Skip to content

Evidence request lists

FIRST CSIRT Services Framework and Standards

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FIRST: CSIRT Services Framework v2.1 - Foundational and Mandate

FIRST-CSIRTF-Mandate-Quality
CSIRT Services Framework v2.1 - Mandate, Scope and Quality Management

FIRST CSIRT Services Framework v2.1 (2019) Foundational. MANDATE + SCOPE: the CSIRT must have a CLEARLY DOCUMENTED MANDATE from its parent organisation (national authority + sector authority + corporate executive) defining: (a) AUTHORITY level (advisory + coordinating + commanding); (b) CONSTITUENCY (the user community served); (c) SERVICE AREAS provided (subset of the 5 in the framework); (d) DELIVERY MODEL (centralized + distributed + outsourced + hybrid); (e) FUNDING + STAFFING; (f) RELATIONSHIP with parent organisation + peer CSIRTs + national + international cooperation. The MANDATE is typically formalized in a CHARTER + Terms of Reference + Service Level Agreement. QUALITY MANAGEMENT + METRICS: CSIRTs operate quality management processes per CSIRT Maturity Models (e.g. SIM3 + CMMI-style); metrics include incident response time + customer satisfaction + service coverage + skills dev

Artefacts an auditor will ask for
  • CSIRT charter + ToR + SLA
  • Quality metrics + SIM3 assessment
  • Constituency + service area documentation
Where this commonly fails
  • Mandate unclear or undocumented
  • SLAs not measured or reported
  • SIM3 assessment skipped

FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

FIRST-CVSS-v4
FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy

FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Interaction + Vulnerable System Impact + Subsequent System Impact (Confidentiality + Integrity + Availability for each); (b) THREAT METRICS (replacing v3.1 Temporal) - Exploit Maturity; (c) ENVIRONMENTAL METRICS - Modified Base + Confidentiality / Integrity / Availability Requirements; (d) SUPPLEMENTAL METRICS (NEW in v4) - Safety + Automatable + Recovery + Value Density + Vulnerability Response Effort + Provider Urgency; (e) MACRO VECTOR - 5-character compressed equivalence-class identifier; (f) QUALITATIVE SEVERITY - None (0.0) / Low (0.1-3.9) / Medium (4.0-6.9) / High (7.0-8.9) / Critical (9.0-10.0). CVSS v4 IMPROVEMENTS: finer-grain

Artefacts an auditor will ask for
  • CVSS calculator integration
  • Scoring procedure + evidence
  • KEV monitoring + remediation
  • Sector-specific Supplemental scoring
Where this commonly fails
  • CVSS v3.1 used exclusively (v4 not adopted)
  • Supplemental metrics not used
  • KEV remediation deadlines missed
FIRST-IEP-MPCVD
FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD)

FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD) Guidelines. IEP v2.0: a machine-readable extension of TLP that conveys handling restrictions + sharing permissions in structured form (JSON-LD). IEP CATEGORIES: HANDLING (encryption + authentication required + secure transmission + DESTRUCTION); ACTION (PERMITTED + DENIED + ATTRIBUTION-REQUIRED); SHARING (with whom; for how long; under what classification); LICENSE (terms of use). IEP fields complement TLP for automated CTI routing in STIX/TAXII + open-source threat-intel platforms. MPCVD GUIDELINES: best-practice framework for coordinating vulnerability disclosure when MULTIPLE affected vendors or affected parties exist; structured WORKFLOW including: (a) FIRST coordinator role; (b) VENDOR identification + outreach; (c) DISCLOSURE TIMELINE (typically 90 days + extensions) + per-vendor

Artefacts an auditor will ask for
  • IEP integration with CTI platforms
  • MPCVD coordination procedure
  • Disclosure timeline + evidence
  • ISO 29147/30111 mapping
Where this commonly fails
  • IEP not used (TLP alone insufficient for automation)
  • MPCVD workflow ad-hoc
  • Disclosure timeline exceeded without rationale
  • ISO 29147/30111 not aligned
FIRST-PSIRT-Services
FIRST PSIRT Services Framework (2020) - Product Security Incident Response Team Service Catalog

