1 of 22

Slide Notes

DownloadGo Live

Incident response, the good, the bad and the ugly

Published on Nov 18, 2015

No Description

PRESENTATION OUTLINE

INCIDENT RESPONSE

The God, the Bad & the Ugly
Photo by peterned

CERT/CSIRT

Computer Security Incident Response Team

RFC 2350

  • Who/when/how to contact
  • Mission & Constituency
  • Policies & Procedures
  • Services & Reporting
Photo by ekkiPics

contact information

  • Telephone / Fax
  • timezone / work times
  • E-mail / Web-form
  • PGP
  • The Team

CONSTITUENCY

  • People/Entity wise
  • company, sector, country...
  • Technological/Network wise
  • ASN, TLD, IP range...

SERVICES

  • Reactive Serivces :
  • incident response/coordination
  • Proactive Services :
  • training, security audits/consultancy
  • ...

THE UGLY

why bother with security ?

Incidents in Luxembourg (CIRCL 2012)

Victims by sector (CIRCL 2012)

THE GOOD

Benefits of a CERT/CSIRT

  • Dedicated/specialised team
  • Centralised coordination (SPoC)
  • Legally sound evidence preservation
  • Keep track of technological devs
  • Be part of the community
Photo by carnagenyc

Untitled Slide

222 CERTS IN 42 COUNTRIES (Europe)

THE BAD

Lessons learned

  • CERT is not LE (you can't dictate)
  • stay technical / avoid politics
  • focus on expertise (NIS is people)
  • be proactive (don't wait for a call)
  • handle data EXTREMELY careful
Photo by Thomas Hawk

Untitled Slide

Untitled Slide

THANK YOU FOR your ATTENTIOn

Photo by kevin dooley