Advanced Technology Laboratory

Security Checklist

Avoid Panic.

Assess the appropriate level of response.

Immediately hoard all available information.

Assess immediate corporate/date risk.

If necessary/appropriate, disconnect compromised machines from the network.

Stop, Look, Listen.

With a creative colleague, and away from a keyboard, draw up a recovery plan on a nearby whiteboard.

Educate users and management on the assessed risk and preliminary recovery strategy.

Implement the recovery strategy.

If you determine the problem to have come from outside your organization, report the incident to the Computer Emergency Response Team (CERT) at +1-412-268-7090 (MILNET USERS: call SCC at 1-800-235-3155).


shrdlu AT deaddrop DOT org

Last modified: Sat Oct 30 23:04:39 PDT 2004