- Identify stakeholders1 and participants.
- Obtain management support and sponsorship.
- Develop a CSIRT project plan.
- Gather information.
- Identify the CSIRT constituency.
- Define the CSIRT mission.
- Secure funding for CSIRT operations.
- Decide on the range and level of services the CSIRT will offer.
- Determine the CSIRT reporting structure, authority, and organizational model.
- Identify required resources such as staff, equipment, and infrastructure.
- Define interactions and interfaces.
- Define roles, responsibilities, and the corresponding authority.
- Document the workflow.
- Develop policies and corresponding procedures.
- Create an implementation plan and solicit feedback.
- Announce the CSIRT when it becomes operational.
- Define methods for evaluating the performance of the CSIRT.
- Have a backup plan for every element of the CSIRT.
- Be flexible.
A Moro indigenous ethnic of Austronesian who live geographically in Maritime Southeast Asia, root language is Malayo-Polynesian (sometimes called Extra-Formosan or Malagasy). Today I speak Bajau, Malay and English.
Thursday, October 21, 2010
Security Incident Response Team: CSIRT: Getting Start
Action List for Developing a Computer Security Incident Response Team (CSIRT)
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment