02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5 Future Work<br />

Based on <strong>the</strong> information collected in this <strong>State</strong> <strong>of</strong> <strong>the</strong> <strong>Practice</strong> <strong>of</strong> CSIRTs report, we believe<br />

<strong>the</strong> following areas <strong>of</strong> work are prime candidates for future development:<br />

• <strong>State</strong> <strong>of</strong> <strong>the</strong> practice survey—continue collection <strong>of</strong> data with a new and updated survey<br />

that can be used to feed information into CSIRT best practice development<br />

• CSIRT best practices—development <strong>of</strong> a series <strong>of</strong> best practice recommendations on<br />

CSIRT operations based on <strong>the</strong> current information collected and continued research<br />

• CSIRT criteria—for developing teams, determining staffing skills, and determining team<br />

effectiveness<br />

• CSIRT process guidelines—for <strong>of</strong>fering various services<br />

As a starting point, included below is a list <strong>of</strong> suggested topic areas where we see <strong>the</strong> need for<br />

more discussion or for more specific resources and guidelines to be developed. In many <strong>of</strong><br />

<strong>the</strong>se areas, work has already begun, or a prototype may even exist that can be used as a basis<br />

for fur<strong>the</strong>r development.<br />

• a new taxonomy specifically for CSIRT processes, incident data, and incident activity<br />

that can be accepted throughout <strong>the</strong> CSIRT community, perhaps through <strong>the</strong> development<br />

<strong>of</strong> an RFC<br />

• agreed-upon criteria for what constitutes a CSIRT, including different types <strong>of</strong> teams<br />

• a mechanism or mechanisms to identify and validate teams<br />

• more formalized resources to help new teams, including sample forms, checklists, and<br />

templates for CSIRT processes and operations<br />

• tools customized specifically for incident response work<br />

• models for estimating <strong>the</strong> cost and size <strong>of</strong> a CSIRT based on sector and services <strong>of</strong>fered:<br />

• guidelines on <strong>the</strong> services and processes needed for different CSIRT models and CSIRTs<br />

in different sectors<br />

• guidelines and references to cyber crime laws and legal issues (on a country basis) for<br />

incident handlers<br />

• use <strong>of</strong> certification criteria to develop new incident handler training and mentoring programs<br />

or enhance existing ones<br />

CMU/SEI-2003-TR-001 137

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!