FIRST PSIRT (Product Security Incident Response Team) Services Framework v1.1 published December 2020. SCOPE: parallel to CSIRT Services Framework but focused on PRODUCT VENDORS + PRODUCT TEAMS handling vulnerabilities + incidents affecting their products + customers + supply chains. SERVICE AREAS (6): (1) STAKEHOLDER MANAGEMENT - constituency + customer + researcher + supplier + regulator coordination; (2) VULNERABILITY DISCOVERY - intake from researchers + bug bounty + customer + supplier + internal sources; (3) VULNERABILITY TRIAGE + ANALYSIS - CVSS + CVE assignment + reproducibility + impact + scope; (4) REMEDIATION - patch development + workaround + customer communication + verification; (5) VULNERABILITY DISCLOSURE - advisory publication + customer notification + MPCVD coordination + supply-chain notification; (6) TRAINING + EDUCATION - internal product-team training + external res

Artefacts an auditor will ask for
  • PSIRT charter + service catalog
  • Bug bounty program + safe harbor
  • Patch SLA + customer notification procedure
Where this commonly fails
  • No formal PSIRT function
  • Bug bounty without safe harbor or coordination
  • Patch SLA unclear or unmet
FIRST-Sectoral-NationalCSIRT
FIRST Sectoral Coordination - National CSIRTs, ISACs, ENISA, NIS2 + Industry Frameworks

FIRST coordination with national CSIRTs + sector ISACs + regional bodies + regulatory frameworks. NATIONAL CSIRTs (FIRST teams): US-CERT + CISA + DOE-CIRC + DOD-CYBERCOM + UK NCSC + AusCERT + JPCERT/CC + KrCERT/CC + CN-CERT + IR-CERT + many others (FIRST member directory at first.org/members lists 700+ teams). REGIONAL BODIES: (a) ENISA (EU Agency for Cybersecurity) - operates the CSIRTs Network under the NIS Directive + NIS2 + coordinates EU-level cyber crisis response + the CSIRT Network operates under TF-CSIRT (Task Force-CSIRT); (b) APCERT (Asia Pacific CERT) + OIC-CERT (Organization of Islamic Cooperation) + AfricaCERT + LACNIC-CERT; (c) AP-Cybersecurity + NA-Cybersecurity. SECTOR ISACs: Financial Services ISAC (FS-ISAC) + Health ISAC + Aviation ISAC (A-ISAC) + Auto-ISAC + Water-ISAC + Maritime-ISAC + Multi-State ISAC (MS-ISAC) + others - sector-specific threat sharing under FIRST c

Artefacts an auditor will ask for
  • FIRST membership + active participation
  • ENISA + NIS2 CSIRTs Network engagement evidence
  • ISAC participation + threat sharing
  • NIST 800-61 + ISO 27035 alignment
Where this commonly fails
  • FIRST membership without engagement
  • NIS2 CSIRTs Network coordination skipped
  • ISAC participation missing for relevant sector
FIRST-Status-Pipeline
FIRST Standards Pipeline - 2024-2025 Roadmap and Coordination with NIS2, CIRCIA, EU CRA

FIRST standards pipeline + 2024-2025 roadmap. CURRENT STANDARDS: CSIRT Services Framework v2.1 (2019) + CVSS v4.0 (2023) + TLP v2.0 (2022) + IEP v2.0 + MPCVD Guidelines + PSIRT Services Framework v1.1 (2020). UPCOMING + IN DEVELOPMENT: (a) CSIRT Services Framework v3 (anticipated 2026-2027) with refinements for cloud + supply chain + AI-related incident handling; (b) CVSS v4.x interim revisions for emerging-threat metrics; (c) IEP v2.x machine-readable enhancements; (d) SECURITY OPERATIONS SERVICES FRAMEWORK (SOSF) for SOC-style operations; (e) AI INCIDENT RESPONSE GUIDELINES for AI-system incidents + AI Safety Institutes coordination. REGULATORY ALIGNMENT: NIS2 (in force October 2024) + Cybersecurity Act 2024 transpositions in EU Member States; CIRCIA Final Rule effective 2026 for US critical infrastructure (60+ hour notification window); EU CRA (Regulation (EU) 2024/2847) vulnerability

Artefacts an auditor will ask for
  • Standards version tracking + adoption
  • Regulatory transposition tracking
  • Engagement with FIRST roadmap + working groups
Where this commonly fails
  • Standards adoption lagging
  • Regulatory transposition not tracked
  • FIRST engagement absent
FIRST-TLP-v2
FIRST Traffic Light Protocol (TLP) v2.0 (2022) - Information-Sharing Classification

