* Details on the differences between CERTs and CIRTs
endif; ?>One of my fellow instructors in the Master of Science in Information Assurance program at Norwich University recommended this paper by Staff Sergeant Cory Mazzola of the U.S. Air Force. Here is the second of two parts of his article.
Facets of the CIRT mission
While a CERT is typically a distinguished and unified team within a sizable organization, a CIRT does not always operate on such a grandiose scale. CIRTs come in many shapes and sizes, ranging from large departments to small informal groups. While a CERT is typically comprised of a dedicated team of full-time personnel, a CIRT may consist of a limited part-time staff or additional-duty employees who perform their CIRT duties outside of their regular job responsibilities, and often only in the event of an incident. In this sense, the CIRT operates at the section level, where a small-scale incident can be serviced by intra-office expertise and bypass enterprise intervention.
The CIRT function is ideal for remote locations that may be far from centralized computer support and response divisions. Possessing an on-site CIRT capability enables the detached organization to address and/or resolve internal security incidents in the place of CERT involvement, or until the CERT can properly intervene. Nevertheless, the presence of a CIRT provides the necessary liaison channels to direct and coordinate response and recovery actions.
The smaller-scale CIRT operation also works well for the small-business model, where the organization does not possess the manpower nor resources necessary to institute and fund a large-scale CERT. The ability of employees to fill primary job functions while performing incident response as a secondary duty, when necessary, enables an employer to reserve the capability until needed while retaining full mission manning and core operating base.
Numerous mid-range organizations often hire one or two full-time employees for the CIRT, while holding numerous trained staff members on retainer. The reserve members are available and ready to respond when an incident occurs, while performing their primary duties and job functions as usual. The administrative, manning, and training costs of building a capable and robust team can accumulate, but the safety and security of possessing such a capability pays dividends if, or when, its services are called upon.
The CERT’s larger mission
A CERT typically encompasses numerous facets of the security spectrum and is not solely dedicated to incident response. A legitimate CERT incorporates various information assurance disciplines within the team that may or may not be found within a limited CIRT – such as intrusion detection, vulnerability analysis, policy formulation, and enterprise oversight. The CERT typically employs active monitoring and defensive actions to oversee network and system security, ensuring perimeter protection and assuming system/network analysis capabilities. Additionally, the CERT works closely with associated and allied organizations, including other CERTs, to share information, identify vulnerabilities, analyze attack vectors and parameters, and combat apparent and emerging threats to the organization and information infrastructure.
Conclusion
The demanding daily mission and high-profile coordination conducted and demonstrated by numerous CERT organizations spans the globe and consolidates their position as global leaders in the computing security realm, and a necessary cog in the protection and preservation of the Internet and global information base. The services offered by the CERT are broad in scope and diverse in range, including around-the-click network surveillance and analysis, perimeter protection, enterprise security and response. The CIRT, on the other hand, often fills a niche placement within many smaller, mid-range, and decentralized organizations as an internal incident response force, providing on-site awareness, expertise, and recovery oversight. The CIRT performs only a small portion, if any, of the CERT’s immediate mission, often focusing heavily on incident response and mitigation processes. Both the CERT and CIRT, however, serve a necessary purpose in not only securing the information assets of the parent organization, but also protecting the high- and low-level functions of the national information infrastructure and global information grid.
In summary, maintaining a distinction between a CERT and a CIRT serves a useful function in our field and this usage should be maintained by professionals.




