Omni-CSIRT
RFC 2350
Omni-CSIRT

RFC 2350
 
Version 1.2 – 6 May 2024
Classification: PUBLIC


Table of Contents


1  Document information
      Date of last update
      Distribution list for notifications
      Locations where this document may be found
      Authenticating this document
      Document identification
2  Contact information
      Name of the team
      Address
      Time zone
      Telephone number
      Electronic email address
      Other telecommunication
      Public keys and encryption information
3  Charter 3
      Mission statement
      Constituency
      Sponsorship and/or affiliation
      Authority
4  Policies
      Types of incidents and level of support
      Co-operation, interaction and disclosure of information
      Communication and authentication
5  Services
6  Incident reporting
7  Disclaimer

                   
 

1  Document information

This document contains a description of Omni-CSIRT in accordance with RFC 2350. It provides basic information about Omni-CSIRT, its channels of communication, and its roles and responsibilities. Date of last update Version 1.2 – 6 May 2024.

Distribution list for notifications

N/A.

Locations where this document may be found

The current version of this document can be found at: https://omnient.ro/rfc2350

Authenticating this document

This document has been approved by Daniel Broasca, the CEO of Omnient.

Document identification

Title RFC2350
Version 1.2
Document date 6 June 2024
Expiration This document is valid until superseded by a later version
 

2  Contact information

Name of the team

Full name Omni-CSIRT
Short name Omni

Address

Omnient S.R.L. 169 Calea Floreasca, IPA Building, 3rd Floor, Bucharest, Romania

Time zone

EET/EEST

Telephone number

+40 21 3117 808

Electronic email address

For notifications, incident reporting and operational matters, please contact us at: [email protected] This email address is monitored by a duty officer during hours of operation. For non-operational matters, such as administration-related topics and general inquiries, please send us an email at:  [email protected] This email address is monitored by the administrative staff of Omnient during office hours. In case of an emergency, please contact us by phone at +40 21 3117 808. Our days/hours of operation are from 09:00 to 17:00 EET/EEST on business days. We may operate out of these hours and days in case of an emergency only.

Other telecommunication

N/A.

Public keys and encryption information

We use PGP for functional exchanges (notifications, incident reporting, etc.) with our peers, partners and constituents.
Fingerprint A424 3BF3 70E3 C5B2 586D 4CE5 48DA 3B6F 8A51 CD1B
UID Omni <[email protected]>
 

3  Charter

Mission statement

Established in 2006, Omnient SRL is a leading cybersecurity provider headquartered in Bucharest, Romania. Omnient’s service offerings include risk and compliance management, security assessments, cybersecurity defenses, targeted training and awareness programs, and seamless system integration. Omnient’s experts hold certificates from recognized bodies such as Offensive Security, ISC2, ISACA, EC-Council, and Mile2, allowing us to deliver superior cybersecurity services. Omni-CSIRT’s mission is to manage cybersecurity incidents within Omnient and ensuring the protection of our clients digital assets. The scope of our activities covers prevention, detection, response and recovery. We operate according to the following key values:
•   Collaboration – Leadership is a team effort based on respect, honesty, and accountability. We positively impact employees, customers, suppliers, and communities by demonstrating integrity and trustworthiness.
•   Responsibility – We are committed to protecting the health and security of our constituency, ensuring a secure environment for all.
•   Excellence – We deliver the highest service levels, exceeding customer expectations. Our commitment is to serve every customer with flexibility and agility.
•   Integrity – Our employees act with honesty and integrity in all incident response. We adhere to ethical practices, comply with regulations and support our communities.
•   Partnership – Success relies on loyal, trusting partnerships with other CSIRTs. We commit to fair and collaborative relationships, enhancing our collective cybersecurity capabilities.
 

Constituency

Internal Constituency: Includes all Omnient departments, employees, infrastructure, and operations within Romania. This encompasses corporate offices, data centers, manufacturing facilities, and any other premises operated by Omnient in the country, as well as remote and virtual work environments. External Constituency: Consists of Omnient’s external stakeholders in Romania, including:
•   Private sector clients, spanning various industries like finance, energy, and retail.
•   Business partners and other organizations that have a contractual relationship with Omnient for the provision of cybersecurity services.
Given the nature of the work, the exact identity of said customers is kept confidential.  

Sponsorship and/or affiliation

Omni-CSIRT is a service within the Omnient SRL company for incident response, research, and expertise in the field of cyber-security for infrastructure and client’s infrastructure. Omni-CSIRT operates with the authority delegated by Omnient and by the members of its constituency through contractual relationships.

Authority

The Omni-CSIRT operates under the authority delegated by Omnient SRL, adhering to the directives of designated personnel. All actions and responses by team members regarding cybersecurity incidents and threat intelligence research are conducted in compliance with applicable laws and regulations. These activities are carried out with the explicit approval of Omnient SRL management and responsible team leaders to meet the needs and requirements of our in-scope clients.  

