The Experts below are selected from a list of 1470 Experts worldwide ranked by ideXlab platform

Maria Bada - One of the best experts on this subject based on the ideXlab platform.

  • CyberSecurity Culture in Computer Security Incident Response Teams: Investigating difficulties in communication and coordination
    2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), 2019
    Co-Authors: Marios Ioannou, Eliana Stavrou, Maria Bada
    Abstract:

    This study aims to identify the factors related to developing a cyberSecurity culture at an organizational context and the difficulties faced in communicating and cooperating within a CSIRT. Specifically, our aim is to identify: 1) The issues which may limit the communication and the coordination of Incident management process inside a CSIRT, 2) the issues which may limit the cooperation from top management to employees and reverse and 3) approaches towards addressing the issues that limit the communication and the cooperation of a CSIRT. The research was conducted using an online survey and study participants were experts within the existing CSIRT community. In total, 25 participants responded to the questionnaire, from 23 different countries in the world. The questions of the survey queried the personal knowledge and experience of participants regarding CSIRTs. In our analysis, issues such as communication, cooperation, coordination, trust and information sharing are discussed as crucial factors that affect the development of a cyberSecurity culture. Several issues and weaknesses in terms of communication, coordination and cooperation within CSIRT are outlined and a set of recommendations and key elements are defined.

  • Cyber Security - CyberSecurity Culture in Computer Security Incident Response Teams: Investigating difficulties in communication and coordination
    2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), 2019
    Co-Authors: Marios Ioannou, Eliana Stavrou, Maria Bada
    Abstract:

    This study aims to identify the factors related to developing a cyberSecurity culture at an organizational context and the difficulties faced in communicating and cooperating within a CSIRT. Specifically, our aim is to identify: 1) The issues which may limit the communication and the coordination of Incident management process inside a CSIRT, 2) the issues which may limit the cooperation from top management to employees and reverse and 3) approaches towards addressing the issues that limit the communication and the cooperation of a CSIRT. The research was conducted using an online survey and study participants were experts within the existing CSIRT community. In total, 25 participants responded to the questionnaire, from 23 different countries in the world. The questions of the survey queried the personal knowledge and experience of participants regarding CSIRTs. In our analysis, issues such as communication, cooperation, coordination, trust and information sharing are discussed as crucial factors that affect the development of a cyberSecurity culture. Several issues and weaknesses in terms of communication, coordination and cooperation within CSIRT are outlined and a set of recommendations and key elements are defined.

  • Computer Security Incident response teams csirts an overview
    Social Science Research Network, 2014
    Co-Authors: Maria Bada, Sadie Creese, Michael Goldsmith, Chris Mitchell, Elizabeth Phillips
    Abstract:

    Following the pioneering work at Carnegie-Mellon University in the US, national Computer Emergency Response Teams (CERTs) have been established worldwide to try to address the ever-growing threats to information systems and their use. The problem they are designed to address is clearly real and formidable, in mitigating the threats posed by cyber-criminals and state-sponsored cyber-attacks. This paper is presenting the role and purpose of Computer Security Incident Response Teams (CSIRTs) the services they provide, and also various examples of existing national and multinational CSIRTs as well as organizations which foster the cooperation and coordination of CSIRTs are presented. The paper then presents case studies as examples of national CSIRTs.

Mark T. Zajicek - One of the best experts on this subject based on the ideXlab platform.

  • State of the Practice of Computer Security Incident Response Teams (CSIRTs)
    2018
    Co-Authors: Georgia Killcrece, Robin M. Ruefle, Klaus-peter Kossakowski, Mark T. Zajicek
    Abstract:

    Keeping organizational information assets secure in today's interconnected computing environment is a challenge that becomes more difficult with each new product and each new intruder tool. There is no one solution for securing information assets; instead a multi-layered Security strategy is required. One of the layers that many organizations are including in their strategy today is a Computer Security Incident response team, or CSIRT. This report provides an objective study of the state of the practice of Incident response, based on information about how CSIRTs around the world are operating. It covers CSIRT services, projects, processes, structures, and literature, as well as training, legal, and operational issues. The report can serve as a resource both to new teams that are setting up their operations and to existing CSIRTs that are interested in benchmarking their operations

  • Handbook for Computer Security Incident Response Teams (CSIRTs)
    2018
    Co-Authors: Moira West-brown, Robin M. Ruefle, Georgia Killcrece, Klaus-peter Kossakowski, Don Stikvoort, Mark T. Zajicek
    Abstract:

    This document provides guidance on forming and operating a Computer Security Incident response team (CSIRT). In particular, it helps an organization to define and document the nature and scope of a Computer Security Incident handling service, which is the core service of a CSIRT. The document explains the functions that make up the service; how those functions interrelate; and the tools, procedures, and roles necessary to implement the service. This document also describes how CSIRTs interact with other organizations and how to handle sensitive information. In addition, operational and technical issues are covered, such as equipment, Security, and staffing considerations. This document is intended to provide a valuable resource to both newly forming teams and existing teams whose services, policies, and procedures are not clearly defined or documented. The primary audience for this document is managers who are responsible for the creation or operation of a CSIRT or an Incident handling service. It can also be used as a reference for all CSIRT staff, higher level managers, and others who interact with a CSIRT

