02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

service providers, or nation states [West-Brown 03]. Whomever it serves, <strong>the</strong> CSIRT must<br />

clearly identify <strong>the</strong> constituency to ensure that <strong>the</strong>y are providing services to appropriate individuals.<br />

The majority (86%) <strong>of</strong> <strong>the</strong> CSIRTs participating in <strong>the</strong> CSIRT Organizational Survey stated<br />

that <strong>the</strong>y did have an identified constituency. Some <strong>of</strong> <strong>the</strong> new and developing teams stated<br />

that <strong>the</strong>y were still in <strong>the</strong> process <strong>of</strong> identifying <strong>the</strong>ir constituency.<br />

The types <strong>of</strong> constituencies identified by <strong>the</strong> survey participants are shown in Figure 11.<br />

Organizational Survey Participants Constituencies<br />

clients and<br />

customers<br />

17%<br />

IP range or<br />

domain<br />

10%<br />

parent or host<br />

organization<br />

17%<br />

public<br />

3%<br />

military<br />

organizations<br />

26%<br />

university and<br />

research<br />

networks<br />

20%<br />

government<br />

organizations<br />

7%<br />

Figure 11: Constituencies <strong>of</strong> Survey Participants<br />

As would be expected, <strong>the</strong> educational sector CSIRTs identified <strong>the</strong>ir parent research network<br />

or university as <strong>the</strong>ir constituency. The military CSIRTs identified o<strong>the</strong>r areas <strong>of</strong> <strong>the</strong> military<br />

or specific military departments, and <strong>the</strong> information and communication CSIRTs identified<br />

<strong>the</strong>ir customers or supported IP ranges and domains as <strong>the</strong>ir constituency. The non-pr<strong>of</strong>it<br />

CSIRTs identified <strong>the</strong> public or <strong>the</strong>ir host organization as <strong>the</strong>ir constituency.<br />

It should be pointed out that a CSIRT does not just interact with its constituency. A CSIRT<br />

may also communicate with o<strong>the</strong>r CSIRT teams and security experts, individuals outside <strong>of</strong><br />

<strong>the</strong> CSIRT who are reporting problems, representatives from law enforcement, or vendors.<br />

Many CSIRTs, if time permits and if <strong>the</strong>ir policies allow, will try to help those outside <strong>of</strong> <strong>the</strong>ir<br />

constituency when reporting problems. But <strong>the</strong> constituency is <strong>the</strong> formal group that <strong>the</strong><br />

CSIRT provides service for according to its mission.<br />

50 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!