02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

into a course for new incident handling staff. This training is supported by <strong>the</strong> European<br />

Union so that new CSIRT team members can attend <strong>the</strong> training for a nominal fee. 25<br />

Ano<strong>the</strong>r benefit <strong>of</strong> this group is <strong>the</strong> opportunity for members <strong>of</strong> various teams to meet each<br />

o<strong>the</strong>r face-to-face at meetings throughout <strong>the</strong> year. Operational phone calls and data exchanges<br />

are easier when people get to know one ano<strong>the</strong>r. The TF-CSIRT has been successful<br />

in providing this type <strong>of</strong> forum for many <strong>of</strong> <strong>the</strong> European CSIRTs and has <strong>of</strong>fered real opportunities<br />

for collaboration and coordination, as can be seen by <strong>the</strong> projects mentioned previously.<br />

Ano<strong>the</strong>r significant achievement <strong>of</strong> <strong>the</strong> group has been <strong>the</strong> successful expansion <strong>of</strong> its<br />

activities beyond <strong>the</strong> original research networks by attracting commercial and government<br />

teams as participants as well.<br />

Ano<strong>the</strong>r successful outcome <strong>of</strong> this new approach to CSIRT collaboration was <strong>the</strong> Trusted<br />

Introducer or TI. This group took over <strong>the</strong> job <strong>of</strong> maintaining a directory <strong>of</strong> European<br />

CSIRTs. Along with <strong>the</strong> directory, <strong>the</strong> TI provides an accreditation service. Directories maintained<br />

previous to <strong>the</strong> TI (1995-1997 by DFN-CERT, 1998-1999 by EuroCERT) <strong>of</strong> European<br />

CSIRTs really meant work in terms <strong>of</strong> infrastructure and maintenance. The TI was able to<br />

provide this supported infrastructure.<br />

The first step towards <strong>the</strong> TI service was an analysis undertaken in early 2000. The analysis<br />

was commissioned by TERENA (ano<strong>the</strong>r facilitation to get things started) and in its own<br />

words:<br />

The aim <strong>of</strong> this report is to describe TI: an objective process meant to be applied<br />

to teams within <strong>the</strong> above defined scope [CSIRTs], that will enable teams new to<br />

<strong>the</strong> CSIRT community to move to a level where o<strong>the</strong>r teams will find it relatively<br />

easy to share information with <strong>the</strong>m and work with <strong>the</strong>m on incidents (in o<strong>the</strong>r<br />

words: to trust <strong>the</strong>m) - and that will enable teams (also <strong>the</strong> already established<br />

ones) to stay on that level. To ensure <strong>the</strong> process’s objectivity TI will be fully<br />

based on objective statements that can be verified [Kossakowski 00].<br />

A large point <strong>of</strong> discussion between teams was whe<strong>the</strong>r a form <strong>of</strong> certification ra<strong>the</strong>r than<br />

accreditation should be done as part <strong>of</strong> <strong>the</strong> TI work. Most teams felt unsure whe<strong>the</strong>r certification<br />

was really necessary and many thought that <strong>the</strong> issues involved were not well understood<br />

at <strong>the</strong> time. Concentrating on achievable goals, it was decided to go along with an accreditation<br />

framework.<br />

Based on very positive feedback on <strong>the</strong> report, <strong>the</strong> teams decided to implement <strong>the</strong> TI approach.<br />

After a call for tender, <strong>the</strong> TI service started on September 1, 2000, with initial fund-<br />

25<br />

See for more information about <strong>the</strong> project.<br />

26 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!