The services of the eduCSIRT support the Bavarian universities of the Digital Network Bavaria in the technical and organizational management of IT security incidents. This includes the areas of incident analysis, coordination of incident processing, forensic analysis and support in the clean-up of affected systems.
After successful onboarding, IT security incidents can be reported to eduCSIRT. The response to reported IT security incidents usually takes place within four hours. When processing the reported incidents, the eduCSIRT reserves the right to prioritize according to the severity of the incident, the number of organizations affected and available resources at the time of the occurrence or reporting of the incident.
If necessary, the eduCSIRT team can call in an external APT service provider for support.
After successfully completing onboarding, the eduCSIRT will provide the services
available.
The participating universities can report IT security incidents to the e-mail address, via web form or telephone. Missing information will be supplemented after consultation with the eduCSIRT staff and initial information will be provided. The university also supports the eduCSIRT in the collection and provision of data and files for incident analysis. The incident will then be analysed and further action will be coordinated with the university. As part of the onboarding process, the university concerned receives access to the eduCSIRT emergency package. This includes, among other things, instructions for the installation of necessary software, in particular for scanning affected systems, as well as information and other documents that can be used by the university as part of incident handling.
On request and in coordination with the university, the eduCSIRT supports communication with external interest groups, e.g. state authorities and institutions. This does not include public relations work in the context of incident management. This is taken over exclusively by the universities. As part of incident coordination, anonymized incident data may be shared with other CERTs.
The eduCSIRT offers the possibility of forensic analysis of the affected systems. This is done on the one hand by analysing data uploaded by the university, by analysing data collected on site by eduCSIRT employees or in the case of in-depth forensic analyses by an external service provider who is consulted in consultation with the university.
The eduCSIRT advises the universities on the review and adjustment of potentially affected systems. Rebuilding the systems compromised in the incident is not part of the eduCSIRT's service.
IT security incidents can be reported in the following ways:
The authorized persons for activating the service in the event of IT security incidents are determined as part of the onboarding process. The eligible persons can be adjusted at any time by sending an e-mail to informationssicherheit@remove-this.digitalverbund.bayern .
Participation in an onboarding process is mandatory for the use of the eduCSIRT services. This process must be repeated every 2 years. Organizational or technical changes affecting the onboarding process must be reported to eduCSIRT after they become known.
This service is made available to the following categories of users.
| User class | Note |
|---|---|
| (1), (2) | only for members of the Digital Network of Bavaria |
| (3), (4), (5), (6) | not available for these customers |
The service can be requested by CIO, CISO, ISB or data center management of the universities in the Digital Network Bavaria via e-mail to informationssicherheit@remove-this.digitalverbund.bayern .
Leibniz Supercomputing Center
of the Bavarian Academy of Sciences
Boltzmannstraße 1
85748 Garching - Germany