02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

O<strong>the</strong>r areas not included on <strong>the</strong> survey list that were mentioned as coordination partners include<br />

government organizations, investigators, CEOs, and system owners.<br />

Looking at this information by sector,<br />

• All <strong>of</strong> <strong>the</strong> participating banking and finance CSIRTs coordinate with <strong>the</strong>ir CIO, physical<br />

security department, law enforcement and investigators.<br />

• All <strong>of</strong> <strong>the</strong> information and communication CSIRTs coordinate <strong>the</strong>ir response activities<br />

with <strong>the</strong>ir CIO, legal department, and public relations department. 75% <strong>of</strong> <strong>the</strong> information<br />

and communication CSIRTs also stated that <strong>the</strong>y coordinated with law enforcement<br />

and o<strong>the</strong>r CSIRTs.<br />

• All <strong>of</strong> <strong>the</strong> o<strong>the</strong>r commercial CSIRTs coordinate with business managers, <strong>the</strong> legal department,<br />

<strong>the</strong> public relations department, and o<strong>the</strong>r CSIRTs.<br />

• There were no specific trends for educational, military, or non-pr<strong>of</strong>it CSIRTs.<br />

Looking at this information by CSIRT model,<br />

• 75% <strong>of</strong> <strong>the</strong> ad hoc teams coordinate with o<strong>the</strong>r CSIRTs.<br />

• 100% <strong>of</strong> <strong>the</strong> coordination centers coordinate with <strong>the</strong>ir CIO and law enforcement.<br />

• 83% <strong>of</strong> <strong>the</strong> centralized teams coordinate with law enforcement. 60% coordinate with<br />

<strong>the</strong>ir CIO. 50% stated that <strong>the</strong>y coordinate with <strong>the</strong> CERT/CC. 50% also coordinate with<br />

o<strong>the</strong>r CSIRTs and security experts.<br />

• 80% <strong>of</strong> <strong>the</strong> combined teams coordinate with law enforcement, while 60% coordinate with<br />

<strong>the</strong>ir CIO and <strong>the</strong>ir legal department.<br />

• 100% <strong>of</strong> <strong>the</strong> distributed dedicated teams coordinate with <strong>the</strong>ir CIO and public relations<br />

department. 66% coordinate with law enforcement, o<strong>the</strong>r CSIRTs, and with <strong>the</strong>ir legal<br />

departments.<br />

• 75% <strong>of</strong> <strong>the</strong> distributed part-time teams coordinate with o<strong>the</strong>r CSIRTs; 50% coordinate<br />

with <strong>the</strong>ir CIO, business managers, human resources department, physical security, legal<br />

department, public relations department, and law enforcement.<br />

3.7.14.2 With Whom Does <strong>the</strong> CSIRT Share Information?<br />

The majority <strong>of</strong> CSIRTs share information with <strong>the</strong> CIO (66%), <strong>the</strong> IT and telecommunications<br />

departments (58%), law enforcement (58%), and o<strong>the</strong>r CSIRTs (55%). O<strong>the</strong>rs that were<br />

mentioned and not included in <strong>the</strong> original survey list <strong>of</strong> options were investigators. An interesting<br />

question to ask in future surveys would be what type <strong>of</strong> information is shared.<br />

Looking at this information by CSIRT sector,<br />

• 100% <strong>of</strong> <strong>the</strong> banking and finance CSIRTs share information with <strong>the</strong>ir CIO, <strong>the</strong>ir audit<br />

department, law enforcement, and <strong>the</strong>ir IT and telecommunications departments.<br />

CMU/SEI-2003-TR-001 107

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!