Description for eduGAIN
...
CSIRT
...
REMARK: This needs to be synced with https://edugain.org/edugain-security/
in particular the
...
About this document
This is version 1.0.1, draft 2021/07/14, May 25th 2022.
Distribution List for Notifications
Notifications of updates are submitted to the eduGAIN Steering Group mailing list edugain-sg@lists.geant.org. The eduGAIN Steering Group mailing list is composed of all the delegates and deputies of the eduGAIN participants, the subscription is managed by the eduGAIN Service. The mailing list is not moderated.
Locations where this Document May Be Found
The current version of this CSIRT description document is available from the eduGAIN -CSIRT WWW site; its URL is CSIRT website, https://edugain.org/edugain-security/
Please make sure you are using the latest version.
Authenticating this Document
This document has been signed with the eduGAIN - CSIRTs PGP key. The signatures are also on our Web site, under: https://edugain.org/edugain-security/
Contact Information
Name of the Team
eduGAIN - CSIRT: The eduGAIN Computer Security Incident Response Team.
Address
GEANT C/O eduGAIN - CSIRT
Hoekenrode 3
6th floor
1102 BR Amsterdam
The Netherlands
Time Zone
Europe/Amsterdam (GMT+0100, and GMT+0200 from April to October)
Telephone Number
+44 1223 733033
Facsimile Number
Not available.Blank
Other Telecommunication/Instant messaging
Not applicable available.
Electronic Mail Address
abuse@edugain.org This address can be used to report all security incidents which relate to the eduGAIN participants. This is a mail alias that relays mail to the human(s) on duty for the eduGAIN - CSIRT.
Public Keys and Other Encryption Information
The eduGAIN - CSIRT has a PGP key, whose KeyID is CE43BCB8 and whose fingerprint is
F9FF B82B 9700 72D1 F753 25CF 5E3C 31D7 CE43 BCB8.0497 8576 D7A6 3151 5401 DB98 697A 900B 7C8E 095E
The key and its signatures can be found at the usual large public keyservers.
Team Members
The eduGAIN - CSIRT team team is coordinated by the eduGAIN - CSIRT security officer and it is composed by security officers and experts from the constituent participants and the Research and Education community. The current team consists of the following persons:
- Sven Gabriel, NIKHEF (Team Member)
- Daniel Kouril, CESNET (Team Member)
- Davide Vaghetti, GARR (Security Officer)
- Romain Wartel, CERN (Team Member)
composition is available on the eduGAIN wiki: <URL>
eduGAIN CSIRT will use the information you provide to help solve security incidents affecting eduGAIN. This means that by default the information will be distributed further to the appropriate parties – but only on a need-to-know base, and preferably anonymized.
Other Information
General information about eduGAIN security is in https://edugain.org/edugain-security/
The eduGAIN - CSIRTs hours of operation are generally restricted to regular business hours (Monday - Friday 09:00-17:00 (CET/CEST)) Monday to Friday , except public holidays). The . Outside business hours, eduGAIN CSIRT may also provide support outside business hours provides support on a best effort basis.
Charter
Mission Statement
The eduGAIN CSIRT provides a central contact and support point for security incidents , and it at the inter-federation level. It will work in close collaboration with Federation Security Contacts and Federation Operators to coordinate the investigation and resolution of suspected security incidents at the inter-federation level.
Constituency
eduGAIN consists of identity federations, which which members are the federation participants, an association of organizations that exchange information as appropriate about their users and resources to enable collaborations and transactions. With regard to security incident response the identity and service providers (IdP and SP) registered in a federation.Federations whose primarily goal is to provide authentication and authorisation services to the research and education community. The eduGAIN Service provides an infrastructure for establishing trusted communications between Entities, such as Identity and Service Providers, belonging to different Federations.
Please refer to the [eduGAIN Constitution] for further details.
For an up to date list of the current eduGAIN Participants you can refer to: The eduGAIN constituency consists of the eduGAIN participants, see https://technical.edugain.org/status
Sponsorship and/or Affiliation
eduGAIN -CSIRT is part of eduGAIN.orgCSIRT team members affiliated to a GEANT members will be funded by the GEANT project. Other members will be funded by their respective organisations.
Authority
eduGAIN -CSIRT is authorized CSIRT operates with authority delegated by the eduGAIN Steering Group to coordinate incident response at the inter-federation level and provide the services described in section 5 of this document.
Policies
The eduGAIN policy framework is inavailable on the eduGAIN Technical site at the following URL:
https://technical.edugain.org/doc/eduGAIN-Declaration-v2bis-web.pdfThe constitution of the eduGAIN service is in https://technical.edugain.org/doc/eduGAIN-Constitution-v3ter-web.pdfdocuments
Types of Incidents and Level of Support
All security incidents that may have an impact at the inter-federation level are managed by eduGAIN CSIRT.
eduGAIN eduGAIN- CSIRT aims to respond to incident reports requests within 4 office hours.
