<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Trehb101.com - Got Geek? &#187; Computer Incident Response Team</title>
	<atom:link href="http://www.trehb101.com/index.php/tag/computer-incident-response-team/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.trehb101.com</link>
	<description>Information Systems Management &#38; Security, eBusiness, Internet, Life</description>
	<lastBuildDate>Wed, 18 Aug 2010 21:21:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – The Responsibilities of CIRT aka Computer Incident Response Team</title>
		<link>http://www.trehb101.com/index.php/2009/11/30/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-the-responsibilities-of-cirt-aka-computer-incident-response-team/</link>
		<comments>http://www.trehb101.com/index.php/2009/11/30/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-the-responsibilities-of-cirt-aka-computer-incident-response-team/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 17:51:02 +0000</pubDate>
		<dc:creator>TheDon</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Systems]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[CIRT]]></category>
		<category><![CDATA[CISSP Exam]]></category>
		<category><![CDATA[CISSP Review]]></category>
		<category><![CDATA[computer incident]]></category>
		<category><![CDATA[Computer Incident Response Team]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[emergency response]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[notes]]></category>
		<category><![CDATA[response team]]></category>
		<category><![CDATA[security incidents]]></category>

		<guid isPermaLink="false">http://www.trehb101.com/?p=196</guid>
		<description><![CDATA[CIRT (Computer Incident Response Team) is also commonly called CERT (Computer Emergency Response Team) - they are personnel responsible for coordinating the response to computer security incidents in an organization]]></description>
			<content:encoded><![CDATA[<p><strong>What is CIRT?</strong></p>
<p>CIRT (Computer Incident Response Team) is also commonly called CERT (Computer Emergency Response Team) &#8211; they are personnel responsible for coordinating the response to computer security incidents in an organization (Source: <span><a href="http://www.google.com/url?q=http://www.net.ttu.edu/security/policy_definitions.doc&amp;ei=ewQUS8n1EYmqtgPjsOXmAQ&amp;sa=X&amp;oi=define&amp;ct=&amp;cd=1&amp;ved=0CA4QpAMoAQ&amp;usg=AFQjCNF2nzSRWCJeVueQ-XX-x242AlF2kQ" onclick="pageTracker._trackPageview('/outgoing/www.google.com/url?q=http_//www.net.ttu.edu/security/policy_definitions.doc_amp_ei=ewQUS8n1EYmqtgPjsOXmAQ_amp_sa=X_amp_oi=define_amp_ct=_amp_cd=1_amp_ved=0CA4QpAMoAQ_amp_usg=AFQjCNF2nzSRWCJeVueQ-XX-x242AlF2kQ&amp;referer=');"><span style="color: #008000;">www.net.ttu.edu/security/policy_definitions.doc</span></a>)<span id="more-196"></span></span></p>
<p><span>Responsibilities include:</span></p>
<ul>
<li>Manage the company’s response to events that       pose a risk</li>
<li>Coordinating information</li>
<li>Mitigating risk, minimize interruptions</li>
<li>Assembling technical response teams</li>
<li>Management of logs</li>
<li>Management of resolution</li>
</ul>
<p><!--Start CISSP ebook ad--></p>
<table border="0" width="100%">
<tbody>
<tr>
<td bgcolor="#ffcc99">
<h1 style="text-align: center;"><strong>Planning to take the CISSP Exam? </strong></h1>
<h2><strong>Get a copy of my personal notes (300plus pages worth) that I used to pass the exam for only <span class="style1">$25.00</span>.</strong></h2>
<div><strong> </strong></p>
<div class="wp-caption alignleft" style="width: 110px"><strong><strong><a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/"><img title="CISSP Exam Review Notes" src="http://www.trehb101.com/images/entries/CISSP-Review-Notes-PACK-small.png" alt="Click the Add To Cart Button to Purchase" width="100" height="192" /></a></strong></strong><p class="wp-caption-text">Click the Add To Cart Button to Purchase</p></div>
<p><strong>Plus you will also get copies of notes from other CISSPs. </strong></p>
