Notification Phases: Preparation, Management, Closure
Preparation for Notification
The preparation phase is crucial to ensure that the notification of an incident to CSIRT Italia is timely and effective. Here are the key steps:
- Incident Detection: As soon as an incident is detected, it is essential to gather all available information. This includes:
- Date and time of the incident.
- Detailed description of the event.
- Impacted systems and services.
- Indicators of Compromise (IOCs), such as system logs and malware traces.
- Impact Assessment: Determining the severity of the incident is fundamental. This may include:
- The extent of damage to systems.
- The duration of service interruption.
- The effect on the integrity, confidentiality, and availability of data.
- Response Planning: Establish a plan to mitigate the incident and restore normal operations. This should include:
- Immediate actions to contain the incident.
- Long-term measures to prevent similar future incidents.
- Necessary internal and external communications.
Notification Management
Once preparation is complete, you move to the management phase of the notification. This involves:
- Filling out the notification form: CSIRT Italia provides an online form for reporting incidents. The necessary information includes:
- Contact details of the organization and the person responsible for the notification.
- Detailed description of the incident and the measures taken.
- Indicators of Compromise collected.
- Evidence detected, such as system logs and malware samples.
- Sending the notification: The completed form must be sent to CSIRT Italia via their web portal (https://www.csirt.gov.it/segnalazione). It is important to send the notification as soon as possible, ideally within the timeframes established by current legislation.
- Interaction with CSIRT Italia: After sending the notification, CSIRT Italia may request further information or provide specific instructions. Continued cooperation with the CSIRT is essential for effective incident management.
Incident Closure
The final phase is the closure of the incident, which includes:
- Communication of closure: Inform CSIRT Italia that the incident has been resolved and that systems have been restored. This may include:
- A final technical report describing the actions taken.
- An assessment of the consequences of the incident.
- Measures adopted to prevent similar future incidents.
- Post-incident analysis: Conduct an internal review to identify the causes of the incident and lessons learned. This can help improve security measures and future incident response.
- Documentation and archiving: Maintain detailed documentation of the entire incident management process, including reports sent to CSIRT Italia, received communications, and actions taken.
Procedure for reporting and notifying incidents
Who must notify
Not all organizations are required to notify CSIRT Italia of incidents. The main obligated entities include:
- Entities included in the National Cyber Security Perimeter (Perimetro di Sicurezza Nazionale Cibernetica – PSNC): These are public and private entities that perform essential functions of the State or provide fundamental services.
- Operators of Essential Services (OES): Sectors such as energy, transport, banking, health, and digital infrastructure.
- Digital Service Providers (DSPs): Providers of online marketplaces, search engines, and cloud computing services.
How to make a notification to CSIRT
The notification procedure is clear and detailed. Here is a step-by-step guide:
- Identify the incident: As a first step, it is necessary to identify whether the incident falls into categories requiring mandatory or voluntary notification. This identification can be based on criteria such as the severity of the impact and the type of system affected.
- Gather information: Before proceeding with the notification, collect all relevant information about the incident. This includes the nature of the incident, the systems involved, the actions taken, and the evidence collected.
- Access the notification form: Visit the CSIRT Italia website and access the online notification form (https://www.csirt.gov.it/segnalazione).
- Fill out the form: Enter all requested information into the form. This includes details about the incident, contact data, and any relevant evidence.
- Submit the form: After completing the form, submit it via the CSIRT Italia portal. Ensure that you adhere to the established timelines for notification, which vary depending on the type of incident and applicable regulations.
Types of notification
There are different types of notifications, depending on the nature and severity of the incident. The main ones are:
- Mandatory notification: Required for incidents with a significant impact on critical systems or essential services. It must be sent within specific timeframes, which can vary from one hour to 72 hours depending on the severity of the incident.
- Voluntary notification: Can be made for less severe incidents or to report events that do not fall into the mandatory categories but might still be of interest to CSIRT Italia.
CSIRT forms and resources available online
Notification forms
CSIRT Italia provides online forms to facilitate incident reporting. These forms are designed to collect all necessary information in a structured and complete manner. The main available forms include:
- Initial reporting form: Used to quickly notify an incident as soon as it is detected.
- Detailed notification form: Used to provide more detailed information about the incident, including actions taken and evidence collected.
CSIRT support resources
In addition to notification forms, CSIRT Italia offers a series of online resources to support organizations in incident management. These resources include:
- Guidelines and best practices: Documents that provide recommendations on how to prevent, detect, and respond to cyber incidents.
- Security tools: Software and tools to monitor, analyze, and mitigate cyber threats.
- Training and awareness: Training programs to improve awareness and skills in cybersecurity.
How to access CSIRT resources
CSIRT Italia resources are accessible via their website (https://www.csirt.gov.it). Here is how to use them:
- Visit the CSIRT Italia website: Access the official CSIRT Italia website to find all available resources.
- Navigate the resources section: Use the navigation menu to access different sections of the site, such as guidelines, security tools, and notification forms.
- Download and use the resources: Download the necessary documents and tools and use them to improve your organization’s cybersecurity.
Conclusion
Notifying CSIRT Italia of incidents is a fundamental process for ensuring national cybersecurity. Following the preparation, management, and closure phases, and using the resources and forms provided by CSIRT Italia, allows organizations to respond effectively to incidents and minimize associated risks.
At ISGroup SRL, we are aware of the importance of cybersecurity and the need for a timely response to incidents. By collaborating with CSIRT Italia and following their guidelines, we can contribute to creating a more secure digital environment for everyone.
For further information and resources, visit the official CSIRT Italia website at https://www.csirt.gov.it.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
