ISN Special Publication 800-86 National Institute of Standards and Technology Technology Administration U.S. Department of Commerce Guide to Integrating Forensic Technigues into Incident Response Recommendations of the National Institute of Standards and Technology Karen Kent Suzanne Chevalier Tim Grance Hung Dang Guide to Integrating Forensic Techniques NIST Special Publication 800-86 into Incident Response Recommendations of the National Institute of Standards and Technology Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang COMPUTER SECURITY Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20899-8930 August 2006 U.S.Department of Commerce Carlos M. Gutierrez, Secretary Technology Administration Robert C. Cresanti, Under Secretary of Commerce for Technology National Institute of Standards and Technology William A. Jeffrey, Director GUIDE TO INTEGRATING FORENSIC TECHNIQUES INTO INCIDENT RESPONSE Reports on Computer Systems Technology The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL's responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclassified information in Federal computer systems. This Special Publication 800-series reports on ITL's research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations. National Institute of Standards and Technology Special Publication 800-86 Natl. Inst. Stand. Technol. Spec. Publ. 800-86, 121 pages (August 2006) Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose. := GUIDE TO INTEGRATING FORENSIC TECHNIQUES INTO INCIDENT RESPONSE Acknowledgments The authors, Karen Kent and Tim Grance of the National Institute of Standards and Technology, and Suzanne Chevalier and Hung Dang of Booz Allen Hamilton, wish to thank their colleagues who reviewed drafts of this document and contributed to its technical content. The authors would particularly like to acknowledge Rick Ayers, Wayne Jansen, Peter Mell, and Murugiah Souppaya of NIST, and Adam Feldman, Mike Noblett, and Joseph Nusbaum of Booz Allen Hamilton, for their keen and insightful thanks to security experts Susan Ballou (Office of Law Enforcement Standards), Brian Carrier (Purdue University), Eoghan Casey (Stroz Friedberg, LLC), Duane Crider (Microsoft), Kurt Dillard (Microsoft) Dean Farrington (Wells Fargo Bank), Jessica Reust (Stroz Friedberg, LLC), Marc Rogers (Purdue University), and Miles Tracy (U.S. Federal Reserve System), as well as representatives from the Department of State, for their particularly valuable comments and suggestions. Trademarks All product names are registered trademarks or trademarks of their respective companies. ii GUIDE TO INTEGRATING FORENSIC TECHNIQUES INTO INCIDENT RESPONSE Acknowledgments The authors, Karen Kent and Tim Grance of the National Institute of Standards and Technology, and Suzanne Chevalier and Hung Dang of Booz Allen Hamilton, wish to thank their colleagues who reviewed drafts of this document and contributed to its technical content. The authors would particularly like to acknowledge Rick Ayers,
NIST SP800 86 Guide to Integrating Forensic Techniques into Incident Response SP800 86
文档预览
中文文档
5 页
50 下载
1000 浏览
0 评论
309 收藏
3.0分
温馨提示:本文档共5页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
本文档由 人生无常 于 2026-01-06 05:03:18上传分享