OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: Incident investigation methodologies

From: Harlan Carvey (keydet89yahoo.com)
Date: Mon Jun 07 2004 - 12:51:25 CDT


Steven,
 
> In the real world, production systems need to go
> back into production ASAP.

This is exactly my point. In fact, I'm taking it a
step further...that production systems cannot be taken
down w/o proper justificaition to do so.
 
> Frontline support staff simply do not have the time
> or resource
> (or often even the knowledge) to conduct lengthy
> forensic investigations.

Exactly, particularly to the knowledge part of your
comment.
 
> Time = Money, that's a cold, hard fact, and there
> simply isn't any way around it.

Agreed. This is one of my reasons for starting this
thread.