FRAMEWORK FOR ESTABLISHING
AN INTER-AMERICAN CSIRT WATCH & WARNING NETWORK
(Presented by Ambassador Margarita Escobar,
Chair of the Working Group of the OAS Committee on Hemispheric Security
of the OAS, held on January 29, 2004, during the Third Plenary Session)
Objective:
To develop a hemisphere-wide 24-hour per day, seven day per week network of
national points of contact among Computer Security Incident Response Teams (CSIRTs) with national
responsibility (National CSIRTs), in OAS member states, capable of and charged with appropriately and
rapidly responding to cyber-security related crises, incidents, and threats.
As intruders use increasingly sophisticated attack tools, launch highly automated attacks that
travel at Internet speed, and intentionally use attack techniques that make it difficult to understand the
nature and source of the attacks, global, real-time collaboration across response teams will become
increasingly important. This collaboration would:
•
•
•
•
•
•
support rapid and accurate diagnosis of a problem;
rapidly disseminate warnings of actual attacks across the global community;
rapidly disseminate warnings of generic vulnerabilities across the global community;
alert the global community to suspicious activity and support collaborations that
investigate and diagnose the activity;
provide information on mitigation and remediation strategies to combat attacks and
threats; and
minimize duplication of analysis effort across teams.
Collaboration helps to leverage the technical knowledge that exists across the teams to limit
damage and ensure continued operation of critical services.
Principles:
Indigenous – The program must be operated and controlled by entities rooted in each
participating nation, designated by their government.
Systemic – The system must be a multi-faceted operation requiring an aware and trained
workforce, regular sharing of information regarding current threats and vulnerabilities, constant
re-evaluating and implementing of best practices and appropriate interaction with public policy
makers.
On-going - due to the inherent daily evolution of the Internet, any successful program must
regularly be updated and maintained. Internet security will not be achieved with a one-time fix.
Accountable – The “security” in “cyber security”. Strict rules with respect to issues such as the
handling of information must be understood and adhered to, or users will lose confidence and
efforts to make the system more secure will be undermined and become counter-productive.
Built upon existing arrangements – There are a number of pre-existing entities in the hemisphere
that provide cyber-security services to a greater or lesser extent. Any new system should build
upon these pre-existing institutions to avoid duplication and encourage active participation.