• DocumentCode
    3696331
  • Title

    Prerequisites for building a Computer Security Incident Response capability

  • Author

    Roderick Mooi;Reinhardt A. Botha

  • Author_Institution
    Meraka Institute, Council for Scientific and Industrial Research, South Africa
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    There are a number of considerations before one can commence with establishing a Computer Security Incident Response Team (CSIRT). This paper presents the results of a structured literature review investigating the business requirements for establishing a CSIRT. That is, the paper identifies those things that must be in place prior to commencing with the actual establishment process. These include characterising the CSIRT environment, funding, constituency, authority and legal considerations. Firstly, we identified authoritative CSIRT literature. Thereafter we identified salient aspects using a concept matrix. The study enumerates five areas of primary business requirements. Finally, a holistic view of the business requirements is provided by summarising the decisions required in each area.
  • Keywords
    "Information security","NIST","Computer crime","Buildings"
  • Publisher
    ieee
  • Conference_Titel
    Information Security for South Africa (ISSA), 2015
  • Type

    conf

  • DOI
    10.1109/ISSA.2015.7335057
  • Filename
    7335057