RFC 2350 Expectations for Computer Security Incident Response for SOC BLUE energy ================================= 1. About this document 1.1 Date of Last Update This is version 1.0, published on 12 July 2018. 1.2 Distribution List for Notifications There is no distribution list for notifications. 1.3 Locations where this Document May Be Found The current version of this document can always be found at the BLUE energy website: https://www.grupablue.pl/rfc2350.txt and https://www.bluesec.pl/rfc2350.txt 1.4 Authenticating this document This document has been signed with the PGP key of BLUE energy. See section 2.8 for more details. 2. Contact Information 2.1 Name of the Team SOC BLUE energy 2.2 Address BLUE energy Sp. z o.o. ul. Towarowa 35 61-896 Poznań Poland 2.3 Time Zone Central European Time (GMT+0100, GMT+0200 from April to October) 2.4 Telephone Number +48 61 643 51 98 2.5 Facsimile Number Inaccessible. 2.6 Other Telecommunication Inaccessible. 2.7 Electronic Mail Address soc@grupablue.pl 2.8 Public keys and Other Encryption Information BLUE energy has a own PGP key. KeyID: 3865A8CDDA191C55 and Fingerprint: 3FA2FAA234EBA17B6BDC07613865A8CDDA191C55 2.9 Other Information Operational contact is carried out from Monday to Friday between 9:00 am and 5:00 pm. General information about SOC BLUE energy, as well as links to various recommended security resources, can be found at: https://www.grupablue.pl/ https://www.bluesec.pl 2.10 Points of Customer Contact The preferred method for contacting SOC BLUE energy is via e-mail at Please remember to use PGP encryption when sending any sensitive information. 3. Charter 3.1 Mission Statement Monitoring and response to IT security incidents. Threat hunting. Vulnerability management. Security of ICT systems. 3.2 Consituency We provide monitoring and response services to a security incident for public organizations and private companies. 3.3 Sponsorship and/or Affiliation Blue energy Sp. z o.o., ul. Towarowa 35, 61-896 Poznań Registration data: NIP: 7781473428, KRS: 0000361608 3.4 Authority SOC BLUE energy is acting in the field of ICT security in the field of ICT services for clients. The service is provided based on a commercial contract. 4. Policies 4.1 Types of Incidents and Level of Support SOC BLUE energy handles all ICT security incidents within the customer's ICT infrastructure. SOC BLUE energy ensures the implementation of the full incident response process, from its identification through remediation and implementation of preventive action. The level of support and responsibility in the area of incident response are specified in commercial agreements between the Customer and BLUE energy. 4.2 Co-operation, Interaction and Disclosure of Information SOC BLUE energy exchanges all necessary information with other CSIRTs as well as with affected parties' administrators. 4.3 Communication and Authentication In view of the types of information that SOC BLUE energy deals with, telephones will be considered sufficiently secure to be used even unencrypted. Unencrypted e-mail will not be considered particularly secure, but will be sufficient for the transmission of low-sensitivity data. 5. Services 5.1 Incident Response SOC BLUE energy will assist system administrators in handling the technical and organizational aspects of the incidents. 5.1.1 Incident Triage - Investigating whether indeed an incident occured. - Determining the extent of the incident. 