MANAGERIAL STRATEGIES FOR IMPROVING THE SOCIAL MATURITY OF CYBERSECURITY INCIDENT RESPONSE TEAMS AND MULTITEAM SYSTEMS: A WORKSHOP

No ratings

Presented at First 2017 by

CSIRT social maturity reflects how well members of a cybersecurity team collaborate and coordinate together to complete the performance requirements defined by the team’s mission. Establishing the social maturity of a cybersecurity incident response team (CSIRT) represents a critical challenge for CSIRT managers. As an extension of our recently completed work on a four-year, DHS-funded project examining social maturity in CSIRTs, we are offering a three-hour workshop at FIRST 2017 to share our findings and offer strategies and best practices to CSIRT managers for improving CSIRT social maturity from a socio-behavioral perspective. The findings and recommendations we share have been derived from our interviews with representatives of 52 CSIRTs and surveys taken by nearly 90 CSIRT members. In the workshop, we will first define the social maturity challenges we found to be facing CSIRT managers in setting up and maintaining effective CSIRTs. Then we will present staffing and training strategies that establish an effective foundation for collaboration. We will also share strategies for establishing and managing strong collaboration and coordination between cybersecurity teams that exist in what we refer to as CSIR-multiteam systems, or CSIR-MTS. This will lead us to the managerial handbook we created based on our research findings, and we will provide access to a digital copy of the handbook during the workshop. The handbook presents a set of management tools for assessing CSIRT social maturity and delineates the appropriate strategies for improving upon the challenges identified through those tools. These strategies and tools are supported by best practices from socio-behavioral psychology research focused on enhancing team collaboration and coordination. Lastly, we will provide attendees with opportunities and coaching to understand how to take these tools and apply them to their own cybersecurity teams.