詳細検索

Introduction to CSIRT for Small and Medium-sized Enterprises|Incident response system starting with minimal configuration

Avatar
by 菊池
3 min read

Introduction to CSIRT for Small and Medium-sized Enterprises|Incident response system starting with minimal configuration
Translated from 日本語 • View original
菊池
菊池

Hello, I'm Kikuchi, an analyst at Colorkrew Security. The risk of cyberattacks is increasing year by year not only for large companies but also for small and medium-sized enterprises. However, the reality is that there are many voices saying that there are not enough people and time, or that a dedicated team cannot be created. Here are the minimum configurations of CSIRT that even small businesses can start without difficulty.

First You Need to Understand: The Purpose of CSIRT

The Computer Security Incident Response Team (CSIRT) is a
"An organization that prepares for and responds to security incidents to protect its information assets."

In other words, the purpose is not to have a professional "security team",
The essence is not to panic in the event of an incident and to have a system in place to minimize damage.


CSIRT Model with Minimum Configuration

In the case of small and medium-sized enterprises, it is realistic to focus on the following three roles.

Roles Key Responsibilities Example of a person in charge
**CSIRT Leader ** Organization-wide policy decisions, external contact (business partners, police, JPCERT, etc.) Head of Information Systems, CISO Equivalent
**Incident Handler ** Detection, Initial Response, Containment, and Recovery In-house SE, SOC Representative, Outsourced Vendor
Communications Internal Communications, Management Reports, and Public Relations Administrative Departments, General Affairs, Human Resources, etc.

💡 It is OK for one person to play multiple roles at the same time. The important thing is that
It is clear who will respond to what, when, and how.


Actively Leverage External Links

If there is a shortage of manpower and expertise, the following external collaborations are effective.

  • SOC service/MDR service: outsourcing monitoring and primary response
  • Collaboration with vendor CSIRT: Sharing information on product incidents
  • Reporting and consultation to JPCERT/CC/IPA: Official contact point in Japan
  • MS&AD Interrisk Research Institute, ISAC organizations, etc.: Cross-industry information sharing

With the help of external forces, aim for the smallest unit within your company that can make decisions and initial decisions.


Three Elements to Maintain First

The following three points should be at least in place at the beginning of the launch of CSIRT.

  1. Contact system: Who and how to contact in an emergency (internal/external)
  2. Response Procedure (Incident Handbook): Initial Response, Containment, and Reporting Flow
  3. Logging and monitoring system: Basics for detection (MDE, Firewall, email monitoring, etc.)

Just having these things will make you a big step forward from the state of "nothing is decided".


Start Small, Grow Little by Little

CSIRT is not a "make it once, it's over", but a team that nurtures.

  • Conduct incident response drills even once a year
  • Regularize information sharing (IPA and JPCERT alerts)
  • Gradually improve logs and detection rules

This repetition leads to effective CSIRT.


Conclusion

Points Contents
Purpose Create a system that can respond without panic in the event of an incident
Minimum Configuration Three-role system of responsible person, responder, and liaison
External Collaboration Actively Utilizing SOC and JPCERT
Step 1 Start by developing a procedure manual and communication system

Rather than aiming for a "perfect CSIRT", create a "CSIRT that works even at the minimum".
While gaining actual handling experience, let's mature it into a form that suits the organization.

If you have any problems with CSIRT configuration, please feel free to contact Colorkrew Security!

Related Articles