02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 10: Example <strong>of</strong> Team Sponsorship and Propagation <strong>of</strong> CSIRTs<br />

Newly forming teams have benefited from site visits to established team sites; reviewing<br />

o<strong>the</strong>r teams’ web sites, incident reporting forms, and guidelines; and networking at conferences<br />

such as <strong>the</strong> annual FIRST conference or meetings such as those regularly held by <strong>the</strong><br />

TF-CSIRT. Many teams are quite willing to receive visitors and share <strong>the</strong>ir experiences in<br />

establishing <strong>the</strong>ir own team. They are also generally very supportive. In addition, many existing<br />

teams still consider it important for <strong>the</strong>ir day-to-day function to meet o<strong>the</strong>r teams, as any<br />

interaction with those teams will be easier once <strong>the</strong>y have established contact. Such meetings<br />

help teams gain a better understanding <strong>of</strong> each o<strong>the</strong>r and establish a means <strong>of</strong> communication.<br />

As mentioned in Section 1.7, “About <strong>the</strong> Literature Search,” many teams have also made articles<br />

and publications available about <strong>the</strong>ir process for establishing <strong>the</strong>ir team. These documents<br />

help new teams have an idea <strong>of</strong> a process to follow and also help teams avoid pitfalls<br />

and be aware <strong>of</strong> issues that will need to be addressed. Prior to 1998—<strong>the</strong> year <strong>the</strong> first edition<br />

<strong>of</strong> <strong>the</strong> CERT/CC Handbook for CSIRTs [West-Brown 03] was published—no comprehensive<br />

document was available for interested organizations to learn about <strong>the</strong> challenges and tasks<br />

48 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!