Software Engineering Institute Carnegie Mellon

Organizational Models for Computer Security Incident Response Teams (CSIRTs)

[Abstract]   [Title Page]   [Preface]   [Acknowledgements]   [1 Introduction]  
[2 Establishing CSIRT Capabilities]  
[3 Operational Issues]  
[4 Security Team--Using Existing IT Staff]  
[5 Internal Distributed CSIRT]  
[6 Internal Centralized CSIRT]  
[7 Combined Distributed and Centralized CSIRT]  
[8 Coordinating CSIRT]  
[9 Choosing the Right CSIRT Model for Your Organization]  
[10 Closing Remarks
  [Appendix Summary of Services Offered [Bibliography]   [PDF File]


9 Choosing the Right CSIRT Model for Your Organization

In the preceding sections, we have outlined a number of different models and CSIRT services to help you understand the options available. Of course, you can pick the most applicable features from each of the models described and design your own CSIRT model. Or perhaps your organization will require multiple organizational models to fit the needs of your situation. If you are still not sure what type of model would work best for your organizational structure, the guidelines in this chapter for choosing a model might help.

Please be advised that any answer that might be determined from the information below should be seen as a guide rather than a definitive recommendation. A definitive recommendation would require much more specific information about your constituency, mission, and services.

9.1 Do We Describe Your Team in this Handbook?

Although we have described several organizational models for implementing a CSIRT capability, this handbook is not inclusive. Specifically, we do not provide a model of operation for a vendor team or a managed security services provider. There may also be various situations that require a custom model for organizations.

If your team concentrates on security vulnerabilities as part of a vendor company, that is, your team receives reports of security flaws in your vendor products and works to repair these flaws and provide alerts, advisories, and fixes related to these flaws, then you are considered a vendor team. Since we do not provide a model for vendor teams, you may be able to discern a model yourself, based on the advantages and disadvantages described for each model in this handbook.

If your team provides incident response or security services to customers for a fee, then you are most likely a managed security services provider. We also do not provide a model for this type of team. Some of the models presented here may work for your organizational structure, but you will need to review the advantages and disadvantages of each and see which best suits your situation.

9.2 Are You a Security Team?

If you meet the following criteria, then you are probably a security team and should read Chapter 4.

9.3 Are You a Coordinating CSIRT?

If you meet the following criteria, then you are probably a coordinating CSIRT and should read Chapter 8.

9.4 Are You an Internal CSIRT?

If you meet the following criteria, then you are probably an internal CSIRT.

There are three different models for internal CSIRTs: distributed, centralized, and combined. Read the following information to determine what type of model may work best for you.

While it is rather straightforward to differentiate between the main categories of organizational models--security team vs. internal CSIRT vs. coordinating CSIRT, deciding whether a centralized approach would be better than a distributed or combined one for an internal CSIRT may be difficult. Instead we will discuss some of the factors that influence any decision.

The following are a few examples of choosing an organizational model based on combinations of various factors.

 


[Abstract]   [Title Page]   [Preface]   [Acknowledgements]   [1 Introduction]  
[2 Establishing CSIRT Capabilities]  
[3 Operational Issues]  
[4 Security Team--Using Existing IT Staff]  
[5 Internal Distributed CSIRT]  
[6 Internal Centralized CSIRT]  
[7 Combined Distributed and Centralized CSIRT]  
[8 Coordinating CSIRT]  
[9 Choosing the Right CSIRT Model for Your Organization]  
[10 Closing Remarks
  [Appendix Summary of Services Offered [Bibliography]   [PDF File]