FIRST CSIRT Services Framework and Standards
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
FIRST: CSIRT Services Framework v2.1 - Foundational and Mandate
FIRST CSIRT Services Framework v2.1 (2019) Foundational. MANDATE + SCOPE: the CSIRT must have a CLEARLY DOCUMENTED MANDATE from its parent organisation (national authority + sector authority + corporate executive) defining: (a) AUTHORITY level (advisory + coordinating + commanding); (b) CONSTITUENCY (the user community served); (c) SERVICE AREAS provided (subset of the 5 in the framework); (d) DELIVERY MODEL (centralized + distributed + outsourced + hybrid); (e) FUNDING + STAFFING; (f) RELATIONSHIP with parent organisation + peer CSIRTs + national + international cooperation. The MANDATE is typically formalized in a CHARTER + Terms of Reference + Service Level Agreement. QUALITY MANAGEMENT + METRICS: CSIRTs operate quality management processes per CSIRT Maturity Models (e.g. SIM3 + CMMI-style); metrics include incident response time + customer satisfaction + service coverage + skills dev
- CSIRT charter + ToR + SLA
- Quality metrics + SIM3 assessment
- Constituency + service area documentation
- Mandate unclear or undocumented
- SLAs not measured or reported
- SIM3 assessment skipped
FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services
FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Interaction + Vulnerable System Impact + Subsequent System Impact (Confidentiality + Integrity + Availability for each); (b) THREAT METRICS (replacing v3.1 Temporal) - Exploit Maturity; (c) ENVIRONMENTAL METRICS - Modified Base + Confidentiality / Integrity / Availability Requirements; (d) SUPPLEMENTAL METRICS (NEW in v4) - Safety + Automatable + Recovery + Value Density + Vulnerability Response Effort + Provider Urgency; (e) MACRO VECTOR - 5-character compressed equivalence-class identifier; (f) QUALITATIVE SEVERITY - None (0.0) / Low (0.1-3.9) / Medium (4.0-6.9) / High (7.0-8.9) / Critical (9.0-10.0). CVSS v4 IMPROVEMENTS: finer-grain
- CVSS calculator integration
- Scoring procedure + evidence
- KEV monitoring + remediation
- Sector-specific Supplemental scoring
- CVSS v3.1 used exclusively (v4 not adopted)
- Supplemental metrics not used
- KEV remediation deadlines missed
FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD) Guidelines. IEP v2.0: a machine-readable extension of TLP that conveys handling restrictions + sharing permissions in structured form (JSON-LD). IEP CATEGORIES: HANDLING (encryption + authentication required + secure transmission + DESTRUCTION); ACTION (PERMITTED + DENIED + ATTRIBUTION-REQUIRED); SHARING (with whom; for how long; under what classification); LICENSE (terms of use). IEP fields complement TLP for automated CTI routing in STIX/TAXII + open-source threat-intel platforms. MPCVD GUIDELINES: best-practice framework for coordinating vulnerability disclosure when MULTIPLE affected vendors or affected parties exist; structured WORKFLOW including: (a) FIRST coordinator role; (b) VENDOR identification + outreach; (c) DISCLOSURE TIMELINE (typically 90 days + extensions) + per-vendor
- IEP integration with CTI platforms
- MPCVD coordination procedure
- Disclosure timeline + evidence
- ISO 29147/30111 mapping
- IEP not used (TLP alone insufficient for automation)
- MPCVD workflow ad-hoc
- Disclosure timeline exceeded without rationale
- ISO 29147/30111 not aligned
FIRST PSIRT (Product Security Incident Response Team) Services Framework v1.1 published December 2020. SCOPE: parallel to CSIRT Services Framework but focused on PRODUCT VENDORS + PRODUCT TEAMS handling vulnerabilities + incidents affecting their products + customers + supply chains. SERVICE AREAS (6): (1) STAKEHOLDER MANAGEMENT - constituency + customer + researcher + supplier + regulator coordination; (2) VULNERABILITY DISCOVERY - intake from researchers + bug bounty + customer + supplier + internal sources; (3) VULNERABILITY TRIAGE + ANALYSIS - CVSS + CVE assignment + reproducibility + impact + scope; (4) REMEDIATION - patch development + workaround + customer communication + verification; (5) VULNERABILITY DISCLOSURE - advisory publication + customer notification + MPCVD coordination + supply-chain notification; (6) TRAINING + EDUCATION - internal product-team training + external res
- PSIRT charter + service catalog
- Bug bounty program + safe harbor
- Patch SLA + customer notification procedure
