Title

The name of the group is eduGAIN Computer Security Incident Response Team (CSIRT)

Definitions

This document makes use of the Definitions described in the eduGAIN Constitution [eduGAIN-Constitution] and of the following additional ones:

Word/TermDefinition
CSIRTComputer Security Incident Response Team
eduGAIN

The eduGAIN inter-federation service connects identity federations around the world, simplifying access to content, services and resources for the global research and education community.

eSGeduGAIN Steering Group, the governing body of eduGAIN.
eduGAIN stakeholdereSG members, REFEDS members, NRENs, research and education community members.
Entity Security ContactAn entity mail address dedicated to security issues and incident response. It is recommended that the security contact is monitored by multiple individuals.

Purpose and Responsibilities

eduGAIN-CSIRT provides computer security incident response coordination for eduGAIN. It serves as the primary contact point for all security related issues affecting eduGAIN.

The eduGAIN-CSIRT maintains a communication infrastructure to assure that all the relevant information is received by the relevant Federation Operators and Entities security contacts in eduGAIN. That the information is processed and needed response actions are carried out is the responsibility of the Entity and respective Federation Operator Security Contacts.

Constituency

eduGAIN-CSIRT provides incident response coordination for the Entities members of Identity Federations participating in eduGAIN.

Service Description

Members of eduGAIN-CSIRT provide the services described in section 5 of the RFC 2350 eduGAIN-CSIRT document.

Service Level Description

The services described above are provided at least during business hours (9x5 CET/CEST) with 4-hour response, and outside business hours on a best-effort basis.

Composition

Membership

eduGAIN-CSIRT consists of:

Chair

The Chair of eduGAIN-CSIRT is the Security Officer.

Duties and responsibilities

The duties and responsibilities of the Chair include:

The duties and responsibilities of the members include:

Term of Office

The Term of Office is unlimited.

Method of Appointment

The eduGAIN-CSIRT Chair is appointed by the GEANT project.

Operating Procedures

The operation of eduGAIN-CSIRT will obey the eduGAIN Declaration and the eduGAIN Constitution and follow the procedures approved by the eSG. Any eduGAIN stakeholder has the right to suggest new policies and procedures: such requests should be submitted to the eduGAIN Security Officer. The decision whether to accept this request will be discussed within the eduGAIN CSIRT and decision will be recorded in the minutes of the meeting and feedback will be provided to the original requestor.

Communications and Meetings

All the members of the eduGAIN-CSIRT must subscribe to the eduGAIN-CSIRT mailing list (edugain-support-sec-team@lists.geant.org)
and should use it as the primary written communication channel. To allow for low latency communications, the team may communicate using end-to-end encrypted instant messaging channels provided all end-points have been pre-authenticated during a face-to-face validation.

The group deliberations happen at face-to-face meetings, phone/video conferences, or via the group mailing list. To enable consideration, where practicable, the draft agenda together with reports and documents that relate to the group will be forwarded to members three working days prior to scheduled meetings.

Accurate minutes will be kept of each meeting of the group. The minutes of a meeting shall be submitted to group members for ratification at the next subsequent meeting of the group.

Decision making

Peer Organizations

The eduGAIN-CSIRT shall proactively communicate with recognized peer organizations regarding suspected and confirmed security incidents that could affect such peers. It shall maintain a reference to the operating policies and practices of such peer infrastructures and participate in their processes and the evolution thereof.

External Collaborations

The eduGAIN-CSIRT members can decide to collaborate with external experts or entities for the purpose of assisting in a specific incident response or investigation. The external experts'  contribution will be limited to the scope of the incident and it will last for the time of the investigation and resolution of the incident.

Communication Channels

ChannelReference
eduGAIN-CSIRT email listedugain-support-sec-team@lists.geant.org
Report of abuseabuse@edugain.org
eduGAIN-CSIRT wiki & meeting minuteshttps://wiki.geant.org/display/eduGAIN/eduGAIN+Security
Telephone
Instant messaging channelsSignal group, keybase.io: edugain_sec

Related material and references

NameLocation
Policy development Kithttps://aarc-project.eu/policies/policy-development-kit/
Incident Response Handbookhttps://wiki.geant.org/download/attachments/218464365/eduGAIN%20Security%20Incident%20Response%20Handbook-v1-eSG-feedback.pdf?version=2&modificationDate=1612805091663&api=v2
Incident Response Procedures
Communication Flow
RFC-2350 for eduGAIN-CSIRThttps://wiki.geant.org/display/eduGAIN/Paperwork+-+RFC-2350+Draft
eduGAIN-CSIRT public wikihttps://wiki.geant.org/display/eduGAIN/eduGAIN+Security

Reporting

eduGAIN-CSIRT provides input about current operational security activities to Federation Operators group and eSG on request.

Authority

eduGAIN-CSIRT is authorized by the eSG to coordinate computer security incident response activities within its Terms of Reference and the applicable security policies. The eSG is the governing body of eduGAIN-CSIRT.

References