To main content

Monitoring of Incident Response Management Performance

Abstract

Monitoring the performance of incident response (IR) management is important input for improving the IR management system. A set of performance indicators, which assists monitoring in a proper way, is described regarding: the incident response management system; information security culture; number of incidents responded to; average time spent on responding; consequences of incidents; number of incidents of high loss; downtime of SCADA systems; total costs of incident response; and learning. The entire set of proposed indicators is well suited for monitoring the total incident response management of an organisation as it covers all parts of incident response management.

Category

Academic chapter/article/Conference paper

Language

English

Author(s)

Affiliation

  • SINTEF Digital / Software Engineering, Safety and Security
  • Norwegian University of Science and Technology
  • SINTEF Digital
  • University of Agder

Year

2006

Publisher

German Informatics Society

Book

IT-Incident Management & IT-Forensics - IMF 2006

View this publication at Cristin