Handout-AC475

advertisement
Firewall Management, Intrusion Detection, Intrusion Prevention and
Security Information Management
AC475 Team Project:
Katherine Jackowski
Elizabeth Kearney-Lang
Daureen Lingley-Chor
IPDS – IPS – Intrusion Prevention System – performing intrusion detection and attempting to stop
detected possible incidents (false positive, false negative). IDS – monitoring the events occurring in a
computer system or network and analyzing them for signs of possible violations or imminent threats of
violation of computer security policies, acceptable use policies, or standard security practices. IPDS
systems are primarily focused on identifying possible incidents, logging information about them,
attempting to stop them, and reporting them to the security administrators.
Sources:
Campbell, P. L. (2003, September). An Introduction to Information Control Models. Albuquerque, New
Mexico, United States of America.
COBIT 4.1. (2007). Rolling Meadows, Illinois, United States of America: IT Governance Institute.
Firewall Operations Management, Auditing and Compliance. (2011, February). Retrieved April 2011,
from Tufin Secure Track Web site: http://www.tufin.com
IIA. (2011). Global Technology Audit Guide. Retrieved February 13, 2011, from The Institute of Internal
Auditors: www.theiia.org
ISACA. (2005). Critical Elements of Information Security Program Success. Rolling Meadows, Illinois,
United States of America.
ISACA. (2010). IT Standards, Guidelines,and Tools and Techniques for Audit and Assurance and
Control Professionals. Rolling Meadows.
Scarfone, K., & Hoffman, P. (2009, September). National Institute of Standards and Technology
Guidelines on Firewalls and Firewall Policy SP800-41 Revision1. Gaithersburg, Maryland, United States
of America.
Scarfone, K., & Mell, P. (2007, February). National Institute of Standards and Technology Guide to
Intrusion Detection and Prevention Systems (IPDS) SP 800-94. Gaithersburg, Maryland, United States of
America.
Scarfone, K., Grance, T., & Masone, K. (2008, March). Computer Security Incident Handling Guide
NIST SP 800-61 Revision 1. Gaithersburg, Maryland, United States of America.
Skybox Security, Inc. (2010, May). Retrieved April 2011, from Skybox Security Web Site:
http://www.skyboxsecurity.com
Download