There is a layered system of Cyber Security Incident Response Teams (CSIRT) that support organizations. This reflects a threat's severity, likelihood, and sphere of operation. Broadly speaking, CSIRTs support organizations with common interests (for example, companies, industries, research areas, national interests, and so on). A representation of this is shown in the following diagram, although there can be variations on this:
NIST.SP 800-61 Revision 2 lists six different incident response teams. In this section, we will learn how to describe the goals of each team and explain how they differ.
The overall aim of a CSIRT is consistent: to respond to cybersecurity incidents. This means reducing the technical impact, but also the impact on user confidence, customer engagement, and public opinion. In...