Content How to use this guide 1 08 PLANNING 2 IMPLEMENTATION Human Resource Selection 66 Management 68 Operations 68 Definition 12 CSIRT Action Areas 14 Research & Development 69 The Role of a National CSIRT 16 Information Technology 69 Stakeholders 17 Training 70 Establishment 28 Training in Cyber Security 72 Document of Establishment 29 72 Institutional Framework 34 Training in Cyber Security Incident Response Legal Framework 36 Forensics and Malware Analysis Courses 73 Scope 38 IT Facilities and Infrastructure 74 Target Community 39 Services 41 CSIRT Facilities 75 Reactive Services 42 CSIRT Network Basic Design 77 Proactive Services 43 Suggested Basic Equipment 78 Value Added Services 44 Operational Policies and Procedures 80 Evolution of CSIRT Services 44 Mandatory Minimum Policies 81 Organization and HR 45 Other policies 81 Organizational Structures of the Response Centers 46 Organization Size 47 Roles and Responsibilities 48 Organizational Structure 50 Size and Quantity of Resources 56 3 Timeline 58 Conclusion of Preliminary Planning 62 CLOSURE Formal Closure 85 ANNEXES Sample Acceptable Use Policy 88 Disclosure Policy 90 Incident Response Forms 92 Works cited 103

Select target paragraph3