02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Model<br />

Coordinating CSIRT<br />

Description<br />

Often centralized, a coordinating CSIRT is located in one physical or<br />

geographical location. In this model <strong>the</strong> CSIRT coordinates and facilitates<br />

<strong>the</strong> handling <strong>of</strong> incidents across a variety <strong>of</strong> organizations.<br />

The CSIRT can be a coordinating entity for individual subsidiaries <strong>of</strong><br />

a corporation, multiple branches <strong>of</strong> a military organization, branch<br />

campuses in an educational organization, institutions in a research<br />

network or specific domain or for a particular country or state. Coordinating<br />

CSIRTs usually have a broader scope and a more diverse<br />

constituency.<br />

More information about <strong>the</strong>se organizational models and structures can be found in Organizational<br />

Models for CSIRTs.<br />

In <strong>the</strong> pilot survey, we combined <strong>the</strong> above functional and organizational categories to create<br />

<strong>the</strong> following list:<br />

• security team (called an ad hoc team)s<br />

• distributed dedicated team<br />

• distributed part-time team<br />

• centralized team<br />

• coordination center<br />

• analysis center<br />

• managed security service provider<br />

We <strong>the</strong>n asked <strong>the</strong> participating teams to identify what category best described <strong>the</strong>ir CSIRT<br />

structure. See Section 3.2.3, “Organizational Placement <strong>of</strong> <strong>the</strong> CSIRT,” for <strong>the</strong> survey results<br />

<strong>of</strong> <strong>the</strong>ir responses.<br />

CSIRTs can also be categorized by <strong>the</strong> sector in which <strong>the</strong>y are located or in which <strong>the</strong>ir constituency<br />

is located. The sectors can be consolidated into a few general categories: government,<br />

research and education, national, commercial, and o<strong>the</strong>r.<br />

The following list breaks <strong>the</strong> above categories into more detail. These were <strong>the</strong> sectors used<br />

in <strong>the</strong> CSIRT Organizational Survey. See Figure 2, “Demographics <strong>of</strong> CSIRT Survey Participants,”<br />

for <strong>the</strong> results <strong>of</strong> <strong>the</strong> pilot survey.<br />

• military<br />

• education<br />

• information and communication<br />

• electric power<br />

16 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!