FIRST CSIRT Services Framework and Standards
FIRST: CSIRT Services Framework v2.1 - Foundational and Mandate

FIRST CSIRT Services Framework and Standards FIRST-CSIRTF-Mandate-Quality: CSIRT Services Framework v2.1 - Mandate, Scope and Quality Management

FIRST CSIRT Services Framework v2.1 (2019) Foundational. MANDATE + SCOPE: the CSIRT must have a CLEARLY DOCUMENTED MANDATE from its parent organisation (national authority + sector authority + corporate executive) defining: (a) AUTHORITY level (advisory + coordinating + commanding); (b) CONSTITUENCY (the user community served); (c) SERVICE AREAS provided (subset of the 5 in the framework); (d) DELIVERY MODEL (centralized + distributed + outsourced + hybrid); (e) FUNDING + STAFFING; (f) RELATIONSHIP with parent organisation + peer CSIRTs + national + international cooperation. The MANDATE is typically formalized in a CHARTER + Terms of Reference + Service Level Agreement. QUALITY MANAGEMENT + METRICS: CSIRTs operate quality management processes per CSIRT Maturity Models (e.g. SIM3 + CMMI-style); metrics include incident response time + customer satisfaction + service coverage + skills development + drill/exercise outcomes + peer-cooperation engagement; FIRST publishes SIM3 (Security Incident Management Maturity Model) v2 with self-assessment + auditor-assessment paths.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.