It is with GREAT excitement that I am pre-announcing my next area of research focus – security incident response.
In brief, here is what I have in mind for the next few months:
- Host and Malware Forensics Tools and Practices (title tentative), an assessment of the endpoint investigation tool scene (to complement my just-finished report on network forensics)
- Incident Response in the Age of APT (title tentative), a guidance to doing incident response (from tools to teams!) in the modern era of industrial cyber-crime, APT and also cloud/virtual/mobile environments.
Some of the vendors I am speaking with or planning to speak are Crowdstrike, Mandiant, Guidance Software, Carbon Black, some anti-malware/EPP vendors (who actually think rather than milk). And of course, as with all Gartner GTP research, I am planning to have lots of conversations with enterprise CIRTs, other end users and whatever others sources of current IR wisdom…
Possibly related posts:
Speaking at Gartner Catalyst Conference 2013 (some early research results on incident response will be presented there)
Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.