Skip to content

Hide Navigation Hide TOC

Function: Information security status reporting (a1915495-7312-5fbb-a9c5-ecc15c4dc45e)

The function involves delivering concise and factual information about the current status of cyber security inside the constituency. As a crisis might be used to start other attacks or as occurring attacks might be part of the overall activities leading this crisis, it is very important for the crisis management team to establish complete situational awareness. The CSIRT can provide such situational awareness for its services and constituents. This may either be requested or is expected by standard policies in a time of crisis. In any case, as crisis management is only successful based on the established information flow as it depends on coordinate resources to address the most critical aspects of the crisis, reporting must be timely and accurate. As ongoing information security incidents will require resources to handle them, a decision must be taken to either discontinue the response for the duration of the incident (and allocate the now available resources to other areas) or to carry on. Reasonable decisions can only be taken based on the best situational awareness available.

Cluster A Galaxy A Cluster B Galaxy B Level
Service: Crisis management support (ee34661b-0cb2-5933-8f19-47d9a0d106fd) FIRST CSIRT Services Framework Function: Information security status reporting (a1915495-7312-5fbb-a9c5-ecc15c4dc45e) FIRST CSIRT Services Framework 1