<p><strong>Learn more about this package by visiting this blog entry: <a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/">CISSP REVIEW NOTES I USED TO PASS THE  EXAM. </a></strong></div>
<p style="text-align: center;" align="center"><strong>CLICK BELOW TO MAKE YOUR PURCHASE NOW. </strong></p>
<p style="text-align: center;" align="center"><strong><object><form method="post"  action=""  style="display:inline" onsubmit="return ReadForm(this, true);"><input type="submit" value="Add to Cart" /><input type="hidden" name="product" value="CISSP Review Notes Package" /><input type="hidden" name="price" value="25.00" /><input type="hidden" name="product_tmp" value="CISSP Review Notes Package" /><input type="hidden" name="addcart" value="1" /></form></object></strong></p>
<p style="text-align: center;" align="center">All Purchases are securely processed through Paypal. Once you click the button please check your shopping cart at the upper right hand side of the page to complete your order.</p>
<p style="text-align: center;" align="center"><strong>IMPORTANT NOTICE: </strong></p>
<p style="text-align: center;" align="center">I  MANUALLY REVIEW ALL ORDERS. SO ONCE YOU PURCHASE THE PRODUCT, THERE  WILL BE SOME DELAY ON YOU RECIEVING AN E-MAIL FROM ME WITH THE LINK TO  THE DOWNLOAD AREA OF THE PRODUCT. YOU WILL GET A RESPONSE FROM ME  WITHIN 24-48 HOURS.</p>
</td>
</tr>
</tbody>
</table>
<p><!--End CISSP ebook ad--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.trehb101.com/index.php/2009/11/30/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-the-responsibilities-of-cirt-aka-computer-incident-response-team/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP Exam Note (Domain 2: Telecommunications and Networking Security) &#8211; Remote Access Security Management</title>
		<link>http://www.trehb101.com/index.php/2009/11/24/cissp-exam-note-domain-2-telecommunications-and-networking-security-remote-access-security-management/</link>
		<comments>http://www.trehb101.com/index.php/2009/11/24/cissp-exam-note-domain-2-telecommunications-and-networking-security-remote-access-security-management/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 18:53:12 +0000</pubDate>
		<dc:creator>TheDon</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Systems]]></category>
		<category><![CDATA[Availability]]></category>
		<category><![CDATA[CIRT]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[Computer Incident Response Team]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[RADIUS]]></category>
		<category><![CDATA[remote access]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[TACACS]]></category>

		<guid isPermaLink="false">http://www.trehb101.com/?p=171</guid>
		<description><![CDATA[Remote Access Security Management focuses in the creation of:

    * Host and networked based monitoring
    * Event notification
    * CIRT – Computer Incident Response Team
          o CIRT Performs
                + Analysis of event
                + Response to incident
                + Escalation path procedures
                + Resolution – post implementation follow-up
]]></description>
			<content:encoded><![CDATA[<p><strong>Key Concepts:</strong></p>
<ul>
<li><strong>Confidentiality – </strong>no disclosure of data</li>
<li><strong>Integrity </strong>– no alteration of data</li>
<li><strong>Availability – </strong>no destruction of data</li>
</ul>
<p><strong>Common Remote Connections</strong></p>
<ul>
<li>xDSL – Digital Subscriber Line</li>
<li>Cable Modem</li>
<li>Wireless</li>
<li>ISDN – Integrated Services Digital Network</li>
</ul>
<p><strong>Common Tools in Securing External Remote Connections</strong></p>
<ul>
<li>VPN – Virtual Private Network</li>
<li>SSL – Secure Socket Layer</li>
<li>SSH – Secure Shell<span id="more-171"></span></li>
</ul>
<p><strong>Technologies for</strong> <strong>Remote Access Authentication</strong></p>
<ul>
<li>RADIUS –  <strong>Remote Authentication Dial In User Service</strong> &#8211; is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service. RADIUS was developed by Livingston Enterprises, Inc., in 1991 as an access server authentication and accounting protocol and later brought into the IETF standards. (Source: <a href="http://en.wikipedia.org/wiki/RADIUS" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/RADIUS?referer=');">http://en.wikipedia.org/wiki/RADIUS</a>)</li>
