11.2.6
Stage 5 – Standards and Implementation Guides
National focal points also help critical infrastructure owners, providers and vendors build
capacity to defend systems and information. The organisation may issue technical
implementation guides and best practice guides. The focal point may either perform this
role or work with the national technical and information assurance organisations.
11.3
NATIONAL COMPUTER INCIDENT
RESPONSE TEAM (CIRT)
The growing sophistication, frequency and gravity of cyber threats necessitate formal
54
frameworks for watch, warning and incident response. Resolution 58 of the ITU World
Telecommunication Standardization Assembly (WTSA) 2008 and WTDC-10 Resolution
55
69 encourage ITU Member States to create national CIRTs (ITU 2008). Typically, a
national CIRT is responsible for:
11.3.1
Providing incident response support to all relevant stakeholders via established,
trusted, authorised and centrally coordinated initiatives at the national level;
Dissemination of critical information such as early warnings and alert notifications,
security advisory, and upholding security best practices;
Acting as a single point of contact for cyber incident reporting and coordination;
Detecting and identifying anomalous activity;
Analysing cyber threats and disseminating cyber threat warning information;
Analysing and synthesizing incident and vulnerability information disseminated by
others such as vendors to provide an assessment for interested stakeholders;
Establishing trusted communications mechanisms and facilitating communications
among stakeholders to share information and address cyber security issues;
Developing mitigation and response strategies and coordinating incident response;
Sharing data and information about the incident and corresponding responses;
Determining trends and long-term remediation strategies;
Publicising best practices in incident response and prevention advice;
Coordinating international cooperation on cyber incidents; and
Building capacity in all the above areas using advanced technology and techniques,
establishing methods, and researching threat analyses and mitigations.
Protection Principles
ISO/IEC 27002:2005 regards incident management as about ensuring the effective and
timely communication of security events and weaknesses associated with information
systems. All employees, contractors and third party users must understand the
54
55
Obtain a copy of WTSA-08 Resolution 58 at http://www.itu.int/dms_pub/itu-t/opb/res/T-RES-T.58-2008-PDF-E.pdf
Obtain a copy of WTDC-10 Resolution 69 at http://www.itu.int/osg/csd/intgov/resoultions_2010/resolution69.pdf
64