Wiik, Johannes with Jose Gonzalez, Pål Davidsen and Klaus-Peter Kossakowski, "Preserving a balanced CSIRT constituency", 2009 July 26-2009 July 30

ua435

Since their inception Computer Security Incident Response Teams (CSIRTs) have been afflicted by chronic problems concerning workload, QoS and sustaining their constituency. We have cooperated with one of the oldest CSIRTs to model the most challenging issues. Low- and high-priority incident response cause different problems. In companion papers we dealt with the impact of the exponential growth of low-priority incidents on the CSIRT workload and the effect of high-priority incident response on the CSIRT workload and QoS. Here, we focus on a severe consequence of instabilities in high-priority incident response: problems to retain the internal constituency, i.e, the customer base or community who by its funding enable the existence of the CSIRT. Such an external constituency (people and organizations outside the internal constituency) that are provided with limited services, is unavoidable and even desirable, since security incidents often involve sites outside the internal constituency. But our model indicates that the instabilities in high-priority incident reporting create an imbalance that -- if it persists -- could threaten the very existence of the CSIRT. Our model suggests that a management strategy that reduces the turnover of the most frequent reporters is much better than any attempt to attract a higher number of frequent reporters.

This is the whole item.

Date created
  • 2009 July 26-2009 July 30
Type
Processing Activity License

ITEM CONTEXT

Part of

4818cb531cdd68d6ec6af3f291216fc7

Scope and Contents
Part of

b3584c6b53c3f58e0202549d7d851f84

Scope and Contents
Part of

23d738ba88f8333bc39725f9cb5bd0b8

Scope and Contents
Collection

System Dynamic Society Records

Scope and Contents
Collecting area

Itens