The International Telecommunications Union Standardardization Sector (ITU-T) Recommendation X.1060 establishes a framework for organisations to build and manage a cyber defence centre which may be a CSIRT or SOC. Through three (3) processes – building, management, and evaluation – a CSIRT determines which security services should be included in its service catalogue, profile, and portfolio.
ITU-T Recommendation X.1060 identifies nine (9) service categories. Based on the basic, standard, and advanced recommendation levels, a CDC can extract a service catalogue from this service list. Furthermore, by determining the service assignment as insourced, outsourced or unassigned, the CDC can develop a service profile and finally a service portfolio by measuring the current service score (As-is) or medium-long term target service score (To-be):
A) strategic management of CDC;
B) real-time analysis;
C) deep analysis;
D) incident response;
E) checking and evaluation;
F) collection, analysis and evaluation of threat intelligence;
G) development and maintenance of CDC platforms;
H) support of internal fraud response;
I) active relationship with external parties.
Figure 4: Cyber Defence Centre Services. Source: ITU-T Recommendation X.1060