02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6 Closing Remarks<br />

This document discusses a wide variety <strong>of</strong> issues within <strong>the</strong> practice <strong>of</strong> establishing and operating<br />

a CSIRT. Although many topics were discussed, we realize that <strong>the</strong> first edition <strong>of</strong> this<br />

technical report could not be a comprehensive, inclusive look at that state <strong>of</strong> <strong>the</strong> practice <strong>of</strong><br />

CSIRTs. But it is an initial attempt to begin to collect information on <strong>the</strong> history, practice,<br />

structure, services, and challenges <strong>of</strong> CSIRTs.<br />

There is much more information o<strong>the</strong>r teams could have contributed to this body <strong>of</strong> work, but<br />

it was not possible to talk or interact with every team. To that end we would like to get your<br />

feedback on this technical document: did it meet your expectations, was it helpful, what was<br />

missing, and what was beneficial? We would welcome any data you have collected regarding<br />

<strong>the</strong> issues addressed in this document that you are able and willing to share. We would also<br />

welcome hearing about any best practices, case studies, success stories, or o<strong>the</strong>r experiences<br />

that you or your team may have in creating and operating a CSIRT and that we could incorporate<br />

into future editions.<br />

Please feel free to contact us at csirt-info@cert.org.<br />

If you are interested in reading more about CSIRT development and operations, a good place<br />

to start is <strong>the</strong> newly revised Handbook for CSIRTs, which is available on <strong>the</strong> CERT web site<br />

at http://www.cert.org/archive/pdf/csirt-handbook.pdf. You can also find many interesting and<br />

helpful articles in <strong>the</strong> bibliography attached to this document.<br />

If you are interested in learning more about CSIRTs and processes and best practices for incident<br />

handling, you may want to attend one <strong>of</strong> our CSIRT courses. You can find course information<br />

and schedules at http://www.cert.org/nav/index_gold.html.<br />

Once again we would like to thank everyone who helped us in <strong>the</strong> creation and production <strong>of</strong><br />

this document. Without your support, we would not have been able to publish this state <strong>of</strong> <strong>the</strong><br />

practice.<br />

CMU/SEI-2003-TR-001 139

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!