Storming Media: Pentagon Reports and DocumentsPentagon Reports: Fast. Definitive. Complete.     
New Account »
Forgot Password?
Advanced Search »
ManagementAdministration and Management

Best Practices for National Cyber Security: Building a National Computer Security Incident Management Capability, Version 2.0

Authors: John Haller; Samuel A Merrell; Matthew J Butkovic; Bradford J Willke; CARNEGIE-MELLON UNIV PITTSBURGH PA SOFTWARE ENGINEERING INST
Abstract:
As nations recognize that their critical infrastructures have integrated sophisticated information and communications technologies (ICT) to provide greater efficiency and reliability, they quickly realize the need to effectively manage risk arising from the use of these technologies. Establishing a national computer security incident management capability can be an important step in managing that risk. In this document, this capability is referred to as a National CSIRT, although the specific organizational form may vary among nations. Nations face various challenges when working to strengthen incident management, such as the lack of information providing guidance for establishing a national capability, determining how this capability can support national cyber security, and managing the national incident management capability. This document, first in the Best Practices for National Cyber Security series, provides information that interested organizations and governments can use to develop a national incident management capability. The document explains the need for national incident management and provides strategic goals, enabling goals, and additional resources pertaining to the establishment of National CSIRTs and organizations like them.

Limitations: APPROVED FOR PUBLIC RELEASE
Description: Technical rept.
Pages: 40
Report Date: Apr 2011
Contract Number: FA8721-05-C-0003
Report Number: A993945
Keywords relating to this report:
CASE STUDIES
COMMUNICATIONS NETWORKS
COMPUTER NETWORKS
COMPUTER SECURITY
CRISIS MANAGEMENT
HANDBOOKS
INFORMATION SYSTEMS
INFRASTRUCTURE
INTEGRATED SYSTEMS
MANAGEMENT PLANNING AND CONTROL
NATIONAL SECURITY
POLICIES
PROTECTION
RISK MANAGEMENT
Email This Abstract