1. DOCUMENT INFORMATION
- 1.1. Date of last updated
- This is version 2.0 as of December 9, 2024.
- 1.2. Distribution list for notifications
- Changes to this document are not distributed by a mailing list. Any specific questions or comments, please go to the email address contacto@csirt.gob.do
2. CONTACT INFORMATION
-
- 2.1. Team name
- National Cyber Incident Response Team, CSIRT-RD
- 2.2. Time zone
- UTC / GMT -4 hours
- 2.3. Other telecommunications
- No
- 2.4. Email
- Incident Report: incidentes@csirt.gob.do
- 3073 8B9F F322 05FA 60AD 59CB 92EB 51BD 373F 9423
General Information: info@csirt.gob.do
- 2.5. Team members
- A complete list of CSIRT-RD team members is not publicly available. Team members will be identified in front of the reporting party with their full name in an official communication about an incident.
- 2.6. Other information
- General information on the services provided by CSIRT-RD and on the agency itself are published on the web portal cncs.gob.do
- 2.1. Team name
- 2.7. Customer contact points
- For any communication, please use the email info@csirt.gob.do. Our regular response schedule is every day of the week from 08:30am to 05:00pm. Outside these hours, the Shift Officer is available for incidents and mail can be contacted incidentes@csirt.gob.do
3. LETTER
- 3.1. Mission
- CSIRT-RD is the National Cyber Incident Response Team, attached to the National Cybersecurity Center (CNCS), created by Decree 230-19 on June 19, 2018. Your mission is to ensure the establishment of appropriate cybersecurity mechanisms that protect the state and national security through continuity, update and evaluation of the National Cybersecurity Strategy,the formulation of policies derived from this strategy and the definition of initiatives, programs and projects that lead to the successful realization of the strategy, as well as the prevention, detection and management of incidents generated in government information systems and in national critical infrastructures. Being the national alert and response center that cooperates and helps respond quickly and efficiently to cyberattacks, actively address cyberthreats, including national coordination of different incident response and decision-making capabilities in crisis.
- 3.2. Constituency
- CSIRT-RD operates under the National Cybersecurity Center (CNCS), under the authority of the Executive Director and the Board of Directors.
- 3.3. Sponsorship and/or Affiliation
- CSIRT-RD is the Dominican government’s center of expertise in cyber security and incident response. Aimed at preventing ICT and internet-related incidents. It is part of the Ministry of the Presidency and the National Cybersecurity Center, consisting of the technical director and incident management analysts.
- 3.4. Authority
- CSIRT-RD operates within the National Cybersecurity Center (CNCS), under the authority of the Executive Director and the Board of Directors.
4. POLICIES
- 4.1. Types of incidents and level of support
- CSIRT-RD performs tasks to prevent and respond to a variety of incidents affecting its constituency, including:
- -Malicious Code
-Availability Issues
-Information Theft
-Intrusions
-Information Compromise
-Fraud
- CSIRT-RD performs tasks to prevent and respond to a variety of incidents affecting its constituency, including:
-
- Incident severity leves determine the service response time:
-
-
- -CRITICAL: 15 minutes
- -HIGH: 30 minutes
- -MEDIUM: 3 hours
- -LOW: 7 hours
- 4.2. Cooperation, interaction and dissemination of information
- CSIRT-RD uses the TLP protocol to facilitate secure information exchange and handles all received data confidentially. Sensitive information is stored and communicated only in secure environments and, if necessary, protected with encryption technologies.
All information provided to CSIRT-RD is used exclusively for resolving security incidents and shared only on a need-to-know basis, preferably anonymously.
- CSIRT-RD uses the TLP protocol to facilitate secure information exchange and handles all received data confidentially. Sensitive information is stored and communicated only in secure environments and, if necessary, protected with encryption technologies.
- 4.3. Communication and authentication
- Our preferred method of communication is by email. For secure communication, we use the following PGP key: 3073 8B9F F322 05FA 60AD 59CB 92EB 51BD 373F 9423.
5. SERVICES
- Incident response provides 24/7 availability to coordinate the recovery of all types of ICT-related incidents and consists of expertise, tools, and other capabilities to act, analyze, and communicate with stakeholders and the media.
- 5.1.1 Classification of the Incident
- – Investigate whether an incident actually occurred.
– Determination of the extent of the incident.
– Evaluation and comparison of the incident with historical.
- – Investigate whether an incident actually occurred.
- 5.1.2. Coordination of incidents
- – Determine the initial cause of the incident.
– Facilitate contact with other sites that may be involved.
– Communicate with stakeholders and the media
- – Determine the initial cause of the incident.
- 5.1.3. Incident Resolution
- – Provide advice to the reporting party that will help eliminate the vulnerabilities that caused the incident and protect the systems from the effects of incidents.
– Evaluate which actions are best suited to provide the desired results regarding incident resolution.
– Provide assistance in the collection of evidence and interpretation of data where necessary.
- – Provide advice to the reporting party that will help eliminate the vulnerabilities that caused the incident and protect the systems from the effects of incidents.
- 5.2. Proactive activities
- Proactive activities aim to reduce the likelihood or impact of incidents on constituents. CSIRT-RD provides updated information and advice on new threats and attacks, raises awareness and skills among employees, and issues alerts and practical advice to the public and small businesses through https://cncs.gob.do/alertas/.
6. INCIDENT NOTIFICATION FORMS
- To report incident, send communication: incidentes@csirt.gob.do
- Alternatively, fill out the incident report form: Report an Incident
- For more details see, Cyber Incident Identification and Reporting Guide
7. DISCLAIMERS
- CSIRT-RD takes all necessary precautions in preparing information, notifications, alerts, and reports but assumes no responsibility for errors, omissions, or damages resulting from the use of the provided information.