02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

d. __ Subscriptions<br />

e. __ Research consortium<br />

f. __ O<strong>the</strong>r: ___________________________________________________________<br />

14. How many people work full-time (100% <strong>of</strong> <strong>the</strong>ir time) on your CSIRT? _______<br />

15. How many people work part-time (less than 100% <strong>of</strong> <strong>the</strong>ir time) on your CSIRT? ______<br />

For <strong>the</strong>se part-time workers, please estimate <strong>the</strong> equivalent number <strong>of</strong> full-time staff that<br />

would account for <strong>the</strong>ir effort: _______________________________________________<br />

16. Do you have a formal training or mentoring program for your CSIRT staff?<br />

a. ___Yes<br />

b. ___No<br />

17. What degrees or certifications, if any, do you require for CSIRT staff?<br />

______________________________________________________________________<br />

18. What is your approximate CSIRT budget (including salary costs)?<br />

a. __ Under $50,000 USD<br />

b. __ Between $50,000 and $100,000 USD<br />

c. __ Between $100,000 and $500,000 USD<br />

d. __ Between $500,000 and $1,000,000 USD<br />

e. __ Between $1,000,000 and $2,500,000 USD<br />

f. __ Between $2,500,000 and $5,000,000 USD<br />

g. __ Above $5,000,000 USD<br />

CSIRT Operations<br />

19. What services does your CSIRT provide? (Check all that apply.)<br />

a. __ incident handling/response<br />

b. __ analyzing vulnerabilities in hardware and s<strong>of</strong>tware<br />

c. __ analyzing exploits, toolkits, intruder logs and files (artifacts)<br />

d. __ handling virus reports/incidents<br />

CMU/SEI-2003-TR-001 145

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!