Chapter 15. Incident Management with ESM

 

“Gettin’ good players is easy. Gettin’ ’em to play together is the hard part.”

 
 --Casey Stengel

Incident Management Basics

In 2005, I conducted a webcast for the SANS Institute (SysAdmin, Audit, Network, Security) on incident management with a gentleman by the name of Matthew Klunder, a senior consultant with a big four consultancy firm. Together we explored the makeup of a strong incident management program and received some excellent feedback from SANS listeners. Since the webcast was tightly associated with ESM capabilities for incident management, I decided to build this chapter on the framework we used, and to include the details we garnered from listener feedback. This chapter will help summarize the ...

Get Enemy at the Water Cooler now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.