02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>the</strong>ir web pages. This may also be true for university or research networks. But for local and<br />

commercial teams, that information is not usually available.<br />

There is also no standard manager to which a CSIRT reports. The title <strong>of</strong> <strong>the</strong> manager <strong>of</strong>ten<br />

relates to <strong>the</strong> department in which <strong>the</strong> CSIRT is located and <strong>the</strong> title that department’s manager<br />

has been given, such as “Head <strong>of</strong> Network Services” or “Director <strong>of</strong> Telecommunications.”<br />

Depending on who you talk to in <strong>the</strong> CSIRT community, you will get a variety <strong>of</strong> answers<br />

to <strong>the</strong> question “To whom should a CSIRT report?” Some will say <strong>the</strong>y should report to<br />

<strong>the</strong> CIO, o<strong>the</strong>rs to <strong>the</strong> CSO, and o<strong>the</strong>rs to <strong>the</strong> head <strong>of</strong> audit or <strong>the</strong> compliance divisions.<br />

To find out more information, we asked in our survey where CSIRTs were organizationally<br />

located and to whom <strong>the</strong>y reported. Participants in <strong>the</strong> CSIRT Organizational Survey cited <strong>the</strong><br />

IT department 41% <strong>of</strong> <strong>the</strong> time as <strong>the</strong>ir location in <strong>the</strong> hierarchical structure <strong>of</strong> <strong>the</strong>ir parent or<br />

host organization. 58 The next most frequently cited location (24%) was for CSIRTs that are<br />

separate groups outside <strong>of</strong> any existing department.<br />

Looking at <strong>the</strong> survey data for <strong>the</strong> sector in which a CSIRT is located and its organizational<br />

placement, <strong>the</strong> following trends can be observed: 59<br />

• The majority <strong>of</strong> <strong>the</strong> military CSIRTs were located within <strong>the</strong> IT department.<br />

• Almost all participating educational sector CSIRTs were located in <strong>the</strong> IT department <strong>of</strong><br />

<strong>the</strong> parent university or research network.<br />

There were no o<strong>the</strong>r correlations based on sector.<br />

3.2.3.1 To Whom <strong>the</strong> CSIRT Reports<br />

The survey data also showed no clear or consistent reporting structure for CSIRTs.<br />

• 38% <strong>of</strong> <strong>the</strong> participating CSIRTs stated that <strong>the</strong>y report to someone o<strong>the</strong>r than <strong>the</strong> CIO,<br />

IT manager, CSIRT manager, or security manager. Most <strong>of</strong> <strong>the</strong> teams identified an organizational<br />

department or manager to whom <strong>the</strong> team reports.<br />

• 31% stated that <strong>the</strong>y report to <strong>the</strong> CIO.<br />

• The only correlation between <strong>the</strong> sector and <strong>the</strong> reporting structure was in <strong>the</strong> banking<br />

and finance sector, where all participating teams reported to <strong>the</strong> CIO. Across <strong>the</strong> o<strong>the</strong>r<br />

sectors, <strong>the</strong> teams reported to various o<strong>the</strong>r managers.<br />

58<br />

59<br />

In an informal survey <strong>of</strong> 14 CSIRTs done by <strong>the</strong> CERT CSIRT Development Team in 2000, <strong>the</strong><br />

majority <strong>of</strong> <strong>the</strong> teams also identified this location as <strong>the</strong> department in which <strong>the</strong> CSIRT was positioned.<br />

See page 16 for a list <strong>of</strong> all sectors used in <strong>the</strong> survey.<br />

52 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!