A matter of when, not if. At some point you will face an cyber-security incident, or a security event that looks suspiciously like it. To contain, mitigate, and resolve the incident requires collaboration from everyone: resource providers, collaborations, users, and identity sources. The federated model of the AAI, in the AARC BPA as well as in eduGAIN more generally, means that many incidents touch all of these parties, and only by working together we can squash the incident. To do that effectively requires you have an incident response procedure that addresses your own security as well as the federation as a whole.

First response

Response plans

Every collaboration, infrastructure, and organisation is - to some extent - unique: who should be contacted, is an organisational security team available, what is the responsible chain of management. But the structure of incident response is mostly the same, regardless of the organisation. You should review the Security Incident Response Trust framework for Federated Identity (SIRTFI v2) and check whether you meet each of the basic steps. If you are in doubt about a requirement, that is a good place to start fixing it. Most common observation: lack of communication within your own organisation. This you can fix!

We provide a couple of examples from tried and tested infrastructures as well:

Well-known collaboration platform operators and security contacts

Resources