In the early years of computer security, all the attention was focuses on preventing incidents from happening. However, no matter how much effort an organization puts into implementing preventive security controls, cyber incidents will happen. A prominent initiative to establish cyber readiness was the establishment of the first CERT (Computer Emergency Response Team) in 1988 in response to the Morris worm incident which affected network servers in research institutions mainly in the US. In those days, business processes were not online and were therefore not affected by the Morris worm. In today’s world where everything is online, business processes are easily disrupted by cyber incidents. And when organizations experience a cyber incident, they cannot expect that a CERT will come to the rescue. They are on their own, to a large extent. To be prepared, every organization must have a plan and a certain capacity for handling cyber incidents.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cybersecurity Readiness, Security Testing and Audit

  • Audun Jøsang

摘要

In the early years of computer security, all the attention was focuses on preventing incidents from happening. However, no matter how much effort an organization puts into implementing preventive security controls, cyber incidents will happen. A prominent initiative to establish cyber readiness was the establishment of the first CERT (Computer Emergency Response Team) in 1988 in response to the Morris worm incident which affected network servers in research institutions mainly in the US. In those days, business processes were not online and were therefore not affected by the Morris worm. In today’s world where everything is online, business processes are easily disrupted by cyber incidents. And when organizations experience a cyber incident, they cannot expect that a CERT will come to the rescue. They are on their own, to a large extent. To be prepared, every organization must have a plan and a certain capacity for handling cyber incidents.