Binomial Logo
Disaster Recovery Planning (DRP)
Business Continuity Planning (BCP)
Binomial International
Fire Image
HOME Phoenix Software Seminars Consulting Resources Newsletter Bookstore Contact Us
[Home] [Catalog] [Category] [Previous Item] [Next Item] [Checkout] [Review Cart] [Button]

The Binomial Bookstore

Rothstein Associates Inc.

Info & Network Security, Info Protection

When Hackers Attack (Video on CD) [Item Image]
Qty:
... Incident Response Planning and Forensics.
2005, Video on CD. Also available on VHS
(BN701VHS, $255.00). Special Order Item.
BN701CD
$350.00
WHEN HACKERS ATTACK!
INCIDENT RESPONSE PLANNING AND FORENSICS
Video on CD or VHS
by WatchIT

- “How can we create our own computer incident response team and a response plan
specific to our organization?
- What are the proper phases of incident response?
- How can our organization can learn to respond to incidents in a manner that minimizes
network downtime, protects critical information and the safety of our employees, and
produces consistent, professional results for our organization?
- What is the importance of incident response planning?”

- - - - - - -
“Cliff Riggs, senior member of the Technical Staff at Hill Associates, discusses in detail the
practices and procedures involved in incident response planning and forensics. In an
interview, Hugh Pierce, owner and principal of Forensec, a Vermont-based forensics firm
specializing in computer crimes, explains how to handle evidence of such crimes. According
to Riggs, a security incident can be either a controlled situation or a slowly spiraling disaster.
The difference between the two is the planning that occurs prior to the first incident. In the
program, Riggs outlines the need for creating an incident response plan. He then lists and
describes the required equipment and documentation aids to use when creating an incident
response plan. The program also thoroughly details the phases associated with the plan, and
offers some training resources to investigate when creating your company’s incident
response team. By watching this program you will learn:
- Why it is necessary for your organization to have a formal incident response plan of
action;
- How to create your own computer incident response team and a response plan specific to
your organization; and
- The specific phases involved in incident response so that your organization can learn to
respond to incidents in a manner that minimizes network downtime, protects critical
information and the safety of your employees, and produces consistent, professional results
for your organization.

“For viewers of the CD version, this program provides a selection of Web links that includes
articles such as ‘Building a Computer Incident Response Team,’ from Computerworld, and
‘Steps for Recovering from a UNIX or NT System Compromise,’ from CERT, which discuss
proactive steps organizations can take to prepare themselves for a computer attack, and
actions to take when such attacks do occur. The program also includes white papers, such
as ‘The Essentials of Computer Discovery,’ from Computer Forensics, Inc.™, that explore
issues surrounding computer forensics and digital evidence collection.”

- - - - - - -

PROGRAM TOPICS

INTRODUCTION
AGENDA
THE NEED FOR AN INCIDENT RESPONSE PLAN
Network Security Mechanisms
Undesirable Effects of Security Incidents
Responding to Security Incidents
Hugh Pierce: Information Security Drivers
INFORMATION SECURITY EQUIPMENT AND DOCUMENTATION AIDS
The Incident Response Tool Kit
The Incident Response Tool Kit: Hardware
The Incident Response Tool Kit: Software
The Incident Response Tool Kit: Documentation Aids
Incident Response Planning Costs
CREATING THE CIRT AND PUTTING IT TO WORK
Phases of Incident Response
Phases of Incident Response: Planning - Create the Incident Response Team
Hugh Pierce: The Incident Response Team
Phases of Incident Response: Planning - Where the CIRT Fits Into the Organization
Phases of Incident Response: Planning - Creating the Incident Response Plan
Creating the Incident Response Plan: Prioritizing System Resources
Creating the Incident Response Plan: Threat Level Guidelines
Creating the Incident Response Plan: Threat Response Options
Phases of Incident Response: Prevention
Phases of Incident Response: Evaluation
Phases of Incident Response: Containment
Hugh Pierce: Initial Incident Response
Phases of Incident Response: Investigation
Hugh Pierce: Points to Consider When Collecting Evidence
Phases of Incident Response: Investigation - Record All Chain of Custody Information
Phases of Incident Response: Eradication
Phases of Incident Response: Recovery
Phases of Incident Response: Post-Mortem Analysis
TRAINING RESOURCES FOR THE INCIDENT RESPONSE TEAM
Incident Response Training: InfraGard
Incident Response Training: Carnegie Mellon Software Engineering Institute
Incident Response Training: FIRST
Hugh Pierce: Training the Incident Response Team
CONCLUDING THOUGHTS
Hugh Pierce: Final Thoughts on Incident Response

- - - - - - -

ABOUT THE PRESENTER

“CLIFF RIGGS is a senior member of the technical staff at Hill Associates, a position that
allows him to blend his aptitude for technology with his love of teaching by providing training
services to telecommunications companies. Mr. Riggs is also the founder of Proteris, a
private consulting company that provides security services and network design expertise. He
entered the technology sector by working as a private consultant and a field technician for an
AT&T subcontractor. Mr. Riggs began his professional career as a high school teacher, and
still holds a level two teaching certificate in the state of Vermont. He has both CCIE and
CISSP certifications, and has authored two books on network design and information
security. His interests include weightlifting, Tai Chi, mycology, physics and philosophy.”

- - - - - - -

ABOUT THE INTERVIEWEE

“HUGH PIERCE is principal of ForenSec, Ltd., which offers digital forensics and consulting
services for litigation and corporate investigations, and chief technology officer of Stutzman
Pierce, Inc. Previously, he worked as a staff scientist at a national engineering firm, where he
performed information security architecture and implementation for both internal and external
customers. Mr. Riggs was also the leader of the corporate Information Security Business
Council, where he coordinated physical and information security capabilities. He is a
recognized leader in Microsoft Windows forensics and investigations, serving as a
contributing editor for SANS Securing Windows guides for NT and 2000, a member of the
Center for Internet Security (CIS) Benchmark Development team, and an officer for the
Vermont Infragard. Mr. Pierce is a graduate of Dalhousie University, Halifax, Nova Scotia.”

- - - - - - -
2005, Video, 38 minutes.
Order #DR701-CD (on CD)
Order #DR701-VHS (on VHS)
SPECIAL ORDER ITEM.
- - - - - - -
[Home] [Catalog] [Category] [Previous Item] [Next Item] [Checkout] [Review Cart] [Button]

Rothstein Associates Inc.

4 Arapaho Rd.
Brookfield, CT 06804-3104
1-888-ROTHSTEin
Telephone: 203.740.7444; 888.768.4783
Fax: 203.740.7401
E-Mail: info@rothstein.com
All bookstore enquiries should be sent to Rothstein Associates at the above address.

Looking for Practical Knowledge?