发明名称 INFORMATION TECHNOLOGY INCIDENT RESPONSE AND INVESTIGATION SYSTEM AND METHOD
摘要 <p>A method of responding to an information technology related incident. The method having the steps of receiving a security alert (54), the security ale rt being displayed on an incident response and investigation system (58) for analysis by an administrator; documenting the incident (56) based on information contained in the security alert; opening an investigation file (64) to administratate investigation of the incident; collecting items of electronic evidence and maintaining the evidence in an electronic evidence database associated with the investigation file (66). An incident response a nd investigation system is also disclosed. The system having an incoming securi ty alert administration function for receiving and analyzing security alert, ea ch security alert containing information related to an event (106), the event being related to an information technology policy of an organization; an incident administration function for creating an incident file to document t he event; and an investigation administration function for administering an investigation of the event documented in the incident file (158).</p>
申请公布号 CA2386109(A1) 申请公布日期 2001.04.12
申请号 CA20002386109 申请日期 2000.05.31
申请人 SECURITY AUTOMATION INCORPORATED 发明人 DAUGSTRUP, MICHAEL H.
分类号 G06F21/55;(IPC1-7):G06F13/00 主分类号 G06F21/55
代理机构 代理人
主权项
地址