FRAMEWORK FOR ESTABLISHING AN INTER-AMERICAN CSIRT WATCH & WARNING NETWORK (Presented by Ambassador Margarita Escobar, Chair of the Working Group of the OAS Committee on Hemispheric Security of the OAS, held on January 29, 2004, during the Third Plenary Session) Objective: To develop a hemisphere-wide 24-hour per day, seven day per week network of national points of contact among Computer Security Incident Response Teams (CSIRTs) with national responsibility (National CSIRTs), in OAS member states, capable of and charged with appropriately and rapidly responding to cyber-security related crises, incidents, and threats. As intruders use increasingly sophisticated attack tools, launch highly automated attacks that travel at Internet speed, and intentionally use attack techniques that make it difficult to understand the nature and source of the attacks, global, real-time collaboration across response teams will become increasingly important. This collaboration would: • • • • • • support rapid and accurate diagnosis of a problem; rapidly disseminate warnings of actual attacks across the global community; rapidly disseminate warnings of generic vulnerabilities across the global community; alert the global community to suspicious activity and support collaborations that investigate and diagnose the activity; provide information on mitigation and remediation strategies to combat attacks and threats; and minimize duplication of analysis effort across teams. Collaboration helps to leverage the technical knowledge that exists across the teams to limit damage and ensure continued operation of critical services. Principles: Indigenous – The program must be operated and controlled by entities rooted in each participating nation, designated by their government. Systemic – The system must be a multi-faceted operation requiring an aware and trained workforce, regular sharing of information regarding current threats and vulnerabilities, constant re-evaluating and implementing of best practices and appropriate interaction with public policy makers. On-going - due to the inherent daily evolution of the Internet, any successful program must regularly be updated and maintained. Internet security will not be achieved with a one-time fix. Accountable – The “security” in “cyber security”. Strict rules with respect to issues such as the handling of information must be understood and adhered to, or users will lose confidence and efforts to make the system more secure will be undermined and become counter-productive. Built upon existing arrangements – There are a number of pre-existing entities in the hemisphere that provide cyber-security services to a greater or lesser extent. Any new system should build upon these pre-existing institutions to avoid duplication and encourage active participation.

Select target paragraph3