Showing posts with label Incident Reporting. Show all posts
Showing posts with label Incident Reporting. Show all posts

Advanced Reporting Vulnerability Management



Beyond the reporting discussed so far and related to customization, more advanced reporting capabilities are yet to be fully demonstrated by vendors. We will discuss this in a separate section of this book because, for organizations that have not yet begun to mature their processes, these capabilities may not be immediately needed. However, if you think that your organization will have a firm need for reports in support of process optimization, consider the following basic requirements:
  • The product should be able to allow for customized reporting based on access to raw audit results.
  • Summary tables of audits should be available in an open database structure (schema).
  • Add-on functionality should permit some statistical analysis of vulnerability data.
  • Beyond data analysis, the information should be combined with or readily able to combine with network topology information to assess risk by attack vectors.
These capabilities are more complex and require greater discipline in staffing and process. They directly feed risk management functions as well as security incident management. Products already on the market can combine this information from the major VM vendors and combine it with firewall, intrusion prevention system (IPS), and network equipment products to map and identify threats. Some vendors can even permit you to assess risks at a high level and then drill down into the specific configuration items on host, network, and security elements that can be altered to remediate an impending threat.
Assess your candidate vendor’s compatibility with these advanced products to leave a path for future enhancement. As of this writing, the most advanced of these risk management products are few and expensive but offer great functionality to the technical risk manager.

Sample Crisis Information Capture Reports



The following section provides examples of some crisis information capture reports. The list and report contents offered are not designed to be exhaustive or allinclusive, but to illustrate how information capture and dissemination, as well as response guidelines, can work to complement each other when a company and its employees deal with an emergency situation. Companies should seek to align the questions posed in such reports to their response guidelines, as well as to their unique corporate interests and the particular operating environment in which a business activity or project may be taking place. Questions should be designed to meet three basic needs:
  1. Increase organizational understanding.
  2. Enable effective management decision making.
  3. Provide documented evidence.
The first information capture box is designed so that the issuer captures administrative details such as which region, country, and project the report came from, what restrictions might apply in terms of information sharing, when the incident happened, and any administrative codes or numbers that might be attached to the report. A reference column has been included at the lefthand side of each chart to guide managers through questions they should be asking. A blank column is at the righthand side so that information is succinctly captured with questions and answers on one document. The structure of reports should be simple, consistent, and cognizant of the range of capabilities and experience within the company, in terms of both those providing information and those interpreting the reports.

Serious Incident Reporting


While there is significant value in developing tailored data calls to reflect the wide range of postulated risks a company might face, there is also mileage in having a catchall incident data call which meets the generic needs of those risks which might not have been anticipated; or span multiple areas. Companies should develop a standardized serious incident report (SIR) to document and manage information flow on serious events that occur within a project or region. The report should be completed and released during and following each serious incident, either to capture multiple risk natures or to reflect a gap in company reporting templates. Companies may wish to have staged reports to capture the details of a fluid event requiring initial, interim, and closure reports. All reports must be completed correctly and in sufficient detail, as they may be used for audit or investigation purposes. The company or its subcontracted vendors might have preferences regarding formatting as well as the distribution list—these should be in alignment with the communications plan. An agreement should be reached between the company and external parties to ensure that reports capture all necessary details and are sent only to agreed recipients. Serious incidents might include hostile incidents resulting in injury, death, or major project problems; severe injury or death from natural causes or accidents; serious industrial accidents or evacuations; serious legal or reputational situations; and the loss of a critical of highvalue asset. The following provides a suggested format for a SIR.

Serious Incident Report Incident Management Data Call


It is useful to catalog and distribute measures that have been tried and have either failed or succeeded during a crisis situation in order to avoid duplication and demonstrate efforts being taken to a wider audience, as well as illustrate the degree of focus being paid toward resolving an issue. It also provides a failsafe to ensure that no options are accidently overlooked. A common failing found within response measures is for the crisis management team, either local or corporate, to not mention failed efforts, but rather to focus on successful approaches. This can create further questions and not illustrate the efforts and routes being pursued to resolve an issue. A full reporting of successes and failures is important during a crisis situation—as well as for any postincident investigations. A simple format should be used to track all efforts attempted, such as the example provided here:

Popular Posts