02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

This document provides a view <strong>of</strong> <strong>the</strong> current state <strong>of</strong> <strong>the</strong> CSIRT practice as we see it. We<br />

recognize that as teams form, mature, and expand <strong>the</strong>ir services and capabilities, and as <strong>the</strong><br />

Internet and intruder threats evolve that CSIRTs practices will also evolve. However, we believe<br />

this document is a useful representation <strong>of</strong> information available at this time. We hope<br />

that this will provide guidance to those <strong>of</strong> you who are establishing CSIRTs or looking to<br />

benchmark your existing CSIRT. Certainly it will be available as a basis for any fur<strong>the</strong>r discussion<br />

or research on <strong>the</strong>se topics.<br />

This document will also provide a general reference for teams, with links and information on<br />

CSIRT processes, articles and white papers, training materials, and legal issues. Please note<br />

that all information mentioned here is for information purposes only. Inclusion in this report<br />

does not constitute an endorsement by <strong>the</strong> CERT/CC.<br />

The material in this report is based on <strong>the</strong> information we have collected through our own<br />

experiences, discussions with and observations <strong>of</strong> o<strong>the</strong>r CSIRTs, research and review <strong>of</strong> existing<br />

publications and literature related to CSIRTs and incident response, and <strong>the</strong> results <strong>of</strong> a<br />

pilot survey <strong>of</strong> some existing teams. We want to continue to learn, so if you have comments<br />

on this document, or if you want to share your opinions or suggest additions to this document,<br />

please contact us. We regularly attend FIRST conferences and teach CSIRT courses,<br />

and can be contacted in person or reached as a group by sending email to csirt-info@cert.org.<br />

xii<br />

CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!