Welcome to 'CERT-in-a-Box' and 'Alerting service-in-a-Box'
The project 'CERT-in-a-Box' and 'Alerting service-in-a-Box' is an initiative of GOVCERT.NL to preserve the lessons learned from setting up GOVCERT.NL and 'De Waarschuwingsdienst', the Dutch national Alerting service.
The project aim is to help others starting a CSIRT or Alerting Service by:
- Getting them up to speed faster
- Taking the benefits and not making the same mistakes
Security, a growing concern.
Society has become very dependent on ICT. At the same time, security risks are becoming worse. Security attacks are getting technically more complicated and easier to execute at the same time. The odds are against safety: today, one in every thousand lines of new computer code contains an error. Every error might in its turn, cause a security flaw. This situation is not likely to change any time soon.
The Dutch government set up GOVCERT.NL to organize measures focused on the prevention of and response to ICT related security incidents for the whole Dutch government.
Helping you is the aim of the box projects
From the beginning, the purpose of the Dutch CSIRT was to give as much information as possible on how we are operating and share it with the CSIRT community. Therefore, we have collected and preserved all our implementation and project plans during the set up of GOVCERT.NL and the Dutch National Alerting Service (De Waarschuwingsdienst). The chance to set up a brand new CSIRT using the existing knowledge from the International CERT-community and with the help of the respected and large scale CSIRTS like CERT-CC and AUSCERT, helped us to set up a CSIRT and have it fully operational in nearly a year.
We see this project as an opportunity to give and to help the CSIRT community to mature and grow. Moreover we would like to help to start up CSIRTS with a very practical 'how-to' on setting up a CSIRT.
How to read this documentation
We have grouped our information into the following chapters:
These chapters represent the main issues you will address when setting up a CSIRT or Alerting Service. As much as possible, we have separated the information on our GOVCERT.NL project and our project for the Alerting Service 'De Waarschuwingsdienst'. Please bear in mind that we developed the alerting service in parallel once our GOVCERT.NL project was a few months in. You will therefore find a lot of relevant information by just reading all our results, tips and helpful information. Most of the time these apply to setting up a CSIRT as well as an Alerting Service.