ITU has employed the CIRT Framework to African countries including Botswana, Burundi, Gambia, Ghana, Kenya, Malawi, Tanzania, Uganda, and Zambia in setting up national teams. This framework consists of four (4) phases: assessment, design, establishment and enhancement.
Phase 1: Assessment This phase involves evaluation of the country’s cybersecurity posture through onsite assessment and stakeholder engagement in a series of workshops to clarify the value and justification of establishing a CSIRT and obtaining support for resourcing and financing mechanisms. The outcome of this phase is an assessment report, prepared by ITU experts, that contains key issues, findings and analyses, recommendations, and a phased implementation plan for setting up the national CIRT.
Phase 2: Design The outcome of this phase is detailed Design Document and involves a review of the mandate and positioning of the CSIRT, the definition of services model according to the FIRST CSIRT Services Framework, list of workflows, policies and procedures, a processes map, constituency engagement plan and communication strategy, networks design, list of hardware and software equipment and tools, selection of premises and personnel.
Phase 3: Establishment This phase involves capabilities (process, policies, procedures, technology and human resource) development, capabilities deployment and testing, customization, fine-tuning and training, operations, handover and closure. The outcomes of this phase reports, documentation and operational acceptance of the CIRT by the beneficiary country.
Phase 4: Enhancement This phase establishes new services (situation awareness and digital forensics) based on the FIRST CSIRT Services Framework (see section 5.2), custom-built services and better automation of existing services.