FIRST Traffic Light Protocol (TLP) v2.0 published August 2022 + replaces TLP v1.0. TLP v2 CATEGORIES: (a) TLP:RED - not for disclosure + restricted to participants only + verbal communication preferred; (b) TLP:AMBER - limited disclosure + restricted to participants and their organizations; (c) TLP:AMBER+STRICT (NEW in v2) - limited disclosure + restricted to participants only (NOT their organizations - clarifying v1 TLP:AMBER ambiguity); (d) TLP:GREEN - limited disclosure + restricted to the community; (e) TLP:CLEAR (renamed from TLP:WHITE in v2 for accessibility + inclusiveness) - disclosure is not limited. USAGE GUIDANCE: TLP is recipient-applied + non-binding per FIRST + relies on community trust; TLP markings should be prominently displayed in the header + footer of communications + embedded in metadata for structured data (STIX + IEP + JSON); TLP must be respected per the originato

Artefacts an auditor will ask for
  • TLP marking procedure
  • STIX/IEP TLP-tag integration
  • Recipient awareness training
Where this commonly fails
  • TLP:WHITE used (deprecated; should be TLP:CLEAR)
  • TLP:AMBER vs TLP:AMBER+STRICT confused
  • Downgrade without originator authorization

FIRST: Service Area 1 - Information Security Event Management

FIRST-CSIRTF-SA1-ISEM
Service Area 1 - Information Security Event Management (Monitoring, Detection, Triage)

FIRST CSIRT Services Framework v2.1 Service Area 1 - Information Security Event Management (ISEM). SCOPE: identification + analysis of security-relevant events (potential threats not yet escalated to incidents). SUB-SERVICES: (1) MONITORING + DETECTION - SIEM + IDS/IPS + EDR + NetFlow + threat-intel feeds + log aggregation + behavioural anomaly detection + UEBA + threat hunting at perimeter + endpoint + network + cloud + identity layers; (2) EVENT ANALYSIS - first-line triage + enrichment with contextual data + threat intel + asset criticality + likelihood + impact; (3) EVENT CATEGORIZATION + PRIORITIZATION - mapping events to risk levels + escalation criteria + handoff to ISIM if escalated to incident; (4) EVENT REPORTING - structured reporting per TLP + IEP + organisational channels.

Artefacts an auditor will ask for
  • SIEM + EDR + IDS coverage
  • Analyst playbook + runbooks
  • Categorization + escalation criteria
  • Reporting templates per TLP
Where this commonly fails
  • Monitoring coverage gaps
  • Analyst playbooks stale or missing
  • Escalation criteria unclear or inconsistent

FIRST: Service Area 2 - Information Security Incident Management

FIRST-CSIRTF-SA2-ISIM
Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

FIRST CSIRT Services Framework v2.1 Service Area 2 - Information Security Incident Management (ISIM). SCOPE: end-to-end management of confirmed incidents from intake through closure + lessons learned. SUB-SERVICES: (1) INCIDENT REPORT ACCEPTANCE - intake from constituency + sensors + external sources; identity verification + handling per TLP; ticket creation; SLA tracking; (2) INCIDENT ANALYSIS - root-cause investigation + indicators-of-compromise enumeration + scope determination + timeline reconstruction + threat-actor attribution support; (3) ARTEFACT + FORENSIC EVIDENCE ANALYSIS - malware + memory + disk + network forensics + chain-of-custody + tool selection; (4) MITIGATION + RECOVERY - containment + eradication + recovery + post-incident hardening; (5) INCIDENT COORDINATION - cross-organisational + national + international coordination including peer CSIRTs + law enforcement + ISAC

Artefacts an auditor will ask for
  • IR procedure + intake template
  • Analysis + forensics evidence + chain-of-custody log
  • Mitigation + recovery playbook
  • Crisis management plan + escalation matrix
Where this commonly fails
  • Intake without identity verification or TLP
  • Forensics without chain-of-custody
  • Mitigation skipped to recovery
  • Crisis management not exercised or exercised infrequently

FIRST: Service Area 3 - Vulnerability Management + Coordinated Disclosure

FIRST-CSIRTF-SA3-VulnMgmt
Service Area 3 - Vulnerability Management and Coordinated Disclosure