- No formal PSIRT function
- Bug bounty without safe harbor or coordination
- Patch SLA unclear or unmet
FIRST coordination with national CSIRTs + sector ISACs + regional bodies + regulatory frameworks. NATIONAL CSIRTs (FIRST teams): US-CERT + CISA + DOE-CIRC + DOD-CYBERCOM + UK NCSC + AusCERT + JPCERT/CC + KrCERT/CC + CN-CERT + IR-CERT + many others (FIRST member directory at first.org/members lists 700+ teams). REGIONAL BODIES: (a) ENISA (EU Agency for Cybersecurity) - operates the CSIRTs Network under the NIS Directive + NIS2 + coordinates EU-level cyber crisis response + the CSIRT Network operates under TF-CSIRT (Task Force-CSIRT); (b) APCERT (Asia Pacific CERT) + OIC-CERT (Organization of Islamic Cooperation) + AfricaCERT + LACNIC-CERT; (c) AP-Cybersecurity + NA-Cybersecurity. SECTOR ISACs: Financial Services ISAC (FS-ISAC) + Health ISAC + Aviation ISAC (A-ISAC) + Auto-ISAC + Water-ISAC + Maritime-ISAC + Multi-State ISAC (MS-ISAC) + others - sector-specific threat sharing under FIRST c
- FIRST membership + active participation
- ENISA + NIS2 CSIRTs Network engagement evidence
- ISAC participation + threat sharing
- NIST 800-61 + ISO 27035 alignment
- FIRST membership without engagement
- NIS2 CSIRTs Network coordination skipped
- ISAC participation missing for relevant sector
FIRST standards pipeline + 2024-2025 roadmap. CURRENT STANDARDS: CSIRT Services Framework v2.1 (2019) + CVSS v4.0 (2023) + TLP v2.0 (2022) + IEP v2.0 + MPCVD Guidelines + PSIRT Services Framework v1.1 (2020). UPCOMING + IN DEVELOPMENT: (a) CSIRT Services Framework v3 (anticipated 2026-2027) with refinements for cloud + supply chain + AI-related incident handling; (b) CVSS v4.x interim revisions for emerging-threat metrics; (c) IEP v2.x machine-readable enhancements; (d) SECURITY OPERATIONS SERVICES FRAMEWORK (SOSF) for SOC-style operations; (e) AI INCIDENT RESPONSE GUIDELINES for AI-system incidents + AI Safety Institutes coordination. REGULATORY ALIGNMENT: NIS2 (in force October 2024) + Cybersecurity Act 2024 transpositions in EU Member States; CIRCIA Final Rule effective 2026 for US critical infrastructure (60+ hour notification window); EU CRA (Regulation (EU) 2024/2847) vulnerability
- Standards version tracking + adoption
- Regulatory transposition tracking
- Engagement with FIRST roadmap + working groups
- Standards adoption lagging
- Regulatory transposition not tracked
- FIRST engagement absent
FIRST Traffic Light Protocol (TLP) v2.0 published August 2022 + replaces TLP v1.0. TLP v2 CATEGORIES: (a) TLP:RED - not for disclosure + restricted to participants only + verbal communication preferred; (b) TLP:AMBER - limited disclosure + restricted to participants and their organizations; (c) TLP:AMBER+STRICT (NEW in v2) - limited disclosure + restricted to participants only (NOT their organizations - clarifying v1 TLP:AMBER ambiguity); (d) TLP:GREEN - limited disclosure + restricted to the community; (e) TLP:CLEAR (renamed from TLP:WHITE in v2 for accessibility + inclusiveness) - disclosure is not limited. USAGE GUIDANCE: TLP is recipient-applied + non-binding per FIRST + relies on community trust; TLP markings should be prominently displayed in the header + footer of communications + embedded in metadata for structured data (STIX + IEP + JSON); TLP must be respected per the originato
- TLP marking procedure
- STIX/IEP TLP-tag integration
- Recipient awareness training
- TLP:WHITE used (deprecated; should be TLP:CLEAR)
- TLP:AMBER vs TLP:AMBER+STRICT confused
- Downgrade without originator authorization
FIRST: Service Area 1 - Information Security Event Management
FIRST CSIRT Services Framework v2.1 Service Area 1 - Information Security Event Management (ISEM). SCOPE: identification + analysis of security-relevant events (potential threats not yet escalated to incidents). SUB-SERVICES: (1) MONITORING + DETECTION - SIEM + IDS/IPS + EDR + NetFlow + threat-intel feeds + log aggregation + behavioural anomaly detection + UEBA + threat hunting at perimeter + endpoint + network + cloud + identity layers; (2) EVENT ANALYSIS - first-line triage + enrichment with contextual data + threat intel + asset criticality + likelihood + impact; (3) EVENT CATEGORIZATION + PRIORITIZATION - mapping events to risk levels + escalation criteria + handoff to ISIM if escalated to incident; (4) EVENT REPORTING - structured reporting per TLP + IEP + organisational channels.
