02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• providing a test lab for information security products. This lab is available for free to industry.<br />

These initiatives show <strong>the</strong> diversity <strong>of</strong> CSIRT services.<br />

2.3.9 Today’s Activities<br />

Today <strong>the</strong>re are many more CSIRTs in operation and many different projects underway to<br />

facilitate coordination and information sharing between teams and to standardize terminology<br />

and processes in CSIRT operations. Some <strong>of</strong> <strong>the</strong> issues being discussed at <strong>the</strong> time <strong>of</strong> <strong>the</strong><br />

publishing <strong>of</strong> this report in 2003 still reflect <strong>the</strong> original goals and objectives <strong>of</strong> early discussions,<br />

namely, to create an effective way to coordinate information sharing, analysis, and response<br />

between teams. <strong>Teams</strong> today are still investigating <strong>the</strong> tools required for this type <strong>of</strong><br />

coordination and also what organizational structures will work best. Many areas are talking<br />

about creating regional coordination mechanisms to focus on particular geographic areas.<br />

How <strong>the</strong>se regional mechanisms will <strong>the</strong>n coordinate has yet to be determined. O<strong>the</strong>r areas <strong>of</strong><br />

discussion and activity include finding ways to standardize work and information exchange<br />

between CSIRTs, <strong>the</strong> impact <strong>of</strong> changing laws and regulations on CSIRT activities and organizational<br />

protection strategies, and <strong>the</strong> difficulty in finding, training, and retaining qualified<br />

incident handling staff. These activities, as well as information about how CSIRTs are currently<br />

operating, are discussed in <strong>the</strong> next section, “Current <strong>State</strong> <strong>of</strong> <strong>the</strong> <strong>Practice</strong> <strong>of</strong> CSIRTs.”<br />

CMU/SEI-2003-TR-001 35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!