<li>TACACS – <strong>Terminal Access Controller Access-Control System -</strong> is a remote authentication protocol that is used to communicate with an authentication server commonly used in UNIX networks. TACACS allows a remote access server to communicate with an authentication server in order to determine if the user has access to the network. (Source: <a href="http://en.wikipedia.org/wiki/TACACS" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/TACACS?referer=');">http://en.wikipedia.org/wiki/TACACS</a>)</li>
</ul>
<p><!--Start CISSP ebook ad--></p>
<table border="0" width="100%">
<tbody>
<tr>
<td bgcolor="#ffcc99">
<h1 style="text-align: center;"><strong>Planning to take the CISSP Exam? </strong></h1>
<h2><strong>Get a copy of my personal notes (300plus pages worth) that I used to pass the exam for only <span class="style1">$25.00</span>.</strong></h2>
<div><strong> </strong></p>
<div class="wp-caption alignleft" style="width: 110px"><strong><strong><a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/"><img title="CISSP Exam Review Notes" src="http://www.trehb101.com/images/entries/CISSP-Review-Notes-PACK-small.png" alt="Click the Add To Cart Button to Purchase" width="100" height="192" /></a></strong></strong><p class="wp-caption-text">Click the Add To Cart Button to Purchase</p></div>
<p><strong>Plus you will also get copies of notes from other CISSPs. </strong></p>
<p><strong>Learn more about this package by visiting this blog entry: <a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/">CISSP REVIEW NOTES I USED TO PASS THE  EXAM. </a></strong></div>
<p style="text-align: center;" align="center"><strong>CLICK BELOW TO MAKE YOUR PURCHASE NOW. </strong></p>
<p style="text-align: center;" align="center"><strong><object><form method="post"  action=""  style="display:inline" onsubmit="return ReadForm(this, true);"><input type="submit" value="Add to Cart" /><input type="hidden" name="product" value="CISSP Review Notes Package" /><input type="hidden" name="price" value="25.00" /><input type="hidden" name="product_tmp" value="CISSP Review Notes Package" /><input type="hidden" name="addcart" value="1" /></form></object></strong></p>
<p style="text-align: center;" align="center">All Purchases are securely processed through Paypal. Once you click the button please check your shopping cart at the upper right hand side of the page to complete your order.</p>
<p style="text-align: center;" align="center"><strong>IMPORTANT NOTICE: </strong></p>
<p style="text-align: center;" align="center">I  MANUALLY REVIEW ALL ORDERS. SO ONCE YOU PURCHASE THE PRODUCT, THERE  WILL BE SOME DELAY ON YOU RECIEVING AN E-MAIL FROM ME WITH THE LINK TO  THE DOWNLOAD AREA OF THE PRODUCT. YOU WILL GET A RESPONSE FROM ME  WITHIN 24-48 HOURS.</p>
</td>
</tr>
</tbody>
</table>
<p><!--End CISSP ebook ad--></p>
<p><strong>Types Remote Node Authentication</strong></p>
<ul>
<li>PAP – Password Authentication Protocol – clear      text</li>
<li>CHAP – Challenge Handshake Authentication      Protocol – protects password</li>
</ul>
<p><strong>Remote User Management</strong></p>
<ul>
<li>Justification of remote access</li>
<li>Support issues</li>
<li>Hardware &amp; software distribution</li>
</ul>
<p><strong>Intrusion Detection Process<br />
</strong></p>
<ul>
<li>Notification</li>
<li>Remediation</li>
</ul>
<p><strong>Remote Access Security Management focuses in the creation of:</strong></p>
<ul>
<li>Host and networked based monitoring</li>
<li>Event notification</li>
<li>CIRT – Computer Incident Response Team
<ul>
<li>CIRT Performs
<ul>
<li>Analysis of event</li>
<li>Response to incident</li>
<li>Escalation path procedures</li>
<li>Resolution – post implementation follow-up</li>
</ul>
</li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.trehb101.com/index.php/2009/11/24/cissp-exam-note-domain-2-telecommunications-and-networking-security-remote-access-security-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
