Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Discuss ways organizations have built a csirt

26/12/2020 Client: saad24vbs Deadline: 7 Days

Module 6 Discussion Forum

Include at least 250 words in your posting and at least 250 words in your reply. Indicate at least one source or reference in your original post. Please see syllabus for details on submission requirements.


Module 6 Discussion Question

Search "scholar.google.com" or your textbook. Include at least 250 words in your reply. Indicate at least one source or reference in your original post. Discuss ways organizations have built a CSIRT. What are the components to building an effective and successful CSIRT team?




Reply-1(Vindhya)






In the building, an effective and successful CSIRT the steps involved are as follows:


1. Buy-In and support of management are obtained: the creation of an effective incident response team becomes problematic and difficult without the support of the management. The support includes time, funding, and provision of resources to the team (D. Penedo, 2006). The important responsibility and function of the CSIRTs are obtaining managements perceptions and expectations.


2. The strategic plan of CSIRT development is determined: by dealing with the administrative issues and addressing the project management issues the development of CSIRT is to be managed.


3. Relevant information is gathered: the service needs of the organization and to determine the incident response the information is gathered. In gathering the information the resources available are inventories of assets and critical system, for enterprise the organization charts and functions of specific business, networks, and systems organizational topologies, plans of business-continuity or existing disaster recovery, the physical security breach of organization is notified by existing guidelines, existing plans of incident-management, regulations of institution or parental, and existing security policies and procedures.


4. CSIRT vision is designed: The key components of the CSIRT are identified by bringing the gathered information to incident response constituency needs. For creating, CSIRT vision the points to be followed are (Z. Yunos, 2016): Constituency identification, the goals, objectives, and mission of CSIRT are defined, CSIRT services are selected and provided to the constituency, the organizational model is determined, required resources are identified, and CSIRT funding is determined.


5. The vision of CSIRT is communicated: the operational plan and vision are communicated to constituency, management, and others involved in the operation and feedbacks are obtained. Communicating vision before implementation helps in identification of problems.


6. CSIRT implementation begins: the steps involved in implementation are the CSIRT staff is hired and trained, in supporting team the necessary infrastructure is built and equipment are bought, the initial set of CSIRT procedures and policies are developed, the specifications of incident-tracking system are defined and the forms and guidelines of incident-reporting are developed for a constituency.


7. CSIRT announcement: broadly announce to constituency when CSIRT is operational also include the operation hours and contact information.


8. The effectiveness of CSIRT is evaluated: information on effectiveness is gathered by including against other CSIRTs the benchmark, with constituency representatives the general discussions involved, on a periodic basis the surveys of evaluation are distributed to members of the constituency, and in evaluating the team the quality parameters or set of criteria created by an audit.


References:


D. Penedo (2006), Optimal Policy for Software Vulnerability Disclosure. Good practice guide for CERTs in the area of Industrial Control Systems - Computer Emergency Response Capabilities considerations for ICS.


Z. Yunos (2016), Creating and Managing Computer Security Incident Handling Teams (CSIRTs), CERT Training and Education Networked Systems Survivability Software Engineering Institute Carnegie Mellon University.




Reply-2 ( Glad)






CSIRT (Computer Security Incident Response Team) is a team within an organization which responds to threats or incidents as they occur within the organization. Their responsibilities include,


- Maintaining and creating an incident response plan


- Identifying, troubleshoot and remediation of any incidents


- Communication methods for incident responses


- Combing the organization and proactively identifying and physical or network security threats.


- Recommending technologies, policy updates, governance updates based off the past threats


Keeping in mind the roles and responsibilities of this team, to build a team to perform these activities and own the responsibilities, the first step towards creating this team would be to buy management support to ensure they are in agreement with the creation of such a team and are on board to sign off on the resource allocation and budget as well as procedural aspects of building a CSIRT team.


The next step would be to create a strategic development plan on the various facets the team should possess and within which time frame team should be formed. The plan should be feasible and the timelines realistic and also care has to be taken to ensure the plan aligns with overall objectives of the organization.


After the strategic plan is developed, information should be gathered to ensure all aspects of the CSIRT team is covered based on the types of policies formulated, types of threats assessed and the services that are to be offered. The team will have to be picked based on the information at this stage.


Once the team is aligned and the vision is set, the vision of this team and its operations will have to be communicated within the organization to bring about an awareness on what this team could do.


Post the organizational wide announcement and policy implementation, the team goes live into operations and implements all the guidelines and procedures thereby serving the organization.


