02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

These early teams have become leaders in <strong>the</strong> Asia Pacific region, helping teams within <strong>the</strong>ir<br />

constituency and country get started and supporting incident response efforts not only in <strong>the</strong>ir<br />

country but globally. They have also been highly instrumental in <strong>the</strong> creation <strong>of</strong> various<br />

working groups for Asia Pacific CSIRTs.<br />

2.3.4.1 Creation <strong>of</strong> <strong>the</strong> Asia Pacific <strong>Security</strong> <strong>Incident</strong> <strong>Response</strong> Coordination<br />

Working Group<br />

There was a great interest by <strong>the</strong> Asia Pacific teams in <strong>the</strong> regional meetings <strong>of</strong> <strong>the</strong> European<br />

teams, and <strong>the</strong>y started similar activities to look at approaches for coordinating CSIRT collaboration<br />

and data sharing for <strong>the</strong> teams in that area. This resulted in <strong>the</strong> formation <strong>of</strong> <strong>the</strong><br />

Asia Pacific <strong>Security</strong> <strong>Incident</strong> <strong>Response</strong> Coordination (APSIRC) Working Group in 1997.<br />

This working group was formed as an outgrowth <strong>of</strong> work by <strong>the</strong> Asia Pacific Networking<br />

Group (APNG) 28 [Ito 03].<br />

The development <strong>of</strong> <strong>the</strong> APSIRC Working Group (APSIRC WG) was spearheaded by<br />

CERTCC-KR, SingCERT, and JPCERT/CC. The main function and services <strong>of</strong> <strong>the</strong> working<br />

group was to provide points <strong>of</strong> contact for <strong>the</strong> various member teams and to also provide resources<br />

and assistance for newly forming teams in <strong>the</strong> area [Ito 03]. Most <strong>of</strong> <strong>the</strong> initial team<br />

members were national teams such as <strong>the</strong> CSIRTs for Singapore, Malaysia, Japan, and Korea.<br />

2.3.4.2 Creation <strong>of</strong> Asia Pacific <strong>Computer</strong> Emergency <strong>Response</strong> Team<br />

In 2003 <strong>the</strong> APSIRC WG was transitioned into a new group, <strong>the</strong> Asia Pacific <strong>Computer</strong><br />

Emergency <strong>Response</strong> Team (APCERT). The APCERT has both a steering committee and a<br />

secretariat to provide organizational support and direction. Its initiatives and goals involve<br />

developing a regional and operational framework for not only <strong>the</strong> sharing <strong>of</strong> information and<br />

incident data between members <strong>of</strong> APCERT but also <strong>the</strong> coordination <strong>of</strong> incident response<br />

efforts. APCERT is also looking into projects concerning accreditation <strong>of</strong> members, methods<br />

for collecting membership fees, and methods for developing and delivering training for new<br />

and existing teams [Ito 03].<br />

APCERT full members as <strong>of</strong> August 2003 include [Ito 03]<br />

• AusCERT - Australian <strong>Computer</strong> Emergency <strong>Response</strong> Team, Australia<br />

• BKIS - Bach Khoa Internetwork <strong>Security</strong> Center, Vietnam<br />

• CCERT - CERNET <strong>Computer</strong> Emergency <strong>Response</strong> Team, Republic <strong>of</strong> China<br />

• CERTCC-KR - <strong>Computer</strong> Emergency <strong>Response</strong> Team Coordination Center-Korea, Korea<br />

• CNCERT/CC - China <strong>Computer</strong> Emergency <strong>Response</strong> Team Coordination Center, Republic<br />

<strong>of</strong> China<br />

28<br />

See for more information on <strong>the</strong> Asia Pacific Networking Group.<br />

28 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!