As more African countries engage in the manufacture and innovation, consideration should be given to security in the design, planning, development, testing and maintenance of products, solutions and services
According to FIRST, a Product Security Incident Response Team (PSIRT) is “an entity within an organization which, at its core, focuses on the identification, assessment, and disposition of the risks associated with security vulnerabilities within the products, including offerings, solutions, components, and/or services which an organization produces and/or sells.” The FIRST PSIRT Services Framework, provides guidance on the profile and capabilities of a team, created to manage vulnerabilities identified in products and offerings.
Examples of a PSIRT include Siemens ProductCERT, which is part of Siemens cyber incident handling and vulnerability handling (IHVH) portfolio and Kaspersky’s Product Security Team (PST). The Microsoft Security Development Lifecycle (SDL) consists of a set of practises that support security assurance and compliance, including the establishment of a standard incident response process.
Resource: Presentation – Product CSIRTSs (PSIRTs) Special Interest Group (SIG)
The presentation made at the FIRST & AfricaCERT Virtual Symposium for Africa and Arab Regions December 7-9, 2021 By PSIRT SIG Co-Chairs Pete Allor, Red Hat and Josh Dembling, Intel covers the following areas:
– PSIRT training videos and maturity guide 2018
– PSIRT Services Framework V.1.1.2019
– PSIRT Services Framework V.1.X. (Q2 2022)
– Determining mission, Goals and Deliverables