Software Engineering Institute Carnegie Mellon

State of the Practice of Computer Security Incident Response Teams (CSIRTs)

[Abstract]   [Title Page]  
[Who is the CERT CSIRT Development Team and What Do They Do?]  
[Preface]  
[Acknowledgements]  
[1 Introduction]   [2 Computer Security Incident Response Teams]  
[3 Current State of the Practice of CSIRTs]  
[4 Summary]   [5 Future Work]  
[6 Closing Remarks]  
[Appendix A: CSIRT Organizational Survey]  
[Appendix B: Comparison of Incident Response Steps and Processes]  

[Appendix C: Training Sources for CSIRTs]  
[Appendix D: Cyber Crime Law Resources]  
[Appendix E: Sample Incident Reporting Forms and Flowcharts]  
[Bibliography]   [PDF File]

Who is the CERT CSIRT Development Team and What Do They Do?

The CERT CSIRT Development Team helps organizations build their own computer security incident response teams (CSIRTs) and also helps existing teams enhance their effectiveness. The team is an outgrowth of the work and products developed in the CERT Coordination Center (CERT/CC). Our focus is to assist new and existing teams in understanding best practices and recommendations for performing incident handling and related CSIRT services. The guidance provided is based on the history and experiences of the CERT/CC, along with knowledge gained from our extensive collaborations with other teams.

To help organizations, we

For more information, please contact csirt-info@cert.org.

 

 

 


[Abstract]   [Title Page]  
[Who is the CERT CSIRT Development Team and What Do They Do?]  
[Preface]  
[Acknowledgements]  
[1 Introduction]   [2 Computer Security Incident Response Teams]  
[3 Current State of the Practice of CSIRTs]  
[4 Summary]   [5 Future Work]  
[6 Closing Remarks]  
[Appendix A: CSIRT Organizational Survey]  
[Appendix B: Comparison of Incident Response Steps and Processes]  

[Appendix C: Training Sources for CSIRTs]  
[Appendix D: Cyber Crime Law Resources]  
[Appendix E: Sample Incident Reporting Forms and Flowcharts]  
[Bibliography]   [PDF File]