Module 4: CSIRT Flashcards
What does CSIRT stand for
Computer Security Incident Response Team (CSIRT)
What is the primary job function of CSIRT
To review, receive, and respond to incidents
What does an Incident Response Team help an organization do
Recover from computer security breaches and threats
What is the goal of a CSIRT
- Manage the security problems
- Reduce and control the damage
- Provide effective response and recovery
Why is a clear vision for the CSIRT needed
A vision acts as a guiding principle for teams and helps them remain focused to achieve a predefined business objective.
What is the purpose of a CSIRT Mission Statement
Infers what a team is trying to achieve
What is a CSIRT’s constituency
The region where the CSIRT is bound to serve.
Such as the constituency of Gulfstream can be “Gulfstream Aerospace Corporation” and “gulfstream.com”
What type of issues does a CSIRT constituency have to face
- Constituencies that overlap (have clear rules of what their services are)
- Relationship to Constituency (level of authority)
- Promoting the CSIRT to the Constituency (how is it viewed to the public)
- Gaining Constituency Trust
What is a full constituency relationship
The CSIRT has fully authority to make any decision(s) on behalf of their constituency
What is a shared constituency relationship
The CSIRT provide direct support to their constituents and share in the decision-making process
What is a none constituency relationship
The CSIRT have no authority and act as advisors
TRUE or FALSE: With all the many different CSIRT’s from around the world it is not encouraged to co-operate with one another in order to get their jobs done.
FALSE
Cooperation and coordination is the heart of the CSIRT framework
What is a internal CSIRT
Offers incident handling services to their parent organization
What is a national CSIRT
Provides services to an entire nation
What is a coordination center
They coordinate and facilitate the handling of the incidents across various CSIRT’s
What is an analysis center
To use synced data from various sources such as patterns to provide early warning and predict future activity
What are vendor teams
They are teams that coordinate with organizations who report and track vulnerabilities
What do Incident Response Providers do
Provide assistance regarding incident handling services to paid clients
What steps need to be done to create a CSIRT
- Obtain management’s support and buy-in
- Determine the CSIRT strategic plan
- Gather relevant information
- Design the CSIRT vision
- Communicate the CSIRT vision and operational plan
- Begin CSIRT implementation
- Announce the operational CSIRT
- Evaluate CSIRT effectiveness
TRUE or FALSE: It is important to get management support for creating a CSIRT. (or for creating any project)
TRUE
They can approve the funding that makes it happen