2.
Systemic – The hemispheric network must be a multi-faceted operation requiring an aware
and trained workforce, regular sharing of information regarding current threats and
vulnerabilities, constant re-evaluating and implementing of best practices and appropriate
interaction with public policy makers.
3.
On-going – due to the inherent daily evolution of the Internet, any successful program must
regularly be updated and maintained, and the staff trained on a periodic basis. Internet
security will not be achieved with a one-time fix.
4.
Accountable – The “security” in “cyber security”. Established rules with respect to issues
such as the handling and provision of information must be understood and adhered to, or
users will lose confidence and efforts to make the system more secure will be undermined
and become counter-productive.
5.
Built upon existing arrangements – There are a number of pre-existing entities in the
hemisphere, including CSIRTs, consulting companies, and contact networks, among others,
that provide cyber-security services to a greater or lesser extent. Any new system should
build upon these pre-existing institutions and the trust relationships that have already been
established intra- and inter-regionally, to avoid duplication and encourage active
participation.
III. IDENTIFICATION OF EXISTING ORGANIZATIONS, ESTABLISHING A SERVICE
MODEL, TRUST ISSUES, FINANCING, PUBLIC AWARENESS,
AND EXTENDING THE NETWORK
1.
Identification of Existing Organizations
There are well over a hundred organizations that use the name CERT (Computer Emergency
Response Team), or CSIRT (the generic term of equivalent meaning), world-wide. The Forum of
Incident Response and Security Teams (FIRST), a world-wide, voluntary association of CSIRTs, lists
80 members within the OAS Member States, however the vast majority of these currently exist in one
member state only. Given the information gaps, conducting a CSIRT census is the essential first step
towards developing a cyber-security network.
2.
Establishing a Service Model
While there are no international standards agreed upon for what constitutes a CSIRT, there
are a number of documents and efforts that can assist the process of defining a CSIRT team and on
certification and accreditation of CSIRTs.
The CERT/CC has published a variety of documents that can assist in the creation of a
CSIRT, including:
•
•
Handbook for Computer Security Incident Response Teams (CSIRTs) provides
updated guidance on generic issues to consider when forming a CSIRT;
State of the Practice of Computer Security Incident Response Teams. This report
includes information collected through a pilot survey of computer security incident