First You Need to Understand: The Purpose of CSIRT
The Computer Security Incident Response Team (CSIRT) is a
"An organization that prepares for and responds to security incidents to protect its information assets."
In other words, the purpose is not to have a professional "security team",
The essence is not to panic in the event of an incident and to have a system in place to minimize damage.
CSIRT Model with Minimum Configuration
In the case of small and medium-sized enterprises, it is realistic to focus on the following three roles.
| Roles | Key Responsibilities | Example of a person in charge |
|---|---|---|
| **CSIRT Leader | ** Organization-wide policy decisions, external contact (business partners, police, JPCERT, etc.) | Head of Information Systems, CISO Equivalent |
| **Incident Handler | ** Detection, Initial Response, Containment, and Recovery | In-house SE, SOC Representative, Outsourced Vendor |
| Communications | Internal Communications, Management Reports, and Public Relations | Administrative Departments, General Affairs, Human Resources, etc. |
💡 It is OK for one person to play multiple roles at the same time. The important thing is that
It is clear who will respond to what, when, and how.
Actively Leverage External Links
If there is a shortage of manpower and expertise, the following external collaborations are effective.
- SOC service/MDR service: outsourcing monitoring and primary response
- Collaboration with vendor CSIRT: Sharing information on product incidents
- Reporting and consultation to JPCERT/CC/IPA: Official contact point in Japan
- MS&AD Interrisk Research Institute, ISAC organizations, etc.: Cross-industry information sharing
With the help of external forces, aim for the smallest unit within your company that can make decisions and initial decisions.
Three Elements to Maintain First
The following three points should be at least in place at the beginning of the launch of CSIRT.
- Contact system: Who and how to contact in an emergency (internal/external)
- Response Procedure (Incident Handbook): Initial Response, Containment, and Reporting Flow
- Logging and monitoring system: Basics for detection (MDE, Firewall, email monitoring, etc.)
Just having these things will make you a big step forward from the state of "nothing is decided".
Start Small, Grow Little by Little
CSIRT is not a "make it once, it's over", but a team that nurtures.
- Conduct incident response drills even once a year
- Regularize information sharing (IPA and JPCERT alerts)
- Gradually improve logs and detection rules
This repetition leads to effective CSIRT.
Conclusion
| Points | Contents |
|---|---|
| Purpose | Create a system that can respond without panic in the event of an incident |
| Minimum Configuration | Three-role system of responsible person, responder, and liaison |
| External Collaboration | Actively Utilizing SOC and JPCERT |
| Step 1 | Start by developing a procedure manual and communication system |
Rather than aiming for a "perfect CSIRT", create a "CSIRT that works even at the minimum".
While gaining actual handling experience, let's mature it into a form that suits the organization.
If you have any problems with CSIRT configuration, please feel free to contact Colorkrew Security!