02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Malaysia <strong>Computer</strong> Emergency <strong>Response</strong> Team (MyCERT) is not an MSSP but at one time it<br />

<strong>of</strong>fered some services for free and additional or special services for a fee 61 [MyCERT 03].<br />

One <strong>of</strong> <strong>the</strong> biggest problems faced by CSIRTs is <strong>the</strong> ability to obtain and maintain funding. In<br />

<strong>the</strong> book <strong>Incident</strong> <strong>Response</strong>, Kenneth van Wyk and Richard Forno point out that it can be<br />

very difficult to get sufficient funding for <strong>the</strong> team because “information security, in general,<br />

plays a supporting role…security functions are not revenue-generators, <strong>the</strong>y are revenue consumers.”<br />

As a result, many organizations are challenged to find ways to make a business case<br />

for funding. The authors also suggests being “aggressive, assertive, and confident” in presenting<br />

a funding case to management. CSIRTs might also consider diverse mechanisms to obtain<br />

funding—levying a tax on business units or charging a fee for services [van Wyk 01]. Ano<strong>the</strong>r<br />

idea to save costs is to start with an ad hoc team, one that is pulled toge<strong>the</strong>r to handle an<br />

incident. The composition <strong>of</strong> <strong>the</strong> ad hoc team comes from o<strong>the</strong>r parts <strong>of</strong> <strong>the</strong> organization.<br />

Staff that perform job functions related to IT maintenance and security are also assigned incident<br />

response tasks. For such a model to work successfully, however, just making staff assignments<br />

isn’t enough to have a good response capability; staff, management, and <strong>the</strong> constituency<br />

need to understand that incident response takes priority over o<strong>the</strong>r tasks. If this is<br />

not handled correctly it will cost <strong>the</strong> organization more by having an inadequate and possibly<br />

incomplete response.<br />

3.3.2 Budgets<br />

CSIRT budgets are as diverse as <strong>the</strong> types <strong>of</strong> teams. Factors influencing budget costs include<br />

<strong>the</strong> type <strong>of</strong> industry sector <strong>the</strong> CSIRT is in (which can influence salary costs), <strong>the</strong> number <strong>of</strong><br />

services to be <strong>of</strong>fered, and <strong>the</strong> assistance provided by o<strong>the</strong>r areas <strong>of</strong> <strong>the</strong> organization (which<br />

could cut down on <strong>the</strong> amount <strong>of</strong> staff and resources needed).<br />

Survey participants were asked to identify what budget range most closely fit <strong>the</strong>ir CSIRT<br />

budget (including salary costs). The categories used were as follows:<br />

• Under $50,000 USD<br />

• Between $50,000 and $100,000 USD<br />

• Between $100,000 and $500,000 USD<br />

• Between $500,000 and $1,000,000 USD<br />

• Between $1,000,000 and $2,500,000 USD<br />

• Between $2,500,000 and $5,000,000 USD<br />

• Above $5,000,000 USD<br />

61<br />

According to <strong>the</strong>ir current web site, MyCERT no longer <strong>of</strong>fers <strong>the</strong>se special services. This information<br />

came from <strong>the</strong>ir web site in 2002.<br />

56 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!