%% You should probably cite rfc3227 instead of this I-D. @techreport{ietf-grip-prot-evidence-05, number = {draft-ietf-grip-prot-evidence-05}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-grip-prot-evidence/05/}, author = {Dominique Brezinski and Tom Killalea}, title = {{Guidelines for Evidence Collection and Archiving}}, pagetotal = 10, year = 2001, month = nov, day = 21, abstract = {A "security incident" as defined in the "Internet Security Glossary", RFC 2828, is a security-relevant system event in which the system's security policy is disobeyed or otherwise breached. The purpose of this document is to provide System Administrators with guidelines on the collection and archiving of evidence relevant to such a security incident. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.}, }