02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 12 shows <strong>the</strong> breakdown <strong>of</strong> budgets indicated by <strong>the</strong> survey participants.<br />

CSIRT Budget Ranges<br />

Between $100,000<br />

and $500,000<br />

25%<br />

Between $50,000<br />

and $100,000<br />

15%<br />

Under $50,000<br />

10%<br />

$5,000,000 and<br />

above<br />

7%<br />

Between<br />

$2,500,000 and<br />

$5,000,000<br />

3%<br />

Between $500,000<br />

and $1,000,000<br />

25%<br />

Between<br />

$1,000,000 and<br />

$2,500,000<br />

15%<br />

Figure 12: Budget Ranges for CSIRT Organizational Survey Participants<br />

The 7% that said <strong>the</strong>ir budgets were above $5,000,000 were all military CSIRTs. The majority<br />

<strong>of</strong> <strong>the</strong> remaining CSIRTs identified <strong>the</strong>ir budgets as ranging between $500,000 and<br />

$1,000,000 (25%) and between $100,000 and $500,000 (25%). Therefore, 50% <strong>of</strong> <strong>the</strong> participating<br />

CSIRTs indicated that <strong>the</strong>ir budgets were between $100,000 and $1,000,000. Educational<br />

and non-pr<strong>of</strong>it CSIRTs, as expected, had <strong>the</strong> lowest budgets. No o<strong>the</strong>r trends by sector<br />

were seen.<br />

3.3.3 Staff Costs<br />

In <strong>the</strong> Internet <strong>Security</strong> Systems (ISS) white paper “<strong>Computer</strong> <strong>Security</strong> <strong>Incident</strong> <strong>Response</strong><br />

Planning,” <strong>the</strong> amount quoted for security administrators and consultant salary costs (obtained<br />

from a January 2001 SysAdmin, Audit, Network, <strong>Security</strong> [SANS] <strong>Security</strong> Alert)<br />

ranged from approximately $60,000–$80,000 per year. This figure applies to those who perform<br />

system and network administration. The ISS report also quoted a Gartner estimate that a<br />

dedicated two-person incident response team will cost $251,000 in <strong>the</strong> first year for capital<br />

expenditures, with $324,000 per year for salaries, benefits, and training. Additionally, Gartner’s<br />

numbers for external investigation and o<strong>the</strong>r forensics services were in <strong>the</strong> $100,000<br />

range, for providing specialized skills in <strong>the</strong> collection and analysis <strong>of</strong> incident information. 62<br />

External staff undertaking this type <strong>of</strong> work will generally need more specialized training in<br />

62<br />

Internet <strong>Security</strong> Systems. “<strong>Computer</strong> <strong>Security</strong> <strong>Incident</strong> <strong>Response</strong> Planning, Preparing for <strong>the</strong><br />

Inevitable.” Atlanta, GA, 2001.<br />

CMU/SEI-2003-TR-001 57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!