How good is your data? Investigating the quality of data generated during security incident response investigations

George Grispos, William Bradley Glisson, Tim Storer

Research output: Chapter in Book/Report/Conference proceedingConference contribution

10 Scopus citations

Abstract

An increasing number of cybersecurity incidents prompts organizations to explore alternative security solutions, such as threat intelligence programs. For such programs to succeed, data needs to be collected, validated, and recorded in relevant datastores. One potential source supplying these datastores is an organization's security incident response team. However, researchers have argued that these teams focus more on eradication and recovery and less on providing feedback to enhance organizational security. This prompts the idea that data collected during security incident investigations may be of insufficient quality for threat intelligence analysis. While previous discussions focus on data quality issues from threat intelligence sharing perspectives, minimal research examines the data generated during incident response investigations. This paper presents the results of a case study identifying data quality challenges in a Fortune 500 organization's incident response team. Furthermore, the paper provides the foundation for future research regarding data quality concerns in security incident response.

Original languageEnglish (US)
Title of host publicationProceedings of the 52nd Annual Hawaii International Conference on System Sciences, HICSS 2019
EditorsTung X. Bui
PublisherIEEE Computer Society
Pages7156-7165
Number of pages10
ISBN (Electronic)9780998133126
StatePublished - 2019
Externally publishedYes
Event52nd Annual Hawaii International Conference on System Sciences, HICSS 2019 - Maui, United States
Duration: Jan 8 2019Jan 11 2019

Publication series

NameProceedings of the Annual Hawaii International Conference on System Sciences
Volume2019-January
ISSN (Print)1530-1605

Conference

Conference52nd Annual Hawaii International Conference on System Sciences, HICSS 2019
Country/TerritoryUnited States
CityMaui
Period1/8/191/11/19

ASJC Scopus subject areas

  • Engineering(all)

Fingerprint

Dive into the research topics of 'How good is your data? Investigating the quality of data generated during security incident response investigations'. Together they form a unique fingerprint.

Cite this