•
response teams (CSIRTs), CERT/CC’s own experience, discussions with and
observations of other CSIRTs, and research and reviews of the current literature on
incident response; and
Creating a Computer Security Incident Response Team: A Process for Getting
Started is a document that describes the basic requirements for creating a CSIRT.
There should be certification and accreditation of national CSIRTs. Member states should
consider whether affiliation of their national CSIRTs with FIRST would satisfy the certification and
accreditation requirements.
In establishing a regional network of cooperating National CSIRTs, a minimum set of
standards for cooperation and information-sharing among the CSIRTs would be expected. These
would include:
3.
i.
Designation of the national CSIRT by the respective government;
ii.
Agreement on principles of information sharing among the cooperating teams;
iii.
Responsibility for receiving information from other national CSIRTs and
disseminating that information to appropriate entities within the country;
iv.
Participation in information-sharing among the other national CSIRTs in the
hemispheric network;
v.
Authorization to disseminate information to other national CSIRTs; and
vi.
Provision of assistance to other national CSIRTs for incidents and threats.
Trust Issues
Much of the information which CSIRTs need to exchange is proprietary or otherwise
sensitive and there are few good models that promote the consistent sharing of information among
CSIRTs. Trust –the essential ingredient in information sharing– when it exists, has developed in
practice among individuals who know and have worked with each other, rather than institutionally,
among organizations. To establish trust, clear expectations on how information exchanged will be
used or disseminated must be understood and followed by all parties. Rules on information-sharing,
stating how information can be used or disseminated, must be agreed to among all of the cooperating
national CSIRTs.
Some of the CSIRT attributes that are required to promote trust in communication and
cooperation about sensitive security issues include:
i.
a secure infrastructure for managing sensitive information;
ii.
the ability to communicate securely with stakeholders;
iii.
the ability to marshal experts and decision-makers;