Hack Proofing your E-commerce Site: The Only Way to Stop a Hacker Is to Think Like One

If you build it, they will come attacks, that is. Expect your site to be probed, poked, prodded, tested, and scanned several times a day at a minimum. If you are a popular site, expect to be attacked several times an hour in some respect or another. Sounds like a lot, doesn't it?
The whole point of the incident response process is to separate the noise from the signal, so to speak. With all these events, how do you know which ones are actually threats and which ones your defense systems are handling? Well, with the proper application of incident tracking and incident policies, you can ensure that you will respond when needed, and will cut out most of the extraneous issues.
Incident response also depends on personnel. People require training, communication channels, and a proper process to follow. This chapter explains how to create a team to handle security events, and how to build policies to ensure that events are tracked and handled correctly. Finally, this chapter explains how to interface with law enforcement officials, should you ever require their assistance.
An Incident Response Policy (IRP) is important for the same reasons that a security policy is important; namely, that it dictates how you react when the situation arises. By way of illustration, let's look at some example scenarios.
Imagine you're one of the network engineers for an e-commerce site. At your company, the network group...