Title: Guidelines for Evidence Collection and Archiving
Author(s): D. Brezinski, T. Killalea.
Status: BEST CURRENT PRACTICE
Date: Feb 2002
Length: 18468
A "security incident" as defined in the "Internet Security Glossary", RFC2828, is a security-relevant system event in which the system's security policy is disobeyed or otherwise breached. The purpose of this document is to provide System Administrators with guidelines on the collection and archiving of evidence relevant to such a security incident.
If evidence collection is done correctly, it is much more useful in apprehending the attacker, and stands a much greater chance of being admissible in the event of a prosecution.
|
|
|