How to use this guide
This guide analyzes several types of CSIRTs, including National-level CSIRTs, which
respond to incidents at the nation-state level. These usually monitor and respond
to incidents in government networks, and also serve as a coordinator of information security for the private sector or other sectors and institutions. They may or
may not provide incident response services to the private sector or end users.
All things CSIRT-related, much like information security in and of itself, require a
broad understanding of a number of different disciplines aside from networking or
computing. They involve such additional considerations as human resource management, legal processes, financial planning, procurement, and many others. Project oversight and management are particularly important in CSIRT creation and deployment as they need to work in a structured, phased, and strategic manner during
planning phases, which necessitates collaboration among diverse stakeholders.
In essence, this is a support guide on managing a project for the creation of a National CSIRT. It is specifically directed to the project manager to use as an aid and
reference throughout the implementation process. It is divided into 3 main sections: Planning, Implementation and Closure, and describes the principal objectives
and outcomes of each phase and present supporting materials for the process.
Nevertheless, as is shown in each chapter, project managers must create a multidisciplinary team to assist throughout the process where specialization is needed.
Each country has a different political structure, culture, geography, legal framework and resources. As such, this guide is not meant to serve as a definitive template, but is meant to be adapted to local conditions, where necessary.
8
9