ITU-T E 409-2004 Incident organization and security incident handling Guidelines for telecommunication organizations (Study Group 2)《事故管理组织和安全事故处理 电信组织指南-第E-电话网络和ISDN操作 编号 路由和移动服务和.pdf
《ITU-T E 409-2004 Incident organization and security incident handling Guidelines for telecommunication organizations (Study Group 2)《事故管理组织和安全事故处理 电信组织指南-第E-电话网络和ISDN操作 编号 路由和移动服务和.pdf》由会员分享,可在线阅读,更多相关《ITU-T E 409-2004 Incident organization and security incident handling Guidelines for telecommunication organizations (Study Group 2)《事故管理组织和安全事故处理 电信组织指南-第E-电话网络和ISDN操作 编号 路由和移动服务和.pdf(22页珍藏版)》请在麦多课文档分享上搜索。
1、 INTERNATIONAL TELECOMMUNICATION UNION ITU-T E.409TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (05/2004) SERIES E: OVERALL NETWORK OPERATION, TELEPHONE SERVICE, SERVICE OPERATION AND HUMAN FACTORS Network management International service statistics Incident organization and security incident hand
2、ling: Guidelines for telecommunication organizations ITU-T Recommendation E.409 ITU-T E-SERIES RECOMMENDATIONS OVERALL NETWORK OPERATION, TELEPHONE SERVICE, SERVICE OPERATION AND HUMAN FACTORS INTERNATIONAL OPERATION Definitions E.100E.103 General provisions concerning Administrations E.104E.119 Gen
3、eral provisions concerning users E.120E.139 Operation of international telephone services E.140E.159 Numbering plan of the international telephone service E.160E.169 International routing plan E.170E.179 Tones in national signalling systems E.180E.189 Numbering plan of the international telephone se
4、rvice E.190E.199 Maritime mobile service and public land mobile service E.200E.229 OPERATIONAL PROVISIONS RELATING TO CHARGING AND ACCOUNTING IN THE INTERNATIONAL TELEPHONE SERVICE Charging in the international telephone service E.230E.249 Measuring and recording call durations for accounting purpos
5、es E.260E.269 UTILIZATION OF THE INTERNATIONAL TELEPHONE NETWORK FOR NON-TELEPHONY APPLICATIONS General E.300E.319 Phototelegraphy E.320E.329 ISDN PROVISIONS CONCERNING USERS E.330E.349 INTERNATIONAL ROUTING PLAN E.350E.399 NETWORK MANAGEMENT International service statistics E.400E.409 International
6、 network management E.410E.419 Checking the quality of the international telephone service E.420E.489 TRAFFIC ENGINEERING Measurement and recording of traffic E.490E.505 Forecasting of traffic E.506E.509 Determination of the number of circuits in manual operation E.510E.519 Determination of the numb
7、er of circuits in automatic and semi-automatic operation E.520E.539 Grade of service E.540E.599 Definitions E.600E.649 Traffic engineering for IP-networks E.650E.699 ISDN traffic engineering E.700E.749 Mobile network traffic engineering E.750E.799 QUALITY OF TELECOMMUNICATION SERVICES: CONCEPTS, MOD
8、ELS, OBJECTIVES AND DEPENDABILITY PLANNING Terms and definitions related to the quality of telecommunication services E.800E.809 Models for telecommunication services E.810E.844 Objectives for quality of service and related concepts of telecommunication services E.845E.859 Use of quality of service
9、objectives for planning of telecommunication networks E.860E.879 Field data collection and evaluation on the performance of equipment, networks and services E.880E.899 For further details, please refer to the list of ITU-T Recommendations. ITU-T Rec. E.409 (05/2004) i ITU-T Recommendation E.409 Inci
10、dent organization and security incident handling: Guidelines for telecommunication organizations Summary The purpose of this Recommendation is to analyse, structure and suggest a method for establishing an incident management organization within a telecommunication organization involved in the provi
11、sion of international telecommunications, where the flow and structure of an incident are focused. The flow and the handling are useful in determining whether an event is to be classified as an event, an incident, a security incident or a crisis. The flow also covers the critical first decisions tha
12、t have to be made. Computer crime follows in the wake of the heavily increased use of computers in international telecommunications. Over the last years, computer crime has literally exploded, as confirmed by several international and national surveys. In the majority of countries, there are no exac
13、t figures on the number of computer break-ins or security incidents, especially those related to international telecommunications. Most telecommunication organizations or companies do not have any specialized organization for handling Information and Communication Networks (ICN) security incidents (
14、although they may have a general crisis team for handling crises of any type). When an ICN security incident occurs it is handled ad hoc, i.e., the person who detects an ICN security incident takes the responsibility to handle it as best as (s)he can. In some organizations the tendency is to forget
15、and cover up ICN security incidents as they may affect production, availability and revenues. Often, when an ICN security incident is detected, the person who detects it does not know who to report it to. This may result in the system or networks administrator deploying a workaround or quick fix jus
16、t to get rid of the problem. They do not have the delegated authority, time or expertise to correct the system so that the ICN security incident does not recur. These are the main reasons why it is better to have a trained unit or group that can handle security incidents in a prompt and correct mann
17、er. Furthermore, many of the issues may be in areas as diverse as media relations, legal, law enforcement, market share, or financial. When reporting or handling an incident, the use of different taxonomies leads to misunderstanding. This may, in turn, result in an ICN security incident getting neit
18、her the proper attention, nor the prompt handling, that is needed in order to stop, contain and prevent the incident from recurring. This may lead to serious consequences for the affected organization (victim). To be able to succeed in incident handling and incident reporting, it is necessary to hav
19、e an understanding of how incidents are detected, handled and resolved. By establishing a general structure for incidents (i.e., physical, administrative or organizational, and logical incidents) it is possible to obtain a general picture of the structure and flow of an incident. A uniform terminolo
20、gy is the base for a common understanding of words and terms. Source ITU-T Recommendation E.409 was approved on 28 May 2004 by ITU-T Study Group 2 (2001-2004) under the WTSA Resolution 1. ii ITU-T Rec. E.409 (05/2004) FOREWORD The International Telecommunication Union (ITU) is the United Nations spe
21、cialized agency in the field of telecommunications. The ITU Telecommunication Standardization Sector (ITU-T) is a permanent organ of ITU. ITU-T is responsible for studying technical, operating and tariff questions and issuing Recommendations on them with a view to standardizing telecommunications on
22、 a worldwide basis. The World Telecommunication Standardization Assembly (WTSA), which meets every four years, establishes the topics for study by the ITU-T study groups which, in turn, produce Recommendations on these topics. The approval of ITU-T Recommendations is covered by the procedure laid do
23、wn in WTSA Resolution 1. In some areas of information technology which fall within ITU-Ts purview, the necessary standards are prepared on a collaborative basis with ISO and IEC. NOTE In this Recommendation, the expression “Administration“ is used for conciseness to indicate both a telecommunication
24、 administration and a recognized operating agency. Compliance with this Recommendation is voluntary. However, the Recommendation may contain certain mandatory provisions (to ensure e.g. interoperability or applicability) and compliance with the Recommendation is achieved when all of these mandatory
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ITUTE4092004INCIDENTORGANIZATIONANDSECURITYINCIDENTHANDLINGGUIDELINESFORTELECOMMUNICATIONORGANIZATIONSSTUDYGROUP2

链接地址:http://www.mydoc123.com/p-795121.html