1 PLANNING Definition A What is a CSIRT? Traditionally, a CSIRT is defined as a team or an entity within an agency that provides services and support to a particular group1 (target community) in order to prevent, manage and respond to information security incidents. These teams are usually comprised of multidisciplinary specialists who act according to predefined procedures and policies in order to respond quickly and effectively to security incidents and to mitigate the risk of cyberattacks. Over time, the concept of the Computer Security Incident Response Team evolved to meet the growing services required by the target community. While early teams provided basic services to respond to basic attacks and incidents, more recently, some CSIRTs have tried to keep pace with larger and more nebulous adversaries by offering advice in risk analysis, business continuity plans, malware analysis, and many other areas. When expanding CSIRT services, the European Union Agency for Network and Information Security (ENISA)2 recommends including forensic analysis and vulnerability management. Again, the level and type of services offered will differ based on who the CSIRT serves and what its mandates are. Teams that arose primarily to respond to incidents have evolved and are now frequently oriented to a comprehensive model of information security management. Indeed, whereas the purview of CSIRTs was largely confined to “response” services, today they increasingly adopt a proactive stance, focusing on incident prevention and detection, achieve through a mix of skills and awareness training, alerts and monitoring, dissemination of information related to information security, development of business continuity plans, development of best practices documents and vulnerability analysis, among others. 12 A B C D 13

Select target paragraph3