Content
How to use this guide
1
08
PLANNING
2
IMPLEMENTATION
Human Resource Selection
66
Management
68
Operations
68
Definition
12
CSIRT Action Areas
14
Research & Development
69
The Role of a National CSIRT
16
Information Technology
69
Stakeholders
17
Training
70
Establishment
28
Training in Cyber Security
72
Document of Establishment
29
72
Institutional Framework
34
Training in Cyber Security
Incident Response
Legal Framework
36
Forensics and Malware
Analysis Courses
73
Scope
38
IT Facilities and Infrastructure
74
Target Community
39
Services
41
CSIRT Facilities
75
Reactive Services
42
CSIRT Network Basic Design
77
Proactive Services
43
Suggested Basic Equipment
78
Value Added Services
44
Operational Policies and Procedures
80
Evolution of CSIRT Services
44
Mandatory Minimum Policies
81
Organization and HR
45
Other policies
81
Organizational Structures
of the Response Centers
46
Organization Size
47
Roles and Responsibilities
48
Organizational Structure
50
Size and Quantity of Resources
56
3
Timeline
58
Conclusion
of Preliminary Planning
62
CLOSURE
Formal Closure
85
ANNEXES
Sample Acceptable Use Policy
88
Disclosure Policy
90
Incident Response Forms
92
Works cited
103