home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!noc.near.net!hri.com!ukma!nsisrv!nssdca.gsfc.nasa.gov!tencati
- From: tencati@nssdca.gsfc.nasa.gov (NSI Security Manager +1-202-434-4541)
- Newsgroups: alt.comp.acad-freedom.talk
- Subject: Incident Response Teams (WAS: Re: CERT and the Dept. of Justice on keystroke monitoring)
- Message-ID: <14DEC199215163611@nssdca.gsfc.nasa.gov>
- Date: 14 Dec 92 20:16:00 GMT
- References: <1992Dec8.041023.4125@eff.org> <1992Dec10.025308.14768@nntp.hut.fi> <jpe.723993622@ee.egr.duke.edu>
- Sender: usenet@nsisrv.gsfc.nasa.gov (Usenet)
- Followup-To: alt.comp.acad-freedom.talk
- Organization: NASA - Goddard Space Flight Center
- Lines: 82
- News-Software: VAX/VMS VNEWS 1.41
- Nntp-Posting-Host: nssdca.gsfc.nasa.gov
-
- In article <jpe.723993622@ee.egr.duke.edu>, jpe@ee.egr.duke.edu (John P. Eisenmenger) writes...
- >jkp@cs.HUT.FI (Jyrki Kuoppala) writes:
-
- >>As responsible net.citizens who value both security and privacy we
- >>should set up public mailing addresses, archives and cooperative
- >>groups to provide functions like collection of computer security
- >>information and distribute information about them. I think I can help
- >>arrange for some ftp/gopher space and mailing addresses on
- >>nic.funet.fi, if that is needed.
- >
- >That's funny. Isn't that exactly what CERT is?
- >
- >-John
- >
- Good Question! The answer is YES and NO. CERT is one of many teams who
- provide security information and incident handling services to a
- particular constituency. DARPA funded the CERT at the SEI of Carnegie-
- Mellon University to provide an incident response team for those
- Internet sites who don't have a team of their own. Their constituency
- is therefore quite vast.
-
- There is an umbrella organization called FIRST (the Forum of Incident
- Response and Security Teams) which comprises response teams from many
- different companies, government agencies (both US and non-US),
- universities, vendors, etc.
-
- *ANY* entity that has its own computer security response effort can
- apply for membership in FIRST and benefit from the interaction with
- other response teams.
-
- On the Internet, there are certainly many users and organizations that
- have no internal security efforts. For those groups, the CERT receives
- money from DARPA to provide certain services.
-
- It would be inappropriate for the CERT to handle incidents for other
- organizations, like NASA, DoD, DoE (to name a few) which have their
- own funding sources for internal computer security incident response
- efforts, as well as non-US entities, for which CERT has no authority
- or charter. The mechanism for all these individual teams to
- "interoperate" is FIRST, which was formalized a little over a year
- ago to address this very issue. The CERT/CC is one of the founding
- and charter members of FIRST. However, they are an equal partner with
- all the other member FIRST organizations.
-
- The CERT also appears to have the most budget (or at least a very
- healthy one) ergo they can provide many services, which makes them
- the most visible.
-
- At a recent steering committee meeting of FIRST, a letter from the
- U.S. Dept. of Justice regarding the legal issues surrounding keystroke
- monitoring was passed from the FIRST Secretariat to the steering
- committee members. Based upon the information contained in the letter,
- CERT took the initiative of contacting the Justice Department, going
- over the details of the letter, and composing their advisory. The CERT
- has no authority to recommend policy or procedures in the legal arena.
- They merely reported to their constituency the result of their
- discussions with the US DoJ. The crux of the message is that if you
- ever hope to use keystroke logs against someone who cracks your
- machine, you better warn the sucker they're being recorded (it also
- protects YOU against charges of wiretapping). The information in the
- CERT bulletin isn't the end-all solution - but it is a start. More
- will follow as the DoJ figures out all the technological
- ideosyncracies of networked computer systems.
-
- More information about FIRST can be obtained by sending email to the
- secretariat at first-sec@first.org. A current list of FIRST members
- and their constituencies can be obtained by sending an email message
- to docserver@first.org with the body of the message reading: send
- first-contacts.
-
-
- Ron Tencati
- Security Manager
- NASA Science Internet
-
- ------------------------------------------------------------------------------
- NASA Science Internet (TCP/IP & DECnet)| NSI/IP: Tencati@Nssdca.Gsfc.Nasa.Gov
- Security and Incident Response Office | NSI/SPAN: NCF::TENCATI/15548::TENCATI
- Suite 950 | Tele - +1-202-434-4541
- 700 Thirteenth St., NW | FAX - +1-202-434-4599
- Washington, D.C. 20005; USA | Beeper +1-800-759-7243, Pin:5460866
- ------------------------------------------------------------------------------
-