Cristin-resultat-ID: 1245358
Sist endret: 1. juni 2015, 08:04
NVI-rapporteringsår: 2015
Resultat
Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
2015

Understanding Collaborative Challenges in IT Security Preparedness Exercises

Bidragsytere:
  • Maria Bartnes Line og
  • Nils Brede Moe

Bok

ICT Systems Security and Privacy Protection : 30th IFIP TC 11 International Conference, SEC 2015, Hamburg, Germany, May 26-28, 2015, Proceedings
ISBN:
  • 978-3-319-18466-1

Utgiver

Springer
NVI-nivå 1

Serie

IFIP Advances in Information and Communication Technology
ISSN 1868-4238
e-ISSN 1868-422X
NVI-nivå 1

Om resultatet

Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
Publiseringsår: 2015
Volum: 455
Hefte: .
Sider: 311 - 324
ISBN:
  • 978-3-319-18466-1

Importkilder

Scopus-ID: 2-s2.0-84942626447

Klassifisering

Fagfelt (NPI)

Fagfelt: IKT
- Fagområde: Realfag og teknologi

Beskrivelse Beskrivelse

Tittel

Understanding Collaborative Challenges in IT Security Preparedness Exercises

Sammendrag

IT security preparedness exercises allow for practical collaborative training, which in turn leads to improved response capabilities to information security incidents for an organization. However, such exercises are not commonly performed in the electric power industry. We have observed a tabletop exercise as performed by three organizations with the aim of understanding challenges of performing such exercises. We argue that challenges met during exercises could affect the response process during a real incident as well, and by improving the exercises the response capabilities would be strengthened accordingly. We found that the response team must be carefully selected to include the right competences and all parties that would be involved in a real incident response process, such as technical, managerial, and business responsible. Further, the main goal of the exercise needs to be well understood among the whole team and the facilitator needs to ensure a certain time pressure to increase the value of the exercise, and both the exercise and existing procedures need to be reviewed. Finally, there are many ways to conduct preparedness exercises. Therefore, organizations need to both optimize current exercise practices and experiment with new ones.

Bidragsytere

Maria Bartnes

Bidragsyterens navn vises på dette resultatet som Maria Bartnes Line
  • Tilknyttet:
    Forfatter
    ved Institutt for informasjonssikkerhet og kommunikasjonsteknologi ved Norges teknisk-naturvitenskapelige universitet
  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS

Nils Brede Moe

  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS
1 - 2 av 2

Resultatet er en del av Resultatet er en del av

1 - 1 av 1