Appendix A: CSIRT Flashcards
Coordination centers
Coordinate handling of incidents across various CSIRTs. (i.e. US-CERT)
Analysis Centers
Synthesize data. Look for trends in incident activity.
Vendor teams
Vendor team that handles vulnerabilities in their products. Also remediation and mitigation.
Incident response providers
MSSP
CSIRT Constituency
Who they support
CSIRT relationship to others
Peers
CSIRT place in org.
Roots (mostly in the SOC)
Reactive service
Triggered by an event, request,
Proactive service
Prepare, protect systems
Triage function
Help desk level activities.
Handling function
Reviews incident report. Analysis. Responses. Notification.
Feedback function
Supports giving feedback on issues not related to specific incident.
Interface with media.
Optional announcement function
Provides advisories