Guidelines for Evidence Collection and Archiving
This RFC 3227 was published in 2002
A "security incident" as defined in the "Internet Security Glossary", RFC 2828, is a security-relevant system event in which the system's security policy is disobeyed or otherwise breached.
The purpose of this document is to provide System Administrators with guidelines on the collection and archiving of evidence relevant to such a security incident.
RFC 3227 introduction
Click here to download RFC 3227: TXT format PDF format (coming soon)
Related Request for Comments
©2015 RFC-Base.org - all rights reserved.