Make the most of your IDS by beefing up your incident reports
Once the IDS alerts you to something going on, the typical response might be to call or e-mail an administrator to impart this information. But before you make the call or send the e-mail, take a minute to consider how best to present the information. You need to find a way to translate this report into detailed information and actionable suggestions that will help defend your company's network from hostile attacks.For example, you could say something like, "We're seeing an SMB service sweep coming from 10.100.64. 10 and BitTorrent activity from 10.100.55. 23." However, while this information might seem useful to you, it has little or no value when it comes to the administrator who has to take action on your report.
- Add new comment
- 2022 reads

Recent comments
51 weeks 1 day ago
1 year 3 weeks ago
1 year 7 weeks ago
1 year 8 weeks ago
1 year 11 weeks ago
1 year 18 weeks ago
1 year 43 weeks ago
2 years 12 weeks ago
2 years 15 weeks ago
2 years 15 weeks ago