  • Defining Incident Management Processes for CSIRTs: A Work in Progress
    2018
    Co-Authors: Christopher J. Alberts, Robin M. Ruefle, Audrey J. Dorofee, Georgia Killcrece, Mark T. Zajicek
    Abstract:

    This report presents a prototype best practice model for performing Incident management processes and functions. It defines the model through five high-level Incident management processes: Prepare/Sustain/Improve, Protect Infrastructure, Detect Events, Triage Events, and Respond. Workflow diagrams and descriptions are provided for each of these processes. One advantage of the model is that it enables examination of Incident management processes that cross organizational boundaries, both internally and externally. This can help Computer Security Incident response teams (CSIRTs) improve their ability to collaborate with other business units and other organizations when responding to Incidents. Future reports will extend this work and provide additional guidance to enable both newly forming and existing Incident management capabilities to use the model to determine where gaps exist in their current processes and to develop plans for creating, improving, or restructuring their Incident management processes. Although the processes defined in this document were originally developed for internal CSIRTs, the models and information presented here are applicable to other types of CSIRTs and other types of Incident management and Security management capabilities

  • Defining Incident Management Processes for CSIRTs: A Work in Progress
    2004
    Co-Authors: Christopher J. Alberts, Robin M. Ruefle, Audrey J. Dorofee, Georgia Killcrece, Mark T. Zajicek
    Abstract:

    Abstract : This report presents a prototype best practice model for performing Incident management processes and functions. It defines the model through five high-level Incident management processes: Prepare/Sustain/Improve, Protect Infrastructure, Detect Events, Triage Events, and Respond. Workflow diagrams and descriptions are provided for each of these processes. One advantage of the model is that it enables examination of Incident management processes that cross organizational boundaries, both internally and externally. This can help Computer Security Incident response teams (CSIRTs) improve their ability to collaborate with other business units and other organizations when responding to Incidents. Future reports will extend this work and provide additional guidance to enable both newly forming and existing Incident management capabilities to use the model to determine where gaps exist in their current processes and to develop plans for creating, improving, or restructuring their Incident management capabilities and processes. Although the processes defined in this document were originally developed for internal CSIRTs, the models and information presented here are applicable to other types of CSIRTs and other types of Incident management and Security management capabilities.

  • Organizational Models for Computer Security Incident Response Teams (CSIRTs)
    2003
    Co-Authors: Georgia Killcrece, Robin M. Ruefle, Klaus-peter Kossakowski, Mark T. Zajicek
    Abstract:

    Abstract : When a Computer Security attack on an organization occurs, an intrusion is recognized, or some other kind of Computer Security Incident occurs, it is critical for the organization to have a fast and effective means of responding. One method of addressing this need is to establish a formal Incident response capability or a Computer Security Incident Response Team (CSIRT). When an Incident occurs, the goal of the CSIRT is to control and minimize any damage, preserve evidence, provide quick and efficient recovery, prevent similar future events, and gain insight into threats against the organization. This handbook describes different organizational models for implementing Incident handling capabilities, including each model's advantages and disadvantages and the kinds of Incident management services that best fit with it. An earlier SEI publication, the Handbook for Computer Security Incident Response Teams (CSIRTs) (CMU/SEI-2003-HB-002), provided the baselines for establishing Incident response capabilities. This new handbook builds on that coverage by enabling organizations to compare and evaluate CSIRT models. Based on this review they can then identify a model for implementation that addresses their needs and requirements.

Elizabeth Phillips - One of the best experts on this subject based on the ideXlab platform.

  • Computer Security Incident response teams csirts an overview
    Social Science Research Network, 2014
    Co-Authors: Maria Bada, Sadie Creese, Michael Goldsmith, Chris Mitchell, Elizabeth Phillips
    Abstract:

    Following the pioneering work at Carnegie-Mellon University in the US, national Computer Emergency Response Teams (CERTs) have been established worldwide to try to address the ever-growing threats to information systems and their use. The problem they are designed to address is clearly real and formidable, in mitigating the threats posed by cyber-criminals and state-sponsored cyber-attacks. This paper is presenting the role and purpose of Computer Security Incident Response Teams (CSIRTs) the services they provide, and also various examples of existing national and multinational CSIRTs as well as organizations which foster the cooperation and coordination of CSIRTs are presented. The paper then presents case studies as examples of national CSIRTs.

Reinhardt A. Botha - One of the best experts on this subject based on the ideXlab platform.

