Building CSIRT and its competency

17
Building Security Incident Response Team and Its Competency Didik Partono Rudiarto

Transcript of Building CSIRT and its competency

Page 1: Building CSIRT and its competency

Building Security Incident Response Team and

Its CompetencyDidik Partono Rudiarto

Page 2: Building CSIRT and its competency

Traditional Security No Longer Works

Page 3: Building CSIRT and its competency

TECHNOLOGY SKILLS

PERSONAL SKILLS

Page 4: Building CSIRT and its competency

Personal Skills

Page 5: Building CSIRT and its competency

Communication

Presentation Skill

Diplomacy

Ability to Follow Policies and Procedures

Team Skills

Integrity

Knowing One's Limits

Coping with Stress

Problem Solving

Time Management

Page 6: Building CSIRT and its competency

Technical Skills

Page 7: Building CSIRT and its competency

Technical Foundation

Page 8: Building CSIRT and its competency

Security Principles

Security Vulnerabilities/Weaknesses

Risk

Network Protocol

Network Application & Services

Network Security Issues

Host/System Security Issues

Malicious Code

Programming Skills

Page 9: Building CSIRT and its competency

Incident Handling

Page 10: Building CSIRT and its competency

Local Team Policies and Procedures

Understanding/Identifying Intruder Techniques

Communicating with Sites

Incident Analysis

Maintenance of Incident Records

Page 11: Building CSIRT and its competency

Skills & Competency Requirements

Page 12: Building CSIRT and its competency

FOUNDATION

INCIDENT HANDLING

FORENSIC

APPLICATION SECURITY

PENETRATION TESTING

NETWORK SECURITY

INTRUSION ANALYSIS

AUDIT& RISK

MANAGEMENT

SYSTEM ADMINISTRATION

MANAGEMENT LEGAL

Cyber Security Skills Framework

Page 13: Building CSIRT and its competency

IT Security Roadmap

IT FundamentalsIT Security

Fundamentals

Role-based Specialist

•Network Administrator

• IT Security Specialist

• IT Security Manager

0 – 1 YearsExperience

1 – 2 YearsExperience

> 3 Years Experience

Page 14: Building CSIRT and its competency

Standards

Page 15: Building CSIRT and its competency

Information Security CertificationORGANIZATION CERTIFICATION

CompTIA Security+

EC-Council CEH, CHFI, ECSA, ECSP, ENSA, LPT

GIAC GSIF, GSEC, GCIA, GCFW, GCFA, GCIH, GPEN, GCUX, GCWN, GWAPT, GAWN, GREM, GSE

ISACA CISA, CISM, CGEIT, CRISC

(ISC)2 CAP, CISSP, CSSLP, ISSAP, ISSEP, ISSMP, SSCP

ISECOM OPST, OPSA, OPSE, OWSE

Offensive Security OSCP, OSCE

Mile2 CPTE, CPT Consultant

CREST CREST Consultant

IACRB CPT, CEPT

eLearnSecurity eCPPT

Security Certified SCNS, SCNP, SCNA

Brainbench BITSF, BISA

CIW CWSA, CWSS, CWSP

CWNP CWTS, CWNA, CWSP

Cisco Systems CCNA Security, CCSP, CCIE Security

Symantec SCS

CheckPoint CCSA, CCSE, CCMSE, CCSEPE, CCMA

Microsoft MCSA Security

Page 16: Building CSIRT and its competency

Function vs Certification

Security Design andCompliance Skills

SpecializedSecurity Skills

NetworkSecurity Skills

Basic SecurityConcept

Foundation SecurityKnowledge

Vendor Specific

Vendor Neutral

InformationWorker

IT Worker

IT Admin

IT Manager

IT Executive

Career Level Required Skills Certifications

Page 17: Building CSIRT and its competency

THANK YOU