Talk With an Expert

Investigative Tree Models

Investigative Tree Models (PDF, 2.62MB)Published: 15 Sep, 2009
Created by:
Rodney Caudle

Responding to information security incidents in today's complex digital environment requires extensive preparation and planning. The current six step approach to incident response provides a broad framework but leaves the population of details up to the individual investigator. The broad unstructured approach to incident response produces inconsistent results, unpredictable time frames and uncontrolled costs. Investigative tree models provide a structured approach to identifying the questions that need to be answered, identifying the location of data needed to answer the questions and prioritizing the collection of this data during incident response. The structured tree model approach to defining how questions are answered allows the incident response team to respond consistently with predictable results. The structured approach also provides for definable, reproducible structures to be created facilitating controlled cost exposure during an incident response cycle.