Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incident response guide should reference forensics documentation #1884

Open
pburkholder opened this issue Mar 4, 2021 · 0 comments
Open
Labels
compliance Compliance, security, and accessibility issues

Comments

@pburkholder
Copy link
Contributor

Recent Emergency Directives have this caveat regarding Expertise (https://cyber.dhs.gov/ed/21-01/#what-does-the-directive-mean-by-expertise)

By “expertise”, we mean that you have staff or supporting personnel that are properly trained in taking a forensic image of system memory and have tooling readily-available to immediately do so.

We need better documentation on the tooling we use, and how to become proficient with those tools should be part of our on-boarding.

Security considerations

Enhancement

@pburkholder pburkholder added the compliance Compliance, security, and accessibility issues label Mar 4, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
compliance Compliance, security, and accessibility issues
Projects
None yet
Development

No branches or pull requests

1 participant