From: Royal United Service Institute
By Calum Jeffray, Research Analyst
The UK’s Computer Emergency Response Team (CERT) was launched this week to universal nods of approval. Questions remain, however, over how it will achieve its aims and what value it will add in an increasingly crowded UK network of cyber security teams.
On Monday the Cabinet Office officially launched the UK’s Computer Emergency Response Team (CERT-UK), seen as a key milestone in achieving the objectives laid out in the national Cyber Security Strategy. Speaking at the launch event in central London, officials gave an overview of the CERT’s main functions; in short, providing a centralised incident management response capability in the wake of major cyber attacks, situational awareness and analysis of threats, and a main point of contact for international CERT engagement.
Perhaps most importantly, government, industry and overseas partners now know who to call (or tweet) in a crisis.
However, the very public launch of this initiative elicited few details on set-up and cost. Though it is still early to judge UK-CERT, here are important questions that must be answered at the outset:
1. What’s New?
Although a new entity, it could be argued that CERT-UK does little more than bring together teams that existed previously – namely, the Cyber Security Incident Response Team and Cyber Security Information Sharing Partnership (CISP) – under one management structure.
In this new form, CERT-UK can be placed on the long – and often confusing – list of bodies responsible for anticipating and responding to cyberspace threats in the UK. CERT-UK joins, rather than replaces, other government CERTs such as GovCertUK (assisting public sector organisations in the response to incidents) and MODCERT (responsible for coordinating the Ministry of Defence’s response to incidents).
Indeed, CERT-UK will be the twenty-third CERT in the UK recognised by the European Union Agency for Network and Information Security (ENISA). This is in addition, of course, to bodies such as the Centre for the Protection of National Infrastructure (CPNI) and units such as the National Crime Agency’s National Cyber Crime Unit, who conduct their own situational awareness and threat analyses.
CERT-UK may indeed prove crucial in providing the sorely needed coordinating body between all these different groups, though it is questionable whether its functions of incident management response and situational awareness are not already being provided elsewhere.
Leave a Reply