Georgia Killcrece
Software Engineering Institute
Georgia Killcrece is an SEI alumni employee.
Georgia Killcrece is a Member of the Technical Staff in the CERT Program at the Software Engineering Institute (SEI). She has over seventeen years direct experience within the CERT/CC in developing and transitioning best practices for developing effective incident response teams. Since 1999 Killcrece has led the CERT CSIRT Development Team within the CERT Program. She takes an active role in promoting the development of computer security incident response teams (CSIRTs) worldwide and has worked directly with a number of government, industry, and academic enterprises to facilitate the development of their incident management capabilities. Her team is involved in developing products aimed at evaluating CSIRT capabilities that can be transitioned to the global incident response community. Killcrece is internationally recognized as a leader in CSIRT development activities and has been a guest lecturer and invited speaker at numerous international conferences and government venues. She chaired the 2006 FIRST conference, an international forum representing over 180 government, academia, and industry response teams. Killcrece manages and participates in the creation and delivery of a suite products targeted at creating, managing, and sustaining effective incident management practices, including technical reports, articles, public and on-site training, as well as facilitated workshops focused on CSIRT development. She is an author and contributor to a series of CSIRT documents that define best practice approaches for effective incident response. More information about the CSIRT Development Team is available on the CERT web site at http://www.cert.org/csirts/. Killcrece can be reached directly by email at georgia@cert.org.
Publications by Georgia Killcrece
-
Incident Management Mission Diagnostic Method, Version 1.0
March 01, 2008 • Technical Report
Audrey J. DorofeeGeorgia KillcreceRobin Ruefle
This report is superseded by the Mission Risk Diagnostic for Incident Management Capabilities, CMU/SEI-2014-TN-004.
read -
The Real Secrets of Incident Management
April 03, 2007 • Podcast
Stephanie LosiGeorgia KillcreceRobin Ruefle
In this podcast, participants explain that incident management is not just technical response, but a cross-enterprise effort.
learn more -
Incident Management
December 01, 2005 • White Paper
Georgia Killcrece
In this paper, the author describes incident management capability and what it implies for controlling security events and incidents.
read -
Defining Incident Management Processes for CSIRTs: A Work in Progress
October 01, 2004 • Technical Report
Christopher J. AlbertsAudrey J. DorofeeGeorgia Killcrece
In this report, the authors present a prototype best practice model for performing incident management processes and functions.
read -
Steps for Creating National CSIRTs
August 02, 2004 • White Paper
Georgia Killcrece
In this paper, Georgia Killcrece provides a high-level description of a National Computer Security Incident Response Team (NatCSIRT), its problems, and challenges.
read -
Organizational Models for Computer Security Incident Response Teams (CSIRTs)
December 01, 2003 • Handbook
Georgia KillcreceKlaus-Peter KossakowskiRobin Ruefle
This 2003 report describes different organizational models for implementing incident handling capabilities, including each model's advantages and disadvantages and the kinds of incident management services that best fit with it.
read -
State of the Practice of Computer Security Incident Response Teams (CSIRTs)
October 01, 2003 • Technical Report
Georgia KillcreceKlaus-Peter KossakowskiRobin Ruefle
In this 2003 report, the authors provide a study of the state of the practice of incident response, based on how CSIRTs around the world are operating.
read -
Handbook for Computer Security Incident Response Teams (CSIRTs)
April 01, 2003 • Handbook
Moira West BrownDon StikvoortKlaus-Peter Kossakowski
In this 2003 handbook, the authors describe different organizational models for implementing incident handling capabilities.
read