References:


Fuertes, W., Reyes, F., Valladares, P., Tapia, F., Toulkeridis, T., & Pérez, E. (2017). An Integral Model to Provide Reactive and Proactive Services in an Academic CSIRT Based on Business Intelligence. Systems, 5(4), 52. doi: 10.3390/systems5040052


Möller, K. (2007). Setting up a Grid‐CERT: experiences of an academic CSIRT. Campus-Wide Information Systems, 24(4), 260-270. doi: 10.1108/10650740710834644



Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Peter O.
University Coursework Help
Homework Guru
Top Essay Tutor
Helping Hand
Writer Writer Name Offer Chat
Peter O.

ONLINE

Peter O.

Hello, I can assist you in writing attractive and compelling content on ganja and its movement globally. I will provide with valuable, informative content that you will appreciate. The content will surely hit your target audience. I will provide you with the work that will be according to the needs of the targeted audience and Google’s requirement.

$105 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$112 Chat With Writer
Homework Guru

ONLINE

Homework Guru

Hi dear, I am ready to do your homework in a reasonable price and in a timely manner.

$112 Chat With Writer
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$115 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$110 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

Art during the 1920s - World Perspective Week 4 - Wild swans at coole - David christopher orthopedic surgeon case study - Maritime questions and answers - Imac 2014 wall mount - 4 phases of adlerian therapy - Eutectic point of naphthalene biphenyl system - What is an example of proximodistal development - The rock and kevin hart imitate each other - Cryptography and network security assignments - London transport museum friends - Identify the reducing agent in the chemical reaction 5fe2+ - Basic Biology - Writing Analysis - Socially conscience organization - Travis perkins cordless drills - Equivalent mass of an acid - 2002 general maths hsc answers - Baxley brothers has a dso of 23 days - Cross site request forgery - High country inc produces and sells many recreational products - Marketing analytics udacity - How to properly apply proactive - AVD Raj A - Planet research project rubric - Finance question - A wagner matinee full text - Adf ict service desk - What is the angular diameter of the sun - E Marketing-6 - Gbn gd live television - A pair of star crossed lovers take their life - Air force defence guard - Cane creek scr 5v - Eaton pad mounted transformers - Klein and moeschberger survival analysis solutions - North african pop music - NEED DONE BY WED - Shadow health focused exam abdominal pain objective - How davy crockett died - Bohrer cpa is considering the following factors - Bran nue dae context - Chelsea basketball stadium bonbeach - HR - Post and response - Do you Work in a Toxic Culture? - Explain the differences you saw between the two websites you observed in Wireshark. What were the differences you noticed when you did the trace? You should write about 250 words or more . - Organizational Analysis - Cloud Computing - Most sales presentations follow the aida sequence which stands for - Explain the stepwise approach to asthma treatment and management - Introduction to the financial management of healthcare organizations - Elan valley flooded village - Martinez company's relevant range of production - PC fundementals - In this Professional Reflectionyou will build on what you have learned and experienced to create a set of guiding principles to use as a manager. guiding principles will enable you to employ the appropriate management style for each situation at hand. - Blind spot hidden biases summary - What problems and challenges did home depot experience - Invitrogen zero blunt pcr cloning kit - Baking soda and vinegar limiting reactant lab - Slope of intersecting lines - Organizational behaviour and analysis an integrated approach pdf - Hatching chicken eggs worksheets - Read articles and answer questions - D2luwm - Firestone and ford case study - Inferential Statistics - How to write a teeal paragraph - Fire pump room size - Tea tree gully tennis club - What benefits do wikis provide to companies? - Spt roth ltd switzerland - Water by the spoonful full text - Cheque account commonwealth bank - Climate change persuasive speech outline - Limiting reagent balloon lab answers - Racv emergency home assist - Probability with a deck of cards worksheet answers - Uq vice chancellor scholarship - Shrike on a withered branch print - School age child observation examples - The new republic unit test - Specific heat capacity of polystyrene - What is the square root of 512 - Do my criminal justice homework - Martin luther king letter from birmingham jail essay - Hp 10bii financial calculator decimal places - Yeast air balloon experiment - Sociology - Econ 102 psu exam 1 - Willet creek golf course - T sql cheat sheet - Heterosexuality - Maple flock co ltd v universal furniture products - Which promotional activity will sell the most products - Post - Consumer health a guide to intelligent decisions 9th edition pdf - Mitsubishi heavy industries townsville - Discussion: Unit 3 - Operations Security. - York st john moodle - Neighborhood cellular white settlement texas