02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

tion <strong>of</strong> knowledge resources, tools, or standards that may help a CSIRT’s day-to-day operations<br />

to organizational projects that try to facilitate coordination and collaboration between<br />

CSIRTs.<br />

The projects below have been grouped into <strong>the</strong> following categories: Coordination and Collaboration,<br />

Standards, <strong>Incident</strong> Data Collection, Tools, Information Resources, and Research.<br />

144 It is a selection <strong>of</strong> known projects as <strong>of</strong> September 2003. This is not a comprehensive<br />

list; if you have suggestions for inclusions please send <strong>the</strong>m to csirt-info@cert.org.<br />

Note that <strong>the</strong>se projects are mentioned here for information purposes only. Inclusion in this<br />

report does not constitute an endorsement by <strong>the</strong> CERT/CC.<br />

3.10.1 Coordination and Collaboration<br />

There has been considerable discussion in <strong>the</strong> CSIRT community about efforts to establish<br />

communication and coordination mechanisms between CSIRTs in various geographical regions<br />

that have a need to work toge<strong>the</strong>r due to <strong>the</strong>ir close proximity or shared issues. Methods<br />

being investigated include establishing operational incident coordination mechanisms<br />

and establishing forms or formats for exchanging incident data.<br />

Reviewing and following <strong>the</strong>se types <strong>of</strong> projects can provide CSIRTs with a resource for<br />

keeping up to date on trends, issues, and tools that are discussed. These projects can also provide<br />

ideas for o<strong>the</strong>r teams that plan to perform similar activities.<br />

3.10.1.1 CSIRT Task Force for European CSIRTs<br />

As discussed in Section 2.3.3, this task force sponsored by TERENA helps coordinate incident<br />

response and prevention in <strong>the</strong> European Community. The TF meets three times a year,<br />

provides a mailing list, and is involved in numerous ongoing projects such as <strong>the</strong> Clearinghouse<br />

for <strong>Incident</strong> Handling Tools and <strong>the</strong> development <strong>of</strong> IODEF. The TF works to facilitate<br />

collaboration and information exchange between European CSIRTs. The web site for <strong>the</strong> TF-<br />

CSIRT includes meeting minutes and copies <strong>of</strong> various presentations and CSIRT overviews<br />

presented at <strong>the</strong> meetings [TERENA 03].<br />

For more information see:<br />

http://www.terena.nl/tech/task-forces/tf-csirt/<br />

144<br />

Some projects may actually fall in more than one category, but are discussed in just one for ease <strong>of</strong><br />

organization.<br />

CMU/SEI-2003-TR-001 119

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!