This page is a list of good practice resources available for everyone to use. They have been created and reviewed by international experts, either: as part of a FIRST Special Interest Group (SIG); or through the work done by the FIRST Community and Capacity Building (CCB) team.
FIRST SIGs are collaborative spaces based on particular topics, sectors, and communities. The participants share information and assist each other with incidents and research. The SIGs also collaborate on tangible products that are available as resources for the wider cybersecurity community.
FIRST’s CCB team actively works with the community on the ground and creates process documents, templates, playbooks and other resources for response teams to quickly and easily implement into their systems.
Resources
Resources are organized by subject.
Analysis
Communications
Definitions
Incident Response
- CSIRT Services Framework
Created by the CSIRT Framework Development SIG.
A high-level document describing in a structured way a collection of cybersecurity services and associated functions. Available in English, Arabic, Chinese, French, Japanese, Spanish and Russian.
- Roles and Competencies addendum
Created by the CSIRT Framework Development SIG.
To clarify the needs and requirements for CSIRT roles.
- Security Incident Timing Metrics (PDF)
Created by the Metrics SIG.
An open reference for standardizing the tracking of security incident timeline and measurement security incident timing metrics.
- Metrics for the CSIRT Services Framework
Created by the Metrics SIG.
The CSIRT Services Framework (above) describes the services CSIRTs provide and this document focuses on how those services can be measured. It defines a practical, structured set of quantitative and qualitative metrics that organizations can use to assess, track, and improve the services described in the FIRST Framework.
- Product Security Incident Response Plan (PDF)
Created by the PSIRT SIG.
A best practice framework for creating an incident response plan for teams working on specific products.
- PSIRT Services Framework
Created by the CSIRT Framework Development SIG.
A high-level document detailing possible services that computer incident response teams (CSIRTs) and product incident response teams (PSIRTs) may provide. Available in English, Arabic, Chinese, French, Japanese, Spanish and Russian.
- Consolidated SBOM and CSAF/VEX Operational Framework (PDF)
Created by the PSIRT SIG.
This document guides vendors on implementing and releasing Software Bill of Materials (SBOM) and Common Security Advisory Framework / Vulnerability Exploitability eXchange (CSAF/VEX) information.
- Information Exchange Policy Framework (PDF)
Created by the Information Exchange Policy SIG.
This policy sets out the FIRST Information Exchange Policy (IEP) framework that security teams may consider implementing to support their information sharing and information exchange initiatives.
- FIRST MISP
Created by the Information Sharing SIG.
The FIRST operates a Malware Information Sharing Platform (MISP) instance supported by CIRCL.
- TLP definitions
Created by the TLP-SIG.
Definitions and guidance on correct usage of the Traffic Light Protocol (TLP) system. Available in English, Brazilian Portuguese, Chinese, Czech, Dutch, French, Greek, Japanese, Norwegian, Romanian, Spanish, and Swedish.
- Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure
Created by the Vulnerability Coordination SIG.
The purpose of this document is to assist in improving multi-party vulnerability coordination across different stakeholder communities.