In security response, practice makes perfect

02.10.2012

And the reality? Systems require human intervention. Scripts and rules are not enough. But, humans can't scale like computers can. The cloud only further exacerbates the problem.

"Most organizations don't have a dedicated forensics expert on staff," added Grutzius. "This makes it extremely difficult, if not impossible, to effectively triage and analyze a security event."

One of the more interesting takes on the human element compared to computer-only systems is Henry's description of a network-speed intelligence-sharing system:

- Human-to-human collaboration with little to no system automation involved is not acceptable as it can't scale

- Human-to-machine collaboration is irrelevant as the translations are not always accurate