Resources for Creating a CSIRT
• Collection
Publisher
Software Engineering Institute
Abstract
To establish a computer security incident response team (CSIRT), you should understand what type of CSIRT is needed, the type of services that should be offered, the size of the CSIRT and where it should be located in the organization, how much it will cost to implement and support the CSIRT team, and the initial steps necessary to create the CSIRT. The resources on this page will help you answer these and other questions.
Collection Items

Organizational Models for Computer Security Incident Response Teams (CSIRTs)
• Handbook
By Georgia Killcrece, Klaus-Peter Kossakowski, Robin Ruefle, Mark Zajicek
This 2003 report describes different organizational models for implementing incident handling capabilities, including each model's advantages and disadvantages and the kinds of incident management services that best fit with it.
Read
Incident Management
• White Paper
By Georgia Killcrece
In this paper, the author describes incident management capability and what it implies for controlling security events and incidents.
Read
Build Security In
• Article
By DHS
This article lists resources that developers, architects, and security practitioners can use to build security into software during its development.
Read
Columbia CSIRT Case Study
• White Paper
By Software Engineering Institute
This case study describes the experiences of the Columbia CSIRT in getting its organization up and running.
Read
FAQ: Collaboration Between the CERT Coordination Center and Computer Security Incident Response Teams Worldwide
• Brochure
By Software Engineering Institute
This FAQ answers questions related to the collaboration between the CERT/CC and CSIRTs worldwide.
Learn More
Tunisia Case Study
• White Paper
By Software Engineering Institute
This case study describes the experiences of the Tunisia CSIRT in getting its organization up and running.
Read
Financial Institution CSIRT Case Study
• White Paper
By Software Engineering Institute
This case study describes the experiences of a financial institution CSIRT in getting its organization up and running.
Read
Guidelines for Use of “CERT”
• Brochure
By Software Engineering Institute
These guidelines for using “CERT” help to protect and strengthen the use of the word by everyone.
Learn MorePart of a Collection
CSIRT Resources