Establishing a successful incident response capability requires substantial planning and resources.
There are several types of funding models that can be used when establishing and operating a CSIRT:
- A cost centre within an organisation, or
- full or partial grants, detailing the grant including issuer and source, purpose, amount and duration of the grant should it be determined.
- Selling services either internally or externally
- funded through a consortium of organisations such as universities in a research network.
- Or a combination of any of those listed above.
The funding should cover:
- Capital Expenditure (CAPEX): to cover initial cost related to the acquisition of hardware and software, equipment and tools, and premises;
- Operating Cost (OPEX): to cover recurring operational costs for engagement with the constituency, personnel, facilities and software licences, delivery, maintenance and maintenance of services, technology, processes, and organisational capabilities.