RT for Incident Response (RTIR)



Similar documents
Request Tracker for Incident Response (RTIR)

RT and RT for Incident Response

RT and RT for Incident Response

Designing and Developing an Application for Incident Response Teams

Copyright Soleran, Inc. esalestrack On-Demand CRM. Trademarks and all rights reserved. esalestrack is a Soleran product Privacy Statement

RTIR incident handling work-flow

OTRS: Issue Management System Meets Workflow of Security Team Pavel Kácha, 2007 CESNET, z. s. p. o.

IT Support Tracking with Request Tracker (RT)

Comindware Tracker. Reviewer s Guide Comindware Inc.

PNMsoft Sequence Ticketing Solution (PSTS)

BOOTSTRAPPING YOUR INFORMATION SECURITY PROGRAM. Brian

Incident Informa.on Exchange in Darknet Monitoring System dra9- suzuki- mile- darknet- 00

Add Approval Workflow

User and Customer Interviews How XSOL has assisted ERP implementations. Survey

How to Build a Service Management Hub for Digital Service Innovation

Written by: Johan Strand, Reviewed by: Chafic Nassif, Date: Getting an ipath server running on Linux

The problem with privileged users: What you don t know can hurt you

FULLY MANAGED SERVICE COMPLETE SUPPORT FOR YOUR MOBILE ENTERPRISE

everything HelpDesk [Ease of Use] [100% Web Help Desk] [Business Process Automation] [World Class Customer Service]

Add Feedback Workflow

WRS CLIENT CASE STUDIES

Meanings of different Social Services meetings

How to measure your business resiliency

How Freshservice helped Moneycorp streamline their IT Support

The MANTIS Framework Cyber-Threat Intelligence Mgmt. for CERTs Siemens AG All rights reserved

Looking back on how desktop support has evolved, it s interesting to see how tools

quality hosting solution. we manage your hosting. so that you can manage your business.

PCI DSS Compliance: The Importance of Privileged Management. Marco Zhang

Business Continuity Planning

How to Define SIEM Strategy, Management and Success in the Enterprise

Why Companies are Integrating DAM & Online Proofing

UW Connect Update & Incident Management Overview

Software Development Lifecycle. Steve Macbeth Group Program Manager Search Technology Center Microsoft Research Asia

Kayako 4.0 Helpdesk Upgrade Questionnaire Form 1: Users.

How to Exercise a Business Continuity Plan (BCP)

Beta UX DistributionMaster

Re-thinking IT End User Support A simple, clear and compelling End User support strategy for the future

SQL Azure and SqlBulkCopy

4. Exercise: Developing CERT Infrastructure 4.1 GENERAL DESCRIPTION 4.2 EXERCISE COURSE. 4.3 Introduction to the exercise. CERT Exercises Handbook

AUDIT OF INFORMATION TECHNOLOGY Management (Action Plan) Responses February 2005 # PRIORITY DESCRIPTION MANAGEMENT RESPONSE

Seven Things To Consider When Evaluating Privileged Account Security Solutions

Coverity White Paper. Effective Management of Static Analysis Vulnerabilities and Defects

Managing Agile Projects in TestTrack GUIDE

Manual. Ticket Center Manual. Ticket Center 2: May 17, AdNovum Informatik AG. Released. AdNovum Informatik AG. All rights reserved.

SES / CIF. Internet2 Combined Industry and Research Constituency Meeting April 24, 2012

Data Wrangling: The Elephant in the Room of Big Data. Norman Paton University of Manchester

Momentum offers you free training, webinars and much more to: help you understand the power of your current LANDESK products

A How-to Guide By: Riaan Van Der Merwe, General Manager, Dynamics, Neudesic

MANAGEMENT SYSTEM BASED ON OPEN SOURCE TOOLS

Best Practices for Java Projects Horst Rechner

Implementing HIPAA into a Compliance Program

Free Software Configuration Management (SCM) Is it worth it?

