Comparing compromises (VerIS Metric Framework)*

March 1st, 2010 admin

My friend Alex Hutton and the rest of the RISK Team at Verizon Business have done it again! This time rather than release a report about breaches however, they’ve release the Verizon Incident Sharing Metrics Framework ( VerIS for short ).    All the awesomeness that went into creating the 2009 Verizon Breach Report is being shared with the incident response community so that we can compare apples to apples when it comes to compromises.  Rather than each company capturing it’s own unique dataset and creating statistics in their own particular way, VerIS is a framework that allows companies …


Originally posted on McKeay

 
  Related Posts
Verizon Incident Sharing Framework
Verizon Incident Sharing Framework
Earlier this month Verizon Business announced their Verizon Incident Sharing Framework (VerIS framework). This document is a means to describe digital security incidents, using four main groupings: 1. Demographics, 2. Incident Classification, 3. Discovery and Mitigation, and 4. Impact Classification. The idea is to provide a framework that incident... 
Dell Needs a PSIRT
Dell Needs a PSIRT
It’s clear to me that Dell needs a Product Security Incident Response Team, or PSIRT . Their response to the malware shipping with R410 replacement motherboards is not what I would like to see from a company of their size and stature. Take a look at this Dell Community thread to see what I mean. It’s almost comical. These are a few... 
Mandiant M-Trends on APT
Mandiant M-Trends on APT
If you want to read a concise yet informative and clue-backed report on advanced persistent threat , I recommend completing this form to receive the first Mandiant M-Trends report. Mandiant occupies a unique position with respect to this problem because they are one of only two security service companies with substantial counter-APT consulting... 
Hackers Targeted Oil Companies for Oil-Location Data
Hackers Targeted Oil Companies for Oil-Location Data
Three U.S. oil companies were targeted in a coordinated hack that sought valuable information about new discoveries of oil deposits and other data, according to a new report in the Christian Science Monitor . The attacks predated by two years recent intrusions into Google and other companies but shared some similarities to those attacks. Highly... 
Why Would APT Exploit Adobe?
Why Would APT Exploit Adobe?
After reading this statement from Adobe , they seem to be using the same language that described the Google v China incident: Adobe became aware on January 2, 2010 of a computer security incident involving a sophisticated, coordinated attack against corporate network systems managed by Adobe and other companies. We are currently in contact with... 
  Related Tweets from Twitter
mckeay (Martin McKeay)  : Just got done hearing a lot of the inside story of the Miraposa Botnet takedown from the folks at Panda. Now to nap before dinner..
Updated : 2010-07-30T22:57:53Z   |  Reply  |  View Tweet
RafalLos (Rafal Los)  : Trying to not get lost in the mass of freak humanity at #Defcon with @ChrisJohnRiley, @Mckeay and other random people I don't know .....
Updated : 2010-07-30T19:40:22Z   |  Reply  |  View Tweet
subdriven (subdriven)  : @mckeay Well, if ConFlu doesn't get you, Denny's probably will..
Updated : 2010-07-30T15:44:12Z   |  Reply  |  View Tweet
mckeay (Martin McKeay)  : @subdriven #Denny's service is much better today. Doesn't taste any better though...
Updated : 2010-07-30T14:56:58Z   |  Reply  |  View Tweet
subdriven (subdriven)  : @mckeay Yeah, last time we went there it was like a 2 hour wait AT THE TABLE! Service sucked! G'luck..
Updated : 2010-07-30T14:49:37Z   |  Reply  |  View Tweet
  Related News from Digg
No comments yet.

Spam Protection by WP-SpamFree

TOP