire knowledge on implementing a comprehensive security strategy aligned with the San CSC framework.

The Response Ready Infrastructure

Add to list
0:00 / 0:00