Vendor Response
Vendor incident response is just that, Vendor
specific. Almost all major hardware and operating system companies
have an Internal Response team that seconds as their Vendor
Response to clients. They are focused on the following procedures
involving an incident with their product.
- Document the vulnerability to their product.
- Verify the vulnerability to their product.
- Determine the cause of the vulnerability.
- Recommend a course of action.
- Coordinate resolution efforts.
- Inform the rest of their customers of the problem and
solution.
- Insert the solution with patches and upgrades.
- Post mortem analysis of the problem.
Disadvantages of a Vendor Response team are as follows.
- Vendors response teams are also spin doctors to play down
the impact of an incident involving their product.
- Vendor response possesses an ETA factor before help arrives.
Many do not make a site visit unless specific Service Level
Agreements are in place for the products.
- Vendors are loyal to their product and company, making
unbiased response evaluation near impossible.
- They are focused on a specific product, and not your entire
organizational infrastructure needs.
|