Identification of Existing Organizations There are well over a hundred organizations that use the name CERT (Computer Emergency Response Team), or CSIRT (the generic term of equivalent meaning), world-wide. Many, but not all, have some affiliation with the CERT Coordination Center (CERT/CC) at Carnegie Mellon University where the first “CERT” was created. Even those CSIRTs associated with CERT/CC vary in their specific approaches to incident response based on a variety of factors such as consistency, geographical and technical issues, authority, services provided, and resources. In the United States, the Department of Homeland Security, National Cyber Security Division has created US-CERT, to be the “Computer Emergency Readiness Team” with national responsibility in the United States. In Canada, the Cyber Protection Division within the newly formed Public Safety and Emergency Preparedness Canada (PSEPC) fulfils a similar national responsibility role. The Forum on Incident Response Teams (FIRST), a world-wide, voluntary association of CSIRTs, lists 79 members within the OAS Member States, of which 68 are in the US. Of the remainder, six are in Canada; two are in Brazil, and one each in Chile, Mexico, and Peru. In addition, some companies, such as ATT, Symantec, and Visa, offer CSIRT services to their customers throughout the world, and there may be other CSIRTs in the region, such as Ar-CERT in Argentina, that that are not part of the FIRST network. Given the information gaps, conducting a CSIRT census is the essential first step towards developing a cyber-security network. Establishing a Service Model While there are no international agreed upon standards for what constitutes a CSIRT, there are a number of documents and efforts that can assist the process of defining a CSIRT team and on certification and accreditation of CSIRTs. The CERT/CC has published a variety of documents that can assist in the creation of a CSIRT, including: • • • Handbook for Computer Security Incident Response Teams (CSIRTs) provides updated guidance on generic issues to consider when forming a CSIRT; State of the Practice of Computer Security Incident Response Teams. This report includes information collected through a pilot survey of computer security incident response teams (CSIRTs), CERT/CC’s own experience, discussions with and observations of other CSIRTs, and research and reviews of the current literature on incident response; and Creating a Computer Security Incident Response Team: A Process for Getting Started is a document that describes the basic requirements for creating a CSIRT. In addition, the United States Department of Defense (US DoD) has created a program of certification and accreditation of computer network defense service providers within the US DoD. This program can be used as a starting point for establishing criteria for the accreditation of National CSIRTs.

Select target paragraph3