This appendix provides a sample template for a SIRT Team Incident Report. This template outlines the information, data, and procedures for documenting a security breach or incident so that accurate information can be collected for each security breach or incident that is identified by the organization. Note that this is an example and each organization should modify this template and/or have their legal counsel and IT security managers provide additional input into the SIRT Team Incident Report.
Introduction to Assessing Network Vulnerabilities
Foundations and Principles of Security
Why Risk Assessment
Risk-Assessment Methodologies
Scoping the Project
Understanding the Attacker
Performing the Assessment
Tools Used for Assessments and Evaluations
Preparing the Final Report
Post-Assessment Activities
Appendix A. Security Assessment Resources
Appendix B. Security Assessment Forms
Appendix C. Security Assessment Sample Report
Appendix D. Dealing with Consultants and Outside Vendors
Appendix E. SIRT Team Report Format Template