4  Policies

Types of incidents and level of support

Omni-CSIRT reserves the right to adjust the priority of an incident based on the circumstances and contractual agreements. While customers can set an initial priority for an incident, Omni-CSIRT maintains the authority to modify this priority following the initial assessment. The level of support provided depends on several factors:
•   Type and Severity of the Incident: The nature and impact of the security incident.
•   Number of Entities Affected: The scope and scale of affected parties.
•   Available Resources: The resources Omni-CSIRT can allocate at the time of the incident.
Please note that direct support to end users is provided on a voluntary basis and is subject to our availability. There is no Service Level Agreement (SLA) applicable for direct end-user support.

Co-operation, interaction and disclosure of information

Omni-CSIRT handles all information received confidentially, regardless of its priority. When communicating sensitive information, please include the word SENSITIVE in the subject line of the email and use encryption. Furthermore, Omni-CSIRT uses and honors the TLP value set. All Information received without a TLP value is automatically assigned a value of “TLP: AMBER.” Unless required by law or by the customer, Omni-CSIRT does not report incidents to law enforcement. Similarly, Omni-CSIRT will cooperate with law enforcement only if either obligated by law or permitted by the customer. Omni-CSIRT will notify the relevant vendors of previously unknown vulnerabilities discovered during incident responses and will handle the disclosure in accordance with its vulnerability disclosure policy.

Communication and authentication

Omni-CSIRT uses GPG for its email communications: messages that do not require confidentiality shall be signed with the sender’s key, messages requiring confidentiality or having sensitive content must be encrypted. This latter requires that Omni-CSIRT have received the partners’ public keys, ideally at the beginning of the contracted service. As an alternative, Omni-CSIRT may use Office365 S/MIME based email encryption to communicate with its constituency. Voice communications shall happen only when the identity of the interlocutor may safely be established, for example using a phone number that has been received in person or provided in the service contract. Communications regarding ongoing incident shall be carried preferentially in person, if not possible over Signal using a video conference so the identity of participants may be established.  

5  Services

  • Incident Response
    • Service Overview:
  • Triage: All incidents go through a triage phase to determine and validate the incident and its potential extent.
  • Management: When mandated, an OMNI-CSIRT Incident Manager will lead the response activities and coordinate among the response teams, the customer, third parties, and law enforcement as needed.
  • Resolution: Includes root cause analysis, tactics, techniques, and procedures (TTP) assessment, containment, eradication, and recovery from the incident.
  • Threat Intelligence: Research threats to support incident response, digital forensic analysis, or threat hunts.
  • Lessons Learned: Post-incident debriefing sessions to improve future incident handling.
    • Scope: All types of cyber incidents such as unauthorized access, data breaches, malware infections, and denial of service attacks.
    • Service Window: regular business hours, 24/7 based on contract.
    • Contact Information:
    • Vulnerability Handling
      • Service Overview: OMNI-CSIRT identifies, analyzes, and disseminates information about system and software vulnerabilities to coordinate remediation efforts.
      • Scope: Vulnerabilities in the constituency’s assets; coordination with vendors for patching.
      • Service Window: Regular hours, emergency contact for critical vulnerabilities.
    • Malware Analysis
      • Service Overview: OMNI-CSIRT examines and analyzes suspicious code or software to understand its behavior, purpose, and impact, advising on containment and remediation.
      • Scope: Malware affecting the constituency’s systems and network.
      • Service Window: Regular hours, priority for widespread incidents.
    • Security Advisory and Alerting
      • Service Overview: OMNI-CSIRT provides advisories and alerts on emerging cyber threats, ensuring timely and accurate threat awareness.
      • Scope: Cyber threat intelligence relevant to the constituency’s operations.
      • Service Window: Continuous monitoring alerts as necessary.
    • Cybersecurity Awareness and Training
      • Service Overview: OMNI-CSIRT offers training programs and campaigns, developed in partnership with Awakeness.ai, to enhance cybersecurity knowledge and practices within the constituency.
      • Scope: Customized training, workshops, webinars.
      • Service Window: Scheduled sessions, ongoing campaigns.
 

6  Incident reporting

Whenever possible, incidents should be reported by email at [email protected], preferably encrypted with our PGP public key. When you contact us, please provide at least the following information:
•   Contact details and organizational information — name of person, organization name and address, email address, telephone number.
•   Short summary of the incident / emergency / crisis and type of event.
•   The event / incident source (e.g. which system produced an alert).
•   Affected system(s).
•   Estimated impact (e.g. loss of communications).
•   Additional information such as details of the observations that led to the discovery of the incident — scanning results (if any), an extract from the log showing the problem, etc.
In case you need to forward any suspicious emails to us, please make sure that all email headers, body and any attachments are included.  

7  Disclaimer

While every precaution is taken in the preparation of information, notifications and alerts, Omni-CSIRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within. This document does not constitute a contract between Omni-CSIRT and its constituency and should be interpreted as presenting and explaining the roles and tasks of Omni-CSIRT. As such, Omni-CSIRT assumes no liability nor obligation as arising from the provision herein.
Omnient
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.