FIRST CSIRT Services Framework v2.1 Service Area 3 - Vulnerability Management. SCOPE: discovery + tracking + remediation + disclosure of vulnerabilities affecting the constituency. SUB-SERVICES: (1) VULNERABILITY DISCOVERY - active scanning + bug bounty + research + threat intel + supplier notifications; (2) VULNERABILITY REPORT INTAKE - structured intake from researchers + vendors + government via secure channels; (3) VULNERABILITY ANALYSIS - CVSS scoring (Base + Threat + Environmental + Supplemental in CVSS v4 or Base + Temporal + Environmental in CVSS v3.1) + exploitability + scope + privilege + UI metrics + assignment of CVE; (4) VULNERABILITY COORDINATION - multi-party coordinated disclosure per MPCVD Guidelines + ISO/IEC 29147 + ISO/IEC 30111; (5) VULNERABILITY DISCLOSURE - publication of advisory with mitigation + workarounds + technical details + IOCs + TLP classification; (6) VU

Artefacts an auditor will ask for
  • Vulnerability intake + secure channel
  • CVSS scoring procedure + scoring evidence
  • MPCVD + ISO 29147/30111 alignment
  • Advisory templates + KEV monitoring
Where this commonly fails
  • CVSS scoring inconsistent or insufficient
  • MPCVD coordination ad-hoc
  • Advisory without TLP or workarounds
  • KEV remediation deadlines missed

FIRST: Service Area 4 - Situational Awareness and Threat Intelligence

FIRST-CSIRTF-SA4-SituationalAwareness
Service Area 4 - Situational Awareness and Threat Intelligence

FIRST CSIRT Services Framework v2.1 Service Area 4 - Situational Awareness. SCOPE: maintaining + sharing operational + tactical + strategic awareness of the cyber threat landscape relevant to the constituency. SUB-SERVICES: (1) DATA ACQUISITION + COLLECTION - threat-intel feeds (CTI) + ISAC sharing + government feeds + vendor feeds + open-source intelligence (OSINT) + dark-web monitoring + sensor data; (2) ANALYSIS + SYNTHESIS - correlation + enrichment + analytic tradecraft (Diamond Model + Kill Chain + MITRE ATT&CK) + threat actor profiling + campaign tracking + indicator-of-compromise + indicator-of-attack development; (3) COMMUNICATION + DISSEMINATION - tailored bulletins + briefings + alerts to executive + technical + constituency audiences with TLP + IEP + STIX/TAXII machine-readable feeds for automation. COORDINATION: cross-feed with FIRST member CSIRTs + national CSIRT networks +

Artefacts an auditor will ask for
  • CTI feed inventory + license tracking
  • Analytic tradecraft + ATT&CK mapping
  • STIX/TAXII publication + consumption
  • Tailored bulletin templates
Where this commonly fails
  • CTI without analyst tradecraft
  • STIX/TAXII automation absent or partial
  • Bulletins not tailored to audience or lacking TLP

FIRST: Service Area 5 - Knowledge Transfer (Awareness + Training + Exercises)

FIRST-CSIRTF-SA5-KnowledgeTransfer
Service Area 5 - Knowledge Transfer (Awareness, Training, Exercises, Advisory)

FIRST CSIRT Services Framework v2.1 Service Area 5 - Knowledge Transfer. SCOPE: building cybersecurity capacity in the constituency + the broader community through awareness + training + exercises + advisory. SUB-SERVICES: (1) AWARENESS BUILDING - phishing simulations + security awareness training + role-specific training + insider risk + supply chain awareness + executive briefings; (2) TRAINING + EDUCATION - technical training for analysts + responders + administrators + developers + with hands-on labs + certifications (FIRST TRANSITS + SANS GIAC + SEI Software Engineering Institute courses); (3) EXERCISES + DRILLS - tabletop exercises + functional exercises + full-scale exercises + red-team / blue-team / purple-team exercises + national + international cyber exercises (e.g. Cyber Storm + Locked Shields + Cyber Europe); (4) TECHNICAL + POLICY ADVISORY - guidance documents + advisories

Artefacts an auditor will ask for
  • Awareness training program + metrics
  • Exercise plan + after-action reports
  • Advisory publications + standards engagement
Where this commonly fails
  • Awareness program inconsistent or unmeasured
  • Exercises infrequent or not assessed
  • No advisory or standards contribution
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FIRST CSIRT Services Framework and Standards framework page.