Current FIRST SIGs

CVSS SIG: Common Vulnerability Scoring System

For a global approach towards scoring metrics for vulnerabilities.

IEP SIG: Information Exchange Policy

The initial goals of this SIG are to collaboratively develop an extensible framework for defining information exchange policy and a set of standard definitions for most common aspects.

ICS SIG: Industrial Control Systems

Information Sharing SIG

The core mission is to support existing and new FIRST members to practice information sharing and acquire feedback from the members to improve the information sharing practices.

Vendor SIG: Internet Infrastructure Vendors

The goal of this SIG is to provide forum for Internet Infrastructure vendors.

Malware Analysis

This SIG will advocate and promote the sharing of malware analysis tools and techniques to enable CSIRTs to combat and analyze malicious code.

Metrics SIG

To improve CSIRT incident management practices within the FIRST community.

Passive DNS Exchange

Develops and maintains a standard for exchanging passive DNS information between organizations.

Red Team SIG

The Red Team SIG shall provide a forum for Red Team members or leaders in order to discuss state of the art Red Teaming technologies, processes and methodologies.

TLP SIG Traffic Light Protocol

The TLP SIG governs the standard definition of TLP for the benefit of the worldwide CSIRT community and its operational partners.

Vulnerability Coordination SIG

Develop and execute a strategy for improving vulnerability coordination globally.

Vulnerability Reporting and Data Exchange SIG

Primarily chartered to research and recommend ways to identify and exchange vulnerability information across disparate vulnerability databases.

Events at spotlight

FIRST is the global Forum for Incident Response and Security Teams

FIRST is the premier organization and recognized global leader in incident response. Membership in FIRST enables incident response teams to more effectively respond to security incidents reactive as well as proactive.

FIRST brings together a variety of computer security incident response teams from government, commercial, and educational organizations. FIRST aims to foster cooperation and coordination in incident prevention, to stimulate rapid reaction to incidents, and to promote information sharing among members and the community at large.

Apart from the trust network that FIRST forms in the global incident response community, FIRST also provides value added services. Some of these are:

Currently FIRST has more than 300 members, spread over Africa, the Americas, Asia, Europe and Oceania.

What's new

  • Fri, 02 Dec 2016
  • The call for papers for FIRST 2017 closed on 1st December 2016 (13:24 +0100)

    For the first time the call was not extended, as a satisfying number of submissions from around the world have been received in time. Actually we have a representation of over 40 countries. While the number of submissions is much higher and much diverse from the previous years there is also a considerable lower number of presentations from the US, showing that the incident response and security teams have really become international. This year's conference chair, Prof. Dr. Klaus-Peter Kossakowski, a long term veteran in the cyber security community and past chair of FIRST, is looking forward for a fruitful discussion within the Program Committee consisting of over 60 volunteers. The reviews will be carried within the next six weeks. He is confident that a very interesting program will be presented in early February 2017 to the public.

  • Tue, 22 Nov 2016
  • FIRST and LACNIC sign agreement to improve incident response capability in Latin America and the Caribbean (14:00 +0100)

    Memorandum of Understanding enables both organizations to benefit from each other’s programs to support computer security incident response teams (CSIRT) in the region.


What is FIRST to you?