Chapter 8. Resources

We’re going to go out on a limb and state, categorically, that no incident response team can be truly effective if it isolates itself from the rest of the world. There is an extensive community of incident response teams out there willing to share their experiences with one another for the benefit of the entire community. In much the same way that the medical community shares information on how to treat various medical ailments, the incident response technical community is relatively open and forthcoming in sharing the technical details of each team’s experiences. Practically every team guards the identity of the affected sites -- much like how the medical community guards the privacy of patients -- but the details concerning the nature of the attack, its symptoms, and its cures are freely exchanged.

This chapter is intended to provide the reader with a solid collection of Internet sites where such information is available. The list is by no means complete, but a series of good starting points for readers to go for additional information.

Security Information on the Web

This section presents some of the more useful and informative web sites on the Internet. Most of the sites in this list offer a wide range of security information, and should typically be on any incident response team’s daily reading list in order to keep up to date with topical security issues. Note that you are likely to find some overlap of information among the sites in this list. Unfortunately, ...

Get Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.