02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3.1.5 O<strong>the</strong>r Trends<br />

O<strong>the</strong>r trends we have observed include <strong>the</strong> growth <strong>of</strong> teams in particular sectors. The<br />

CERT/CC has seen over <strong>the</strong> past few years a marked increase in <strong>the</strong> number <strong>of</strong> teams from<br />

banking and finance, insurance, law enforcement, and critical infrastructures such as power<br />

and energy, transportation, and information and communications. There has also been an increased<br />

interest in creating CSIRTs for federal government agencies, U.S. state governments,<br />

and national teams for countries in all areas <strong>of</strong> <strong>the</strong> world. Figure 9 shows <strong>the</strong> breakdown by<br />

sector <strong>of</strong> organizations that have attended CERT/CC CSIRT courses from 2000-2002.<br />

In <strong>the</strong> past seven years we have seen ano<strong>the</strong>r trend as incident response services have become<br />

<strong>of</strong>fered, along with a range <strong>of</strong> security services, by consulting or managed security service<br />

providers (MSSP). As more and more organizations require such support, <strong>the</strong>y now have a<br />

choice <strong>of</strong> creating <strong>the</strong>ir own team or hiring a team with <strong>the</strong> skills and experience to do <strong>the</strong><br />

job. Table 6 shows that as <strong>of</strong> August 2002, <strong>the</strong>re were approximately 23 MSSP CSIRTs that<br />

were ei<strong>the</strong>r members <strong>of</strong> FIRST or <strong>the</strong> European CSIRTs Directory. The first registered MSSP<br />

CSIRTs were in 1996. Since that time one or two have been added every year, with a large<br />

increase in 2001.<br />

% Organizational Sector Representation for 2000-2002 CSIRT<br />

Classes<br />

Information and<br />

Communications<br />

3%<br />

Public<br />

Administration<br />

19%<br />

Non-Pr<strong>of</strong>it<br />

2%<br />

Finance and<br />

Banking<br />

4%<br />

Energy Critical<br />

Infrastructure<br />

3%<br />

Military<br />

26%<br />

Education<br />

8%<br />

Law Enforcement<br />

2%<br />

Commercial<br />

33%<br />

Figure 9: Organizational Sector Representation for 2000–2002 CERT/CC CSIRT<br />

Classes<br />

Ano<strong>the</strong>r good example <strong>of</strong> <strong>the</strong> large number <strong>of</strong> teams that exist but are not registered comes<br />

from work that is done by CERTCC-KR. This team works with a group <strong>of</strong> 200+ established<br />

CSIRTs in Korea through an initiative called “CONCERT.” These teams come from universi-<br />

46 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!