This is version 0.1, draft 2021/07/14
Notifications of updates are submitted to the eduGAIN Steering Group mailing list edugain-sg@lists.geant.org. The eduGAIN Steering Group mailing list is composed by all the delegates and deputies of the eduGAIN participants, the subscription is managed by the eduGAIN Service. The mailing list is not moderated.
The current version of this CSIRT description document is available from the eduGAIN CSIRT WWW site; its URL is <URL OF THE .txt VERSION OF THE RFC>
Please make sure you are using the latest version.
This document has been signed with the eduGAIN-CSIRTs PGP key. The signatures are also on our Web site, under: <URL OF OUR TEAM_KEY.asc>
eduGAIN-CSIRT: The eduGAIN Computer Security Incident Response Team.
eduGAIN-CSIRT
PROBABLY THE GEANT
POSTAL ADDRESS
Europe/Amsterdam (GMT+0100, and GMT+0200 from April to October
+31 12345679 (SOME GEAN OFFICE NUMBER, where the Opertor at least knows what to do when contacted on security issues related to eduGAIN)
+31 12345679 (SOME GEANT OFFICE FAX NUMBER, where the Opertor at least knows what to do when contacted on security issues related to eduGAIN)
OTHER METHODS MONITORED BY THE eduGAIN CSIRT (keybase? slackchannel?)
abuse@edugain.org This is a mail alias that relays mail
to the human(s) on duty for the eduGAIN-CSIRT.
The eduGAIN-CSIRT has a PGP key, whose KeyID is CE43BCB8 and whose fingerprint is
F9FF B82B 9700 72D1 F753 25CF 5E3C 31D7 CE43 BCB8.
The key and its signatures can be found at the usual large public keyservers.
eduGAIN-CSIRT is coordinated by the eduGAIN-CSIRT security officer. Other team members along with their contact information are listed at the eduGAIN-CSIRT web page: <eduGAIN-CSIRT.WEBPAGE.ORG>
General information about the XYZ-CERT, as well as links to various recommended security resources, can be found at
<eduGAIN-CSIRT.WEBPAGE.ORG>
NOTE: WE NEED TO DISCUS IF WE WANT OT RUN SUCH A PAGE
The eduGAIN-CSIRTs hours of operation are generally restricted to regular business hours (09:00-17:00 (CET/CEST) Monday to Friday except holidays).
The eduGAIN-CSIRT provides security incident coordination for eduGAIN and is the primary contact point for questions related to security issues affecting eduGAIN participants. Therefore eduGAIN-CSIRT operates and maintains a communications infrastructure and provides forensics support on request to end entities in coordination with the respective federations.
The eduGAIN constituency is the eduGAIN participants.
eduGAIN is abc... the role of federations in eduGAIN goes here probably as well
eduGAIN-CSIRT is authorized by the eduGAIN Steering Group to investigate any activity within its Terms of Reference and, in coordination with the federations, take all necessary controlling actions to contain and mitigate suspected and confirmed computer incidents to limit the extend of possible service degradation or reputation damage to eduGAIN.
we do not really have an extended set of policies
federations and comm flows go here, also comms to eSG
TLP adherence and optional encrypted comms go here
This the service a CSIRT has to provide
- Investigating whether indeed an incident occured. - Determining the extent of the incident. Single entity, or multiple federations affected.
We can't do much here I'm afraid
Link to possible incident-report templates
While every precaution will be taken in the preparation of information, notifications and alerts, XYZ-CERT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.