- Identify stakeholders1 and participants.
 - Obtain management support and sponsorship.
 - Develop a CSIRT project plan.
 - Gather information.
 - Identify the CSIRT constituency.
 - Define the CSIRT mission.
 - Secure funding for CSIRT operations.
 - Decide on the range and level of services the CSIRT will offer.
 - Determine the CSIRT reporting structure, authority, and organizational model.
 - Identify required resources such as staff, equipment, and infrastructure.
 - Define interactions and interfaces.
 - Define roles, responsibilities, and the corresponding authority.
 - Document the workflow.
 - Develop policies and corresponding procedures.
 - Create an implementation plan and solicit feedback.
 - Announce the CSIRT when it becomes operational.
 - Define methods for evaluating the performance of the CSIRT.
 - Have a backup plan for every element of the CSIRT.
 - Be flexible.
 
A Moro indigenous ethnic of Austronesian who live geographically in Maritime Southeast Asia, root language is Malayo-Polynesian (sometimes called Extra-Formosan or Malagasy). Today I speak Bajau, Malay and English.
Thursday, October 21, 2010
Security Incident Response Team: CSIRT: Getting Start
Action List for Developing a Computer Security Incident Response Team (CSIRT)
Subscribe to:
Post Comments (Atom)

No comments:
Post a Comment