4.3.4 National Computer Incident Response Team (BWCIRT)
The role of the proposed National CIRT is to act as the trusted point of contact as well
as provide central operational coordination for incident response at National level. This
entails ensuring partnership with international CIRTs to ensure presence of mechanisms
for cross-border incident handling as well as coordinating all sector specific country
response teams. Taking into consideration that Cybersecurity issues are increasing and
that it may take a long time for the realisation of some of the strategic actions and
approval of the strategy, it is recommended that as a matter of urgency the country
starts with the National CIRT so that it can assist in monitoring the cyber threats and
consumer awareness.
The main responsibilities of the National CIRT cover amongst others the following
areas:
i)
ii)
iii)
iv)
v)
vi)
vii)
viii)
ix)
x)
Providing incident response support to all relevant stakeholders via established,
trusted, authorised and centrally coordinated initiatives at the national level;
Dissemination of critical information such as early warnings and alert
notifications, security advisory, and upholding security best practices;
Acting as a single point of contact for cyber incident reporting and coordination;
Detecting and identifying anomalous activity;
Analysing cyber threats and disseminating cyber threat warning information;
Analysing and synthesizing incident and vulnerability information disseminated
by others such as vendors to provide an assessment for interested
stakeholders;
Establishing trusted communications mechanisms and facilitating
communications among stakeholders to share information and address cyber
security issues;
Developing mitigation and response strategies and coordinating incident
response;
Sharing data and information about the incident and corresponding responses;
Coordinating international cooperation on cyber incidents; and Building capacity
in all the above areas using advanced technology and techniques, establishing
methods, and researching threat analyses and mitigations.
4.3.5 Law Enforcement Agencies
Law Enforcement Agencies (LEA) and Security Forces play a key role in investigating
cybercrimes and enforcing Cybersecurity related laws. They also play a vital role in
ensuring collaboration with a wide range of partners to combat cybercrimes with
international dimensions and/ or span multiple jurisdictions. Further, these agencies
play a vital role in keeping law and order during nation-wide cyber-attacks and
33 | P a g e
National Cybersecurity Strategy