**1. What is CSIRT? **
The Computer Security Incident Response Team (CSIRT) is a
This is a specialized team that responds to "information security incidents within the company and the entire organization".
Key Roles:
- Respond to cyberattacks, malware infections, etc.
- Monitor threats to internal systems and networks
- Investigate the cause of an incident, identify the scope of impact, and respond to recovery
- Drawing attention to internal alerts and formulating measures to prevent recurrence
**2. What is PSIRT? **
The Product Security Incident Response Team (PSIRT) is a
This is a specialized team that responds to "vulnerabilities and security issues related to our products and services".
Key Roles:
- Responding to vulnerabilities found in our products (including zero-day)
- Respond to reports from security vendors and researchers
- Disclosure of CVE numbering and vulnerability information (issuance of advisories)
- Software patch provision and user notification
3. Summary of the differences between CSIRT and PSIRT
Coverage
- CSIRT: Overall internal infrastructure and information systems
- PSIRT: Products and services provided by the company
Main Responses
- CSIRT: Attack Detection, Containment, Recovery, and Recurrence Prevention
- PSIRT: Vulnerability analysis, fix, external disclosure, and customer notification
Involved
- CSIRT: Internal IT & Security Department, Employees
- PSIRT: Product Development, Support Team, Security Researcher
Timeline
- CSIRT: Real-time response with an emphasis on immediacy
- PSIRT: Reporting → Evaluation → Fixing → Publishing and Phased Response
Example guidelines
- CSIRT: NISC CSIRT Guidelines, FIRST
- PSIRT:ISO/IEC 30111、CVD(Coordinated Vulnerability Disclosure)
4. Common misconceptions and precautions
- It's not just about "one or the other"
→ Companies that develop products need to establish both CSIRT and PSIRT systems . - "CSIRT also does PSIRT" is prone to inefficiency.
→ Since the technical areas and targets are different, the division of roles is important.
5. Summary: Divide roles correctly to build a strong security posture CSIRT is a team that "protects the organization"
- Focus on incident response and network monitoring
PSIRT is a team that "protects products"
- Focus on vulnerability response, information disclosure, and user response
Cooperation between the two is also important
- Collaboration is necessary because there are cases where product vulnerabilities cause internal damage.
Colorkrew also offers consultations on CSIRT support and operational improvement support.
"What do I need?" "Where do I start?" If you have any concerns, please feel free to contact us!