02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The project will first attempt to establish a “standardized and unambiguous” language for<br />

data exchange. The project will use and build on IODEF and IDMEF work done by <strong>the</strong> IETF<br />

and TF-CSIRT. eCSIRT.net aims at employing IODEF, IDMEF, and o<strong>the</strong>r relevant techniques<br />

in an operational setting between European national research network CSIRTs involving two<br />

commercial companies active in <strong>the</strong> CSIRT market.<br />

The technical work is organized as follows:<br />

• preparation phase (“defining a common language”)<br />

• usage phase (“using <strong>the</strong> common language between partners”)<br />

• clearinghouse function (“ga<strong>the</strong>ring incident statistics from partners using <strong>the</strong> common<br />

language”)<br />

• alert function (“ga<strong>the</strong>ring incident data from partners to derive early warnings and emergency<br />

alerts from, and spread <strong>the</strong>se to partners securely”)<br />

More can be read at:<br />

http://www.ecsirt.net/<br />

3.10.1.4 European Information <strong>Security</strong> Prevention Programme<br />

According to its web site, “The European Information <strong>Security</strong> Promotion Programme<br />

(EISPP) is a project co-funded by <strong>the</strong> European Community under <strong>the</strong> Fifth Framework Programme.<br />

The EISPP project aims to develop a European framework, not only to share security<br />

knowledge but also to define <strong>the</strong> content and ways <strong>of</strong> disseminating security information<br />

to SMEs. 146 By providing European SMEs with <strong>the</strong> necessary IT security services, <strong>the</strong>y will<br />

be encouraged to develop <strong>the</strong>ir trust and usage <strong>of</strong> e-commerce, leading to increased and better<br />

opportunities for new business….The project, started in June 2002 with an expected duration<br />

<strong>of</strong> 18 months, is run by a consortium <strong>of</strong> private sector organisations comprising CERTs,<br />

ISP/ASPs, and security pr<strong>of</strong>essional organisations” [EISPP 03].<br />

One <strong>of</strong> <strong>the</strong> objectives <strong>of</strong> <strong>the</strong> program is to “Set up a network <strong>of</strong> expertise among <strong>the</strong> European<br />

CERTs that will allow <strong>the</strong>m to share and enhance <strong>the</strong>ir own preventative material and to<br />

‘open’ it to <strong>the</strong> o<strong>the</strong>r CERTs and organisations involved in prevention” [EISPP 03].<br />

For more information please see:<br />

http://www.eispp.org/<br />

146<br />

“SME” stands for “small and medium enterprises.”<br />

CMU/SEI-2003-TR-001 121

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!