02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3 Current <strong>State</strong> <strong>of</strong> <strong>the</strong> <strong>Practice</strong> <strong>of</strong> CSIRTs<br />

This section takes a look at <strong>the</strong> information ga<strong>the</strong>red through our research efforts. It pulls toge<strong>the</strong>r<br />

information from our survey, literature search, interviews, and research. The main focus<br />

is to provide a picture <strong>of</strong> <strong>the</strong> current CSIRT community and how teams go about <strong>the</strong>ir<br />

work. We will discuss <strong>the</strong> organizational structure and processes <strong>of</strong> teams, <strong>the</strong> problems in<br />

determining <strong>the</strong> actual number <strong>of</strong> teams, <strong>the</strong> types <strong>of</strong> services being <strong>of</strong>fered by teams, <strong>the</strong><br />

type <strong>of</strong> training available for teams, <strong>the</strong> types <strong>of</strong> projects being implemented by teams, and<br />

<strong>the</strong> major impacts on teams, such as changes in intruder trends and laws.<br />

Topics include <strong>the</strong> following:<br />

• <strong>the</strong> number and types <strong>of</strong> CSIRTs today, including some background on <strong>the</strong> change in<br />

number and type <strong>of</strong> CSIRT in <strong>the</strong> past few years<br />

• <strong>the</strong> organizational structures <strong>of</strong> CSIRTs, including constituency and mission, location,<br />

hours <strong>of</strong> operation, authority, and reporting structures<br />

• types <strong>of</strong> CSIRT funding and <strong>the</strong> costs <strong>of</strong> operating a CSIRT<br />

• <strong>the</strong> types <strong>of</strong> services <strong>of</strong>fered by different types <strong>of</strong> teams<br />

• <strong>the</strong> skill sets and staff positions needed on a team, along with a review <strong>of</strong> available training<br />

• how CSIRTs receive, record, track, categorize, and prioritize incident data<br />

• with whom CSIRTs coordinate response activities and share data<br />

• current influences on CSIRT operations that can potentially affect <strong>the</strong> creation and operation<br />

<strong>of</strong> CSIRTs<br />

• changes in <strong>the</strong> nature and type <strong>of</strong> intruder threat and <strong>the</strong> impact this has had on <strong>the</strong> dayto-day<br />

operations <strong>of</strong> CSIRTs<br />

• an overview <strong>of</strong> some <strong>of</strong> <strong>the</strong> recent projects undertaken by or beneficial to <strong>the</strong> CSIRT<br />

community<br />

3.1 Number and Type <strong>of</strong> CSIRTs Today<br />

It is difficult to determine exactly how many CSIRTs are in existence today. Some <strong>of</strong> <strong>the</strong> reasons<br />

for this difficulty are as follows:<br />

CMU/SEI-2003-TR-001 37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!