  • a management model for building a Computer Security Incident response capability
    SAIEE Africa Research Journal, 2016
    Co-Authors: Roderick Mooi, Reinhardt A. Botha
    Abstract:

    Although there are numerous guides available for establishing a Computer Security Incident response capability, there appears to be no underlying management model that brings them all together. This paper aims to address the problem by developing a management model for establishing a Computer Security Incident Response Team (CSIRT). A design science-based approach has been selected for the overall project. However, the current paper reports on the first three activities in design science research: identifying the problem, listing solution objectives, and designing and developing a model. A comprehensive literature review serves two purposes: to confirm the problem and to provide a structured way of revealing the requirement areas. Following the uncovering of the requirement areas, CSIRT business requirements and services are introduced, before exploring the relationships between the areas using argumentation. This culminates in the development of the management model in two parts: a strategic view and a tactical view. The strategic view comprises the business requirements and “higher” level decisions – the environment, constituency and funding considerations – that need to be made when establishing a CSIRT. The tactical view follows by presenting the “how” considerations. Together, these two views provide an holistic model for establishing a CSIRT by parties interested in doing so.

  • Context for the SA NREN Computer Security Incident Response Team
    2016 IST-Africa Week Conference, 2016
    Co-Authors: Roderick Mooi, Reinhardt A. Botha
    Abstract:

    The South African (SA) National Research and Education Network (NREN) identified the requirement for a Computer Security Incident Response Team (CSIRT). This paper sets the context for the CSIRT by exploring the business requirements and associated decisions in five areas: the environment, constituency, authority, funding and legal considerations. The SA NREN CSIRT was categorised as an academic sector CSIRT serving the research and education community of South Africa with limited authority. The NREN is comprised of two organisations and the corresponding embedded, but distributed, organisational model makes this CSIRT case particularly interesting. Various cost recovery options and relevant South African laws and regulations were also identified. The resulting “strategic” framework sets the scene for the remainder of the establishment process. This paper is useful to anyone desiring to establish a CSIRT, or equivalent capability, who can follow a similar process to discover where to begin.

  • prerequisites for building a Computer Security Incident response capability
    Information Security for South Africa, 2015
    Co-Authors: Roderick Mooi, Reinhardt A. Botha
    Abstract:

    There are a number of considerations before one can commence with establishing a Computer Security Incident Response Team (CSIRT). This paper presents the results of a structured literature review investigating the business requirements for establishing a CSIRT. That is, the paper identifies those things that must be in place prior to commencing with the actual establishment process. These include characterising the CSIRT environment, funding, constituency, authority and legal considerations. Firstly, we identified authoritative CSIRT literature. Thereafter we identified salient aspects using a concept matrix. The study enumerates five areas of primary business requirements. Finally, a holistic view of the business requirements is provided by summarising the decisions required in each area.

  • ISSA - Prerequisites for building a Computer Security Incident Response capability
    2015 Information Security for South Africa (ISSA), 2015
    Co-Authors: Roderick Mooi, Reinhardt A. Botha
    Abstract:

    There are a number of considerations before one can commence with establishing a Computer Security Incident Response Team (CSIRT). This paper presents the results of a structured literature review investigating the business requirements for establishing a CSIRT. That is, the paper identifies those things that must be in place prior to commencing with the actual establishment process. These include characterising the CSIRT environment, funding, constituency, authority and legal considerations. Firstly, we identified authoritative CSIRT literature. Thereafter we identified salient aspects using a concept matrix. The study enumerates five areas of primary business requirements. Finally, a holistic view of the business requirements is provided by summarising the decisions required in each area.

Heather Young - One of the best experts on this subject based on the ideXlab platform.

  • Computer Security Incident Response Team Effectiveness: A Needs Assessment.
    Frontiers in psychology, 2017
    Co-Authors: Rick Van Der Kleij, Geert Kleinhuis, Heather Young
    Abstract:

    Computer Security Incident response teams (CSIRTs) respond to a Computer Security Incident when the need arises. Failure of these teams can have far-reaching effects for the economy and national Security. CSIRTs often have to work on an ad-hoc basis, in close cooperation with other teams, and in time constrained environments. It could be argued that under these working conditions CSIRTs would be likely to encounter problems. A needs assessment was done to see to which extent this argument holds true. We constructed an Incident response needs model to assist in identifying areas that require improvement. We envisioned a model consisting of four assessment categories: Organization, Team, Individual and Instrumental. Central to this is the idea that both problems and needs can have an organizational, team, individual, or technical origin or a combination of these levels. To gather data we conducted a literature review. This resulted in an comprehensive list of challenges and needs that could hinder or improve respectively the performance of CSIRTs. Then, semi-structured in depth interviews were held with team coordinators and team members of five public and private sector Dutch CSIRTs to ground these findings in practice and to identify gaps between current and desired Incident handling practices. This paper presents the findings of our needs assessment and ends with a discussion of potential solutions to problems with performance in Incident response.