Skip to main content
Kent Academic Repository

Incident Response Practices Across National CSIRTs: Results from an Online Survey

Mohd Kassim, Sharifah Roziah Binti, Li, Shujun, Arief, Budi (2022) Incident Response Practices Across National CSIRTs: Results from an Online Survey. OIC-CERT Journal of Cyber Security, 4 (1). pp. 67-84. ISSN 2636-9680. E-ISSN 2682-9266. (KAR id:94119)

Abstract

The aim of this study is to obtain operational insights of real-world practices across national CSIRTs, concerning cyber incident reporting channels, ticketing tools, incident classification schemes, and ways to identify appropriate responses. An online survey involving 19 staff members of 17 national CSIRTs was conducted, leading to four major findings. First, multiple reporting channels are provided by national CSIRTs for prompt incident reporting. Second, free and open-source ticketing tools are popular among national CSIRTs for tracking reported incidents. Third, different incident classification schemes are used across national CSIRTs, indicating a lack of standardised approaches that can have important implications (for example, difficulties in cross-CSIRT information sharing). Fourth, for classifying incidents and identifying appropriate responses, manual approaches are used more than automated ones. We conclude that more cross-CSIRT efforts are needed to define a more standardised cyber incident classification scheme, and to develop more automated tools to support national CSIRTs' operations.

Item Type: Article
Uncontrolled keywords: CSIRT, computer security incident response team, national CSIRT, cyber incident, reporting channel, tick- eting tool, incident classification, survey.
Subjects: H Social Sciences > HD Industries. Land use. Labor > HD61 Risk Management
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > TK5101 Telecommunications > TK5105 Data transmission systems > TK5105.5 Computer networks > TK5105.875.I57 Internet
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Depositing User: Sharifah Binti-Mohd-Kassim
Date Deposited: 22 Apr 2022 13:56 UTC
Last Modified: 25 Apr 2022 09:13 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/94119 (The current URI for this page, for reference purposes)

University of Kent Author Information

Mohd Kassim, Sharifah Roziah Binti.

Creator's ORCID:
CReDIT Contributor Roles:

Li, Shujun.

Creator's ORCID: https://orcid.org/0000-0001-5628-7328
CReDIT Contributor Roles:

Arief, Budi.

Creator's ORCID: https://orcid.org/0000-0002-1830-1587
CReDIT Contributor Roles:
  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.