- SIEM + EDR + IDS coverage
- Analyst playbook + runbooks
- Categorization + escalation criteria
- Reporting templates per TLP
- Monitoring coverage gaps
- Analyst playbooks stale or missing
- Escalation criteria unclear or inconsistent
FIRST: Service Area 2 - Information Security Incident Management
FIRST CSIRT Services Framework v2.1 Service Area 2 - Information Security Incident Management (ISIM). SCOPE: end-to-end management of confirmed incidents from intake through closure + lessons learned. SUB-SERVICES: (1) INCIDENT REPORT ACCEPTANCE - intake from constituency + sensors + external sources; identity verification + handling per TLP; ticket creation; SLA tracking; (2) INCIDENT ANALYSIS - root-cause investigation + indicators-of-compromise enumeration + scope determination + timeline reconstruction + threat-actor attribution support; (3) ARTEFACT + FORENSIC EVIDENCE ANALYSIS - malware + memory + disk + network forensics + chain-of-custody + tool selection; (4) MITIGATION + RECOVERY - containment + eradication + recovery + post-incident hardening; (5) INCIDENT COORDINATION - cross-organisational + national + international coordination including peer CSIRTs + law enforcement + ISAC
- IR procedure + intake template
- Analysis + forensics evidence + chain-of-custody log
- Mitigation + recovery playbook
- Crisis management plan + escalation matrix
- Intake without identity verification or TLP
- Forensics without chain-of-custody
- Mitigation skipped to recovery
- Crisis management not exercised or exercised infrequently
FIRST: Service Area 3 - Vulnerability Management + Coordinated Disclosure
FIRST CSIRT Services Framework v2.1 Service Area 3 - Vulnerability Management. SCOPE: discovery + tracking + remediation + disclosure of vulnerabilities affecting the constituency. SUB-SERVICES: (1) VULNERABILITY DISCOVERY - active scanning + bug bounty + research + threat intel + supplier notifications; (2) VULNERABILITY REPORT INTAKE - structured intake from researchers + vendors + government via secure channels; (3) VULNERABILITY ANALYSIS - CVSS scoring (Base + Threat + Environmental + Supplemental in CVSS v4 or Base + Temporal + Environmental in CVSS v3.1) + exploitability + scope + privilege + UI metrics + assignment of CVE; (4) VULNERABILITY COORDINATION - multi-party coordinated disclosure per MPCVD Guidelines + ISO/IEC 29147 + ISO/IEC 30111; (5) VULNERABILITY DISCLOSURE - publication of advisory with mitigation + workarounds + technical details + IOCs + TLP classification; (6) VU
- Vulnerability intake + secure channel
- CVSS scoring procedure + scoring evidence
- MPCVD + ISO 29147/30111 alignment
- Advisory templates + KEV monitoring
- CVSS scoring inconsistent or insufficient
- MPCVD coordination ad-hoc
- Advisory without TLP or workarounds
- KEV remediation deadlines missed
FIRST: Service Area 4 - Situational Awareness and Threat Intelligence
FIRST CSIRT Services Framework v2.1 Service Area 4 - Situational Awareness. SCOPE: maintaining + sharing operational + tactical + strategic awareness of the cyber threat landscape relevant to the constituency. SUB-SERVICES: (1) DATA ACQUISITION + COLLECTION - threat-intel feeds (CTI) + ISAC sharing + government feeds + vendor feeds + open-source intelligence (OSINT) + dark-web monitoring + sensor data; (2) ANALYSIS + SYNTHESIS - correlation + enrichment + analytic tradecraft (Diamond Model + Kill Chain + MITRE ATT&CK) + threat actor profiling + campaign tracking + indicator-of-compromise + indicator-of-attack development; (3) COMMUNICATION + DISSEMINATION - tailored bulletins + briefings + alerts to executive + technical + constituency audiences with TLP + IEP + STIX/TAXII machine-readable feeds for automation. COORDINATION: cross-feed with FIRST member CSIRTs + national CSIRT networks +
- CTI feed inventory + license tracking
- Analytic tradecraft + ATT&CK mapping
- STIX/TAXII publication + consumption
- Tailored bulletin templates
- CTI without analyst tradecraft
- STIX/TAXII automation absent or partial
- Bulletins not tailored to audience or lacking TLP
FIRST: Service Area 5 - Knowledge Transfer (Awareness + Training + Exercises)
FIRST CSIRT Services Framework v2.1 Service Area 5 - Knowledge Transfer. SCOPE: building cybersecurity capacity in the constituency + the broader community through awareness + training + exercises + advisory. SUB-SERVICES: (1) AWARENESS BUILDING - phishing simulations + security awareness training + role-specific training + insider risk + supply chain awareness + executive briefings; (2) TRAINING + EDUCATION - technical training for analysts + responders + administrators + developers + with hands-on labs + certifications (FIRST TRANSITS + SANS GIAC + SEI Software Engineering Institute courses); (3) EXERCISES + DRILLS - tabletop exercises + functional exercises + full-scale exercises + red-team / blue-team / purple-team exercises + national + international cyber exercises (e.g. Cyber Storm + Locked Shields + Cyber Europe); (4) TECHNICAL + POLICY ADVISORY - guidance documents + advisories
- Awareness training program + metrics
- Exercise plan + after-action reports
- Advisory publications + standards engagement
- Awareness program inconsistent or unmeasured
- Exercises infrequent or not assessed
- No advisory or standards contribution
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FIRST CSIRT Services Framework and Standards framework page.