02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ganizations, and government organizations. The 2003 FIRST conference was held in Ottawa,<br />

<strong>the</strong> Canadian capital.<br />

Many different CSIRT initiatives at various levels <strong>of</strong> government in Canada are being implemented.<br />

Work is going on at <strong>the</strong> country, province, territory, and city level. Some provincial<br />

government CSIRTs have been operating for a few years, while o<strong>the</strong>rs are in <strong>the</strong> process<br />

<strong>of</strong> standing up <strong>the</strong>ir team.<br />

The focal point <strong>of</strong> incident handling at <strong>the</strong> country level is <strong>the</strong> Office <strong>of</strong> Critical Infrastructure<br />

Protection and Emergency Preparedness) (OCIPEP). OCIPEP is a civilian organization operating<br />

in <strong>the</strong> Canadian government’s Department <strong>of</strong> National Defence. OCIPEP works under<br />

<strong>the</strong> concept <strong>of</strong> partnerships. Its web site states that “protecting critical infrastructure and responding<br />

to emergencies is a shared responsibility in Canada, requiring <strong>the</strong> full cooperation<br />

and effort <strong>of</strong> Government <strong>of</strong> Canada departments and agencies, provinces and territories,<br />

municipalities and <strong>the</strong> private sector” [OCIPEP 03].<br />

“OCIPEP’s Infrastructure Protection Coordination Centre monitors physical and cyber threats<br />

(24 hours a day/7 days per week) and serves as a central point <strong>of</strong> contact for threat and incident<br />

information. Related information is currently received from and sent to <strong>the</strong> Government<br />

<strong>of</strong> Canada, provincial and territorial governments, and <strong>the</strong> private sector” [OCIPEP 03].<br />

2.3.7 Developments in <strong>the</strong> United <strong>State</strong>s<br />

Many different types <strong>of</strong> CSIRTs have also been developing over <strong>the</strong> years in <strong>the</strong> United<br />

<strong>State</strong>s. As can be seen in <strong>the</strong> next section, <strong>the</strong>re are currently over 70 U.S. teams that are<br />

FIRST members. These teams come from many sectors, including military, government, education,<br />

critical-infrastructures, financial, ISP, non-pr<strong>of</strong>it, and commercial organizations.<br />

There are many, many more U.S. teams that are not FIRST members. Some <strong>of</strong> <strong>the</strong> areas<br />

where we see <strong>the</strong> biggest growth in CSIRTs have been commercial and critical infrastructure<br />

organizations. Most branches <strong>of</strong> <strong>the</strong> U.S. military have <strong>the</strong>ir own CSIRTs. Many federal<br />

agencies also have <strong>the</strong>ir own teams or are in <strong>the</strong> process <strong>of</strong> creating <strong>the</strong>m.<br />

One <strong>of</strong> <strong>the</strong> newest areas where we see interest and initiatives in creating CSIRTs is at <strong>the</strong> state<br />

government level. <strong>State</strong> governments are receiving mounting pressure to meet <strong>the</strong>ir compliance<br />

requirements with various laws and regulations regarding data privacy and cyber security.<br />

In 2003 a report by Zeichner Risk Analytics concluded that <strong>the</strong> majority <strong>of</strong> states have<br />

not met <strong>the</strong>se requirements and regulations. The report also called for states to work toge<strong>the</strong>r<br />

to come up with a nationwide process for implementing and developing cyber-security laws<br />

and policies [Zeichner 03].<br />

CMU/SEI-2003-TR-001 33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!