02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• <strong>Security</strong> quality management services. These services augment existing and already<br />

well-established services that are independent <strong>of</strong> incident handling and traditionally have<br />

been performed by o<strong>the</strong>r areas <strong>of</strong> an organization such as <strong>the</strong> IT, audit, or training department.<br />

If <strong>the</strong> CSIRT performs or assists with <strong>the</strong>se services, <strong>the</strong> CSIRT’s point <strong>of</strong> view<br />

and expertise can provide insight to help improve <strong>the</strong> overall security <strong>of</strong> <strong>the</strong> organization<br />

and identify risks, threats, and system weaknesses. These services are generally proactive<br />

in nature but contribute indirectly, ra<strong>the</strong>r than directly, to a reduction in <strong>the</strong> number <strong>of</strong> incidents.<br />

Table 9 provides a high level overview <strong>of</strong> <strong>the</strong> various CSIRT services within each <strong>of</strong> <strong>the</strong><br />

above categories as outlined in Organizational Models for CSIRTs and <strong>the</strong> corresponding<br />

CSIRT Services List. The services listed in Table 9 are defined and explained in detail in <strong>the</strong><br />

CSIRT Services list available at http://www.cert.org/csirts/services.html.<br />

Table 9:<br />

CSIRT Services by Category<br />

As illustrated in Table 9, <strong>the</strong>re are many different types <strong>of</strong> services that a CSIRT can provide.<br />

In reviewing <strong>the</strong> service <strong>of</strong>ferings from different CSIRTs, it can be seen that <strong>the</strong>re is not one<br />

set combination <strong>of</strong> functions or services that a CSIRT provides. However, to be considered a<br />

CSIRT, a team must provide some form <strong>of</strong> incident handling service.<br />

<strong>Incident</strong> handling includes three functions: receiving incident reports, performing incident<br />

analysis, and performing incident response. These translate into four basic services: incident<br />

analysis, incident response on-site, incident response support, and incident response coordination.<br />

The various types <strong>of</strong> “incident response” services indicate <strong>the</strong> wide variety <strong>of</strong> “responses”<br />

different types <strong>of</strong> CSIRTs choose to provide. Some teams actually perform repair<br />

66 CMU/SEI-2003-TR-001

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!