Kangas Cybersecurity strategy

A Process is Not Just a Flowchart (or a BPMN model)

The Challenge. Key Challenges at CG Power Systems (Ireland) When Stephen McSharry (Engineering Manager), took over the responsibility

Real world experiences for CMDB Success

Business Continuity Policy and Business Continuity Management System

Operational Lessons from the RSA/EMC CIRC: People, Process, & Threat Intel

By default, the Dashboard Search Lists show tickets in all statuses except Closed.

HTML5 Data Visualization and Manipulation Tool Colorado School of Mines Field Session Summer 2013

A White Paper from AccessData Group. Cerberus. Malware Triage and Analysis

DATATRAK Customer Case Study

Workflow/Business Process Management

Graduating CRM Beyond Pipeline Management CRM

How To Use Open Source Software For Library Work

Zoho Projects. Social collaborative project management platform

T-MOBILE USES SOCIAL MEDIA ANALYTICS TO BOOST EFFICIENCY

WORKPLACE SAFETY AND INSURANCE APPEALS TRIBUNAL

SaaS project development PERSIA, THE APPLICATION FOR RECRUITMENT PROCESSES AUTOMATION.

Transcription:

RT for Incident Response (RTIR) Andy Bone JANET-CERT Manager

What is RTIR A tool for incident handling Currently in Beta

Why Change History Increasing volume of incidents Requirement for multiple person triage System struggling to cope Need to increase resilience (BCP) Increase automation

JANET-CERT was using Remedy-ARS / IMAP based tool Unmaintained Designed for small team and smaller friendlier internet Required manual interaction for each incoming message New development would have been costly Limited platform support History Little built in workflow or integration with external tools Hard for multiple staff to work in parallel on the same incident

History What we wanted to do Allow JANET-CERT staff to manage increasing workload effectively Provide a base for other IR teams to build new tools Be easily extensible as new services need to be provided Save money

History How did we start Began by mapping workflow (through triage) Define requirements >

Define Requirements The buzz words Usable Cross platform Open-source Maintainable using current team skills Extensible using current team skills Securable Supported

History How did we start Began by mapping workflow (through triage) Define requirements > Evaluate current IHS solutions Request Tracker chosen >>

Request Tracker Chosen Why Request Tracker Designed to track issues It doesn t really care what sort What s it used for Bug tracking, helpdesk, customer service, abuse, network operations, sales lead tracking, to do lists. RT was close, but didn t have everything we needed

RT

RT

History How did we start Began by mapping workflow (through triage) Define requirements > Evaluate current IHS solutions Request Tracker chosen >> Extra development and support required >>>

New development What we wanted extra IRT specific workflows clicky data extraction and tracking whois integration >

whois

whois

New development What we wanted extra IRT specific workflows clicky data extraction and tracking whois integration > separate threads for each conversation convenient searching simple scriptable actions new reporting functionality tied into our new SLA requirement

History How did we start Began by mapping workflow (through triage) Define requirements > Evaluate current IHS solutions Request Tracker chosen >> Extra development and support required >>> Agree Statement of Work with Best Practical Work commenced Nov 2002 expected completion June 2003.

Home page

RTIR Structure Incident Reports Someone has a problem of some kind

Incident Reports

Incident Reports

RTIR Structure Incident Reports Someone has a problem of some kind Investigations IRT attempts to get to the root of the problem

Investigations

Investigations

RTIR Structure Incident Reports Someone has a problem of some kind Investigations IRT attempts to get to the root of the problem Blocks Track network level intervention against threat

Blocks

RTIR Structure Incident Reports Someone has a problem of some kind Investigations Blocks IRT attempts to get to the root of the problem Track network level intervention against threat Incidents Ties it all together. May have many related incident reports, investigations and blocks

Incidents

Incidents

Incidents

Incidents

The future Cross-IRT integration IODEF? RT-native integration Cross-tool integration PGP signing/validation Automatically create new incident reports for phenomena detected, but not if RT already knows about it. Auto-categorization of incoming incident reports? Other team implementations

Finding out more rtir-request@lists.bestpractical.com Closed list for incident response team staff http://www.bestpractical.com http:/www.bestpractical.com/pub/rt/release/rtir.tgz sales@bestpractical.com

Questions