02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

REPORT DOCUMENTATION PAGE<br />

Form Approved<br />

OMB No. 0704-0188<br />

Public reporting burden for this collection <strong>of</strong> information is estimated to average 1 hour per response, including <strong>the</strong> time for reviewing instructions, searching<br />

existing data sources, ga<strong>the</strong>ring and maintaining <strong>the</strong> data needed, and completing and reviewing <strong>the</strong> collection <strong>of</strong> information. Send comments regarding<br />

this burden estimate or any o<strong>the</strong>r aspect <strong>of</strong> this collection <strong>of</strong> information, including suggestions for reducing this burden, to Washington Headquarters<br />

Services, Directorate for information Operations and Reports, 1215 Jefferson Davis Highway, Suite 1204, Arlington, VA 22202-4302, and to <strong>the</strong> Office <strong>of</strong><br />

Management and Budget, Paperwork Reduction Project (0704-0188), Washington, DC 20503.<br />

1. AGENCY USE ONLY<br />

(Leave Blank)<br />

2. REPORT DATE<br />

October 2003<br />

3. REPORT TYPE AND DATES COVERED<br />

Final<br />

4. TITLE AND SUBTITLE<br />

5. FUNDING NUMBERS<br />

<strong>State</strong> <strong>of</strong> <strong>the</strong> <strong>Practice</strong> <strong>of</strong> <strong>Computer</strong> <strong>Security</strong> <strong>Incident</strong> <strong>Response</strong> <strong>Teams</strong> F19628-00-C-0003<br />

(CSIRTs)<br />

6. AUTHOR(S)<br />

Georgia Killcrece, Klaus-Peter Kossakowski, Robin Ruefle, Mark Zajicek<br />

7. PERFORMING ORGANIZATION NAME(S) AND ADDRESS(ES)<br />

S<strong>of</strong>tware Engineering Institute<br />

Carnegie Mellon University<br />

Pittsburgh, PA 15213<br />

9. SPONSORING/MONITORING AGENCY NAME(S) AND ADDRESS(ES)<br />

HQ ESC/XPK<br />

5 Eglin Street<br />

Hanscom AFB, MA 01731-2116<br />

11. SUPPLEMENTARY NOTES<br />

8. PERFORMING ORGANIZATION<br />

REPORT NUMBER<br />

CMU/SEI-2003-TR-001<br />

10. SPONSORING/MONITORING AGENCY<br />

REPORT NUMBER<br />

ESC-TR-2003-001<br />

12A DISTRIBUTION/AVAILABILITY STATEMENT<br />

Unclassified/Unlimited, DTIC, NTIS<br />

13. ABSTRACT (MAXIMUM 200 WORDS)<br />

12B DISTRIBUTION CODE<br />

Keeping organizational information assets secure in today’s interconnected computing environment is a challenge<br />

that becomes more difficult with each new “e” product and each new intruder tool. There is no one solution<br />

for securing information assets; instead a multi-layered security strategy is required. One <strong>of</strong> <strong>the</strong> layers<br />

that many organizations are including in <strong>the</strong>ir strategy today is a computer security incident response team, or<br />

CSIRT. This report provides an objective study <strong>of</strong> <strong>the</strong> state <strong>of</strong> <strong>the</strong> practice <strong>of</strong> incident response, based on information<br />

about how CSIRTs around <strong>the</strong> world are operating. It covers CSIRT services, projects, processes,<br />

structures, and literature, as well as training, legal, and operational issues. The report can serve as a resource<br />

both to new teams that are setting up <strong>the</strong>ir operations and to existing CSIRTs that are interested in<br />

benchmarking <strong>the</strong>ir operations.<br />

14. SUBJECT TERMS<br />

CSIRT, computer security incident response team, incident handling,<br />

incident response, computer emergency response team, incident<br />

management, incident response management, CERT/CC, CERT Coordination<br />

Center<br />

16. PRICE CODE<br />

15. NUMBER OF PAGES<br />

290<br />

17. SECURITY CLASSIFICATION<br />

OF REPORT<br />

Unclassified<br />

18. SECURITY CLASSIFICATION OF<br />

THIS PAGE<br />

Unclassified<br />

19. SECURITY CLASSIFICATION OF<br />

ABSTRACT<br />

Unclassified<br />

20. LIMITATION OF ABSTRACT<br />

NSN 7540-01-280-5500 Standard Form 298 (Rev. 2-89) Prescribed by ANSI Std. Z39-18 298-102<br />

UL

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!