Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. It is strongly recommended to use a dedicated email address for the security contact. Personal , personal email addresses are discouraged.
  2. You are encouraged to provide a URL pointing to your incident handling process if available.
  3. Where possible, use the NREN's security function (local CERT/CSIRT). We will also accept specific security capability for the federation service, if the organization has a proper procedure to deal with the communication.
  4. In case of federated security incident possibly related to eduGAIN entities, notify the [eduGAIN-CSIRT] as required by the eduGAIN Incident Security Response Handbook [eduGAIN-SIRH]. 
  5. Respond to requests for assistance with a security incident from the eduGAIN CSIRT or other eduGAIN Participants in a timely manner. The recommended response time is half business day.

  6. Respect the Traffic Light Protocol [TLP] information disclosure policy and use it during incident response communications (ref. https://www.first.org/tlp).

  7. The contact needs to expect that the eduGAIN CSIRT runs periodic communication checks which need to be handled as any other incident response communication.

TODO: add how to update the information (solicited and unsolicited).

[eduGAIN-CSIRT] https://edugain.org/edugain-security/

...