Creating a Computer Security Incident Response Team
This one-day workshop is designed for managers and project leaders
who have been tasked with implementing a computer security incident
response team (CSIRT). This workshop provides a high level overview of
the key issues and decisions that must be addressed in establishing a
CSIRT. As part of the workshop, attendees will develop an action plan
that can be used as a starting point in planning and implementing
their CSIRT.
The workshop is composed of lectures and class
exercises. Participants will learn the requirements for establishing
an effective CSIRT, the various organizational models for a CSIRT, and
the variety and level of services that can be provided by a
CSIRT. Additionally, attendees will identify policies and procedures
that should be established and implemented when creating a CSIRT.
Attendees may also want to register for the three-day companion
workshop, Managing Computer
Security Incident Response Teams.
Audience
- current and prospective CSIRT managers; C-level managers such as
CIOs, CSOs, CROs; and project leaders interested in establishing or
starting a CSIRT
- other staff who interact with CSIRTs and would like to gain a
deeper understanding of how CSIRTs operate. For example, CSIRT
constituents; higher-level management; media relations, legal counsel,
law enforcement, human resources, audit, or risk management staff
Prerequisites
There are no prerequisites for this workshop.
Topics
- incident management and the relationship to CSIRTs
- prerequisites to planning a CSIRT
- creating a CSIRT vision
- CSIRT mission, objectives, and level of authority
- CSIRT organizational issues and models
- range and levels of provided services
- funding issues
- hiring and training initial CSIRT staff
- implementing CSIRT policies and procedures
- requirements for a CSIRT infrastructure
- implementation and operational issues and strategies
- collaboration and communication issues
Objectives
This workshop will help participants to
- understand the requirements for establishing an effective
CSIRT
- strategically plan the development and implementation of a new
CSIRT
- highlight issues associated with assembling a responsive,
effective team of computer security professionals
- identify policies and procedures that should be established and
implemented
- understand various organizational models for a new CSIRT
- understand the variety and level of services that can be provided
by a CSIRT