Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Javascript is currently disabled for your browser. For an optimal search experience, please enable javascript.

Advanced Search

Basic Search

Content Type

Topics

Publication Date

Technical Report

State of the Practice of Computer Security Incident Response Teams (CSIRTs)

  • Abstract

    Keeping organizational information assets secure in today's interconnected computing environment is a challenge that becomes more difficult with each new product and each new intruder tool. There is no one solution for securing information assets; instead a multi-layered security strategy is required. One of the layers that many organizations are including in their strategy today is a computer security incident response team, or CSIRT. This report provides an objective study of the state of the practice of incident response, based on information about how CSIRTs around the world are operating. It covers CSIRT services, projects, processes, structures, and literature, as well as training, legal, and operational issues. The report can serve as a resource both to new teams that are setting up their operations and to existing CSIRTs that are interested in benchmarking their operations.

  • Download

Cite This Report

SEI

Killcrece, Georgia; Kossakowski, Klaus-Peter; Ruefle, Robin; & Zajicek, Mark. State of the Practice of Computer Security Incident Response Teams (CSIRTs) (CMU/SEI-2003-TR-001). Software Engineering Institute, Carnegie Mellon University, 2003. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6571

IEEE

Killcrece. Georgia, Kossakowski. Klaus-Peter, Ruefle. Robin, and Zajicek. Mark, "State of the Practice of Computer Security Incident Response Teams (CSIRTs)," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Report CMU/SEI-2003-TR-001, 2003. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6571

APA

Killcrece, Georgia., Kossakowski, Klaus-Peter., Ruefle, Robin., & Zajicek, Mark. (2003). State of the Practice of Computer Security Incident Response Teams (CSIRTs) (CMU/SEI-2003-TR-001). Retrieved December 26, 2014, from the Software Engineering Institute, Carnegie Mellon University website: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6571

CHI

Georgia Killcrece, Klaus-Peter Kossakowski, Robin Ruefle, & Mark Zajicek. State of the Practice of Computer Security Incident Response Teams (CSIRTs) (CMU/SEI-2003-TR-001). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2003. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6571

MLA

Killcrece, Georgia., Kossakowski, Klaus-Peter., Ruefle, Robin., & Zajicek, Mark. 2003. State of the Practice of Computer Security Incident Response Teams (CSIRTs) (Technical Report CMU/SEI-2003-TR-001). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6571