11.2.6 Stage 5 – Standards and Implementation Guides National focal points also help critical infrastructure owners, providers and vendors build capacity to defend systems and information. The organisation may issue technical implementation guides and best practice guides. The focal point may either perform this role or work with the national technical and information assurance organisations. 11.3 NATIONAL COMPUTER INCIDENT RESPONSE TEAM (CIRT) The growing sophistication, frequency and gravity of cyber threats necessitate formal 54 frameworks for watch, warning and incident response. Resolution 58 of the ITU World Telecommunication Standardization Assembly (WTSA) 2008 and WTDC-10 Resolution 55 69 encourage ITU Member States to create national CIRTs (ITU 2008). Typically, a national CIRT is responsible for: 11.3.1  Providing incident response support to all relevant stakeholders via established, trusted, authorised and centrally coordinated initiatives at the national level;  Dissemination of critical information such as early warnings and alert notifications, security advisory, and upholding security best practices;  Acting as a single point of contact for cyber incident reporting and coordination;  Detecting and identifying anomalous activity;  Analysing cyber threats and disseminating cyber threat warning information;  Analysing and synthesizing incident and vulnerability information disseminated by others such as vendors to provide an assessment for interested stakeholders;  Establishing trusted communications mechanisms and facilitating communications among stakeholders to share information and address cyber security issues;  Developing mitigation and response strategies and coordinating incident response;  Sharing data and information about the incident and corresponding responses;  Determining trends and long-term remediation strategies;  Publicising best practices in incident response and prevention advice;  Coordinating international cooperation on cyber incidents; and  Building capacity in all the above areas using advanced technology and techniques, establishing methods, and researching threat analyses and mitigations. Protection Principles ISO/IEC 27002:2005 regards incident management as about ensuring the effective and timely communication of security events and weaknesses associated with information systems. All employees, contractors and third party users must understand the 54 55 Obtain a copy of WTSA-08 Resolution 58 at http://www.itu.int/dms_pub/itu-t/opb/res/T-RES-T.58-2008-PDF-E.pdf Obtain a copy of WTDC-10 Resolution 69 at http://www.itu.int/osg/csd/intgov/resoultions_2010/resolution69.pdf 64

Select target paragraph3