5.1.2 Incident Coordination - Determining the initial cause of the incident (vulnerability exploited) - Facilitating contact with other sites which may be involved. - Facilitating contact with appropriate law enforcement officials, if necessary. - Making reports to other SOCs/CSIRTs - Composing announcements to users, if applicable 5.1.3 Incident Resolution SOC BLUE energy will give advice incident resolution. - Removing the vulnerability. - Securing the system from the effects of the incident. - Evaluating whether certain actions are likely to reap results in proportion to their cost and risk. - Collecting the evidence of the incident. 5.2 Vulnerability assessment SOC BLUE energy supports clients in actively identifying vulnerabilities and their mitigation. 5.3 Penetration tests SOC BLUE energy supports clients in practical security testing of ICT systems security. 5.4 Proactive Services SOC BLUE energy offers proactive services. The full range of services is available on our websites. 6. Incident Reporting Forms SOC BLUE energy uses a standardized report. All information regarding reporting is agreed with Clients and other partner units. 7. Disclaimers While every precaution will be taken in the preparation of information, notifications and alerts, SOC BLUE energy assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within. -----BEGIN PGP PUBLIC KEY BLOCK----- mQENBFxkeYYBCAC3wvpGxBnm1evRgQThbEfcECCNMuTQkQvOI9IZ3inetCtJ0gKA MXVkDhyVyHGhQyfS2efU+zxuwFfKeTDK/5NFs6lYJSaKt/p0xehtd0pFfCmauB2T xej3p2uXtmJ7TsoQ07cjT7KE2S+Y6SyYX4RYE7mm5sE4t79XjsYSn2GOGrsqSOXf yCqtht0bnTLIxN0OoZIW2OOOhXezjqpZJSv1X/XgKU8Lkhd0IpU+9rWawA++atvW QOzC3dbXNZdkd1MgDifK28hDEo6jX0ZsAzbI9eSubFS82v3O+5J9hF1OQPKUNJqj tI8dfsydNA/1StL5kGEHoxxt1S+i7OmB+oGrABEBAAG0KUJMVUUgZW5lcmd5IFNw LiB6IG8uby4gPHNvY0BncnVwYWJsdWUucGw+iQFUBBMBCAA+AhsDBQsJCAcCBhUK CQgLAgQWAgMBAh4BAheAFiEEP6L6ojTroXtr3AdhOGWozdoZHFUFAl/ZwaAFCQVq aSoACgkQOGWozdoZHFXCLAf/SQkLiJHvRtnBZH+cArG4SJSuQWZ4EZAQUWMTGPr9 HKk+QlHj0EZQTno3jaIVztxDiplW5eT3YLuf/Nv9TpRGPrWbuNg/DBIWv5dsLS60 ehbNfFD20zymCw1fBoLvKOulxbR5N+OBVxsKzFHsZDIMk2jRBJ6hxakDdgITbEt2 Mbp/Rqqh9PfnJYX2vGGaviXUkonJHgUax+Ezv/zv/vji/mOx36Z9Yz/CUb4vei6q A+t/5trG8ylfDSB2J00d7n78gcLd4iFL/nhtkZXWfFxtc4WEfs5WIwDnPF9EIfPx W0sV3iqb2HARrNRrwFPov86OUeG1G4v3PcQJLDgUCZ85C4kCMwQQAQgAHRYhBGmS yucwkqfLhpRo1aMIdNqkPeDwBQJddRSmAAoJEKMIdNqkPeDwc0oP/1zSNs4SEihO ws9VhooBRZ2Gns81fXlAM5pcSk+fcH5yYUodSmlBPhNtxycI7Nxuw93IOMo+nopX xM9/pZAj54TgKpcKAUL7C45ZFkNC/Er1sy1lJbFYrNqaFYy6mKJAaPC3QeSU8glD pXgJnJasHc1hjsKHVkJJyhJoaZazA6M1uQPTTbDnja26tLMRkm3jL83eUFUVW1R4 vkkRK0H6Ifg+1eAm2DHDaJQZUczJZemUgrHp7hiZ/5h6G2CQ4jOxkIctyJuP6uaw p7+B+uVvdtXXdjn4Hc4GTAddW1fLQ9muoGS3h8tcGOqTcUy35uZCtXqaT8vr2v1i oPZp+6gPw+X9zKdG5MvBDEoqKtGkZvd1xLB5XXiauEGctBU2ZmjlaHB3MzMB9yf3 jTgQT69fvqX9itNSQsvCsu1Ecav2K19t+8V+qNJbapECy17j7QI1/+WJlAcdmgg5 ux4TPt5UXtRG587VuLAmR23/OSgMWI3cYynDsz33rv5lIWQVM6Wlurnz/e5BMOOs neYOepE9C0F0tJWkpPUhY83EscMyQSZ9k0EMt+EWcVtxhel0XEoMW4RsXfqqtRcF NzWnQNhUm4hXvNQVhuBdaf2WMkSvTWTaKdC5UsZV+ue/JNIXSOPhmysQRfga4WWE XkGyBEhQarPpprSF2L3Al/5V4ABRIDtruQENBFxkeYYBCACwksqREmmR3DI8AoRF Ej7oY3mjWRCxi6XYQlW3IVJbdYE05Xz1ryzKFf69mf4o5VMrRTjosfNc/XfQq8KM OBXZcIPDYFbQbQn6TWvuM76SYJ0/Aa1e7ieGRNVXz2TJDgIoxrr2/8ULQfKRbMvB VFODkPY0O26ZN2QaJUN1Z9sWAmBTyDX6vtw7cvlq0+OwvUlgZU+aaWqZMbCl4I60 YKFMMT/r264P+Q9rVGW6JQnIxQaH8xGfcMGy0TZPNhiX22Nc8jA6oaeJ1poqE1Je y4GM0RXiIAufH7D51c1QIvLfqR5HGZSPHDgBHIBey0WjFFYduY1Ub5knwGsaM+HE J4mPABEBAAGJATwEGAEIACYWIQQ/ovqiNOuhe2vcB2E4ZajN2hkcVQUCXGR5hgIb DAUJA4k1qgAKCRA4ZajN2hkcVTyWCACkZ3uP5aRhGklLi826ZmMylJ4iS5rKtTNy Uqn1VG4J6HDRRLEfWChp5SnG9Rs08Ub10vhDAxrEMPsA5g2mJiESbXtZtrFC44V/ XdbsmCKg8PGS7eALoZ/LTUs5weeSjZsBJNzwk3Rm+res3gY3yXYyPawE8BI5ipkl e350U9atmDM5tnoJOoeoDq68V+cAas55k2hug0YL+cGlJhp/3D8r2XbwuULvik7M UPYNDidnl+RvBa236dP8tTfk0Wf+hkZyKyXHlLQvzBbhNBONQLu4LaTenkMLRjns LDDAtm8+9IAP4YnXl+rRK40MBIdU1emOTbFSccThvpdbndqw5B+v =kPPy -----END PGP PUBLIC KEY BLOCK-----