Co-operation, Interaction and Disclosure of Information
The eduGAIN Security Team CSIRT closely collaborates with the Identity Federations’ security operators the Federation Security Contacts, Federation Operators, entities Security Contacts and the National Research and Education Network CSIRTs and CERTs in eduGAIN to ensures ensure that all security incidents are investigated as fully as possiblethe parties affected by a security incident at the inter-federation level are timely alerted and supported in the investigation, limitation and remediation process.
The roles and interactions of the different entities relevant to incident response within eduGAIN are described in thethe eduGAIN Security Incident Response Handbook Feedback
<the link needs to be updated to point to the official version of the handbook>
[eduGAIN-SIRH]
eduGAIN eduGAIN- CSIRT reports to the eduGAIN Steering Group (eSG).
Communication and Authentication
ALL incoming information is handled confidentially by eduGAIN - CSIRT, regardless of its priority.
eduGAIN - CSIRT supports the Information Sharing Traffic Light Protocol (ISTLP – see https://www.trusted-introducer.org/ISTLPv11.pdf) - [FIRST TLP] - information that comes in with the tags WHITE, GREEN, AMBER or RED will be handled appropriately.
eduGAIN-Untagged information will be treated as TLP-GREEN (see above). eduGAIN CSIRT will use the information you provide to help solve security incidents affecting eduGAIN. This means that by default the information will be distributed further to the appropriate parties – within the limits of the set TLP Tag, but only on a need-to-know base, and preferably anonymized.
Services
Incident Response
eduGAIN - CSIRTs major IT security incident management function is incident coordination across eduGAIN federationsFederations.
Incident Triage
eduGAIN - CSIRT will support the eduGAIN participants investigating whether indeed an incident occurred and in case, determining the extent of the incident. This ranges from a single entity registered in one or more federations, to multiple entities from different federations affected.
Incident
...
Response Coordination
eduGAIN is a federation of identity federations, in which different organizations operate SPs and IdPs. Usually the mandate and scope of the SPs IdPs security teams are limited to the home organization. The same holds for the federations participating in eduGAIN. eduGAN-CSIRT will organize the security incident communications across affected participants and coordinate the local response activities to allow for an efficient containment and subsequently resolution of security incidents.
Incident Resolution
The incident resolution is ultimately the task of the organizations responsible for the end entities in eduGAIN (Service providers (SP), Identity Providers (IdP))affected entities. If possible and on request, edugain-eduGAIN CSIRT will support the end entities with in coordination with the Federations on requestfederations.
Proactive Activities
<THIS HAS A RISK OF GETTING TIME CONSUMING MORE THEN WE CAN SPEND ON IT>
Incident Reporting Forms
Incident Report templates can be found in: https://aarc-project.eu/wp-content/uploads/2017/02/DNA3.2-Security-Incident-Response-Procedure-v1.0.pdf
The eduGAIN CSIRT will maintain the security communication channels with all the eduGAIN participants. In order to do that, from time to time, the eduGAIN CSIRT will organize communication challenges to assess the reliability and responsiveness of the communication infrastructure.
The eduGAIN CSIRT will occasionally share information about prominent security threats and vulnerabilities that may affect the eduGAIN community .
Incident Reporting Forms
The following form will be used to notify a suspected or verified security incident to any affected party. All the incident reports will be signed by the eduGAIN CSIRT with its PGP key.
Subject: [TLP:COLOR] subject
TLP:COLOR
## SUMMARY ##
Summary of the report.## INTRUSION TIMELINE ##
YYYY-MM-DD HH:MM:SS event 1
..
YYYY-MM-DD HH:MM:SS event N## INDICATORS OF COMPROMISE
Available IoCs.## REPORTING & SHARING
Where to report back about new findings on the incident.
The above form is based on the AARC Deliverable DNA3.2-Security Incident Response Procedure [AARC-DNA3.2]< THE TEMPLATES SHOULD BE EXTRACTED/EDITED FROM THE PDF AND PUT ON THE WEBSITE (WITH A REFERENCE TO THE ORIGINAL DOC) >
Disclaimers
While every precaution will be taken in the preparation of information, notifications and alerts, eduGAIN - CSIRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.
References
[eduGAIN Constitution] https://technical.edugain.org/doc/eduGAIN-Constitution-v3ter-web.pdf
[FIRST TLP] https://www.first.org/tlp
[eduGAIN-SIRH] https://wiki.geant.org/download/attachments/218464365/eduGAIN%20Security%20Incident%20Response%20Handbook-v1-eSG-feedback.pdf
[AARC-DNA3.2] https://aarc-project.eu/wp-content/uploads/2017/02/DNA3.2-Security-Incident-Response-Procedure-v1.0.pdf