Omni-CSIRT
RFC 2350
RFC 2350
Omni-CSIRTRFC 2350
Version 1.2 – 6 May 2024
Classification: PUBLIC
Table of Contents
1 Document information
Date of last update
Distribution list for notifications
Locations where this document may be found
Authenticating this document
Document identification
2 Contact information
Name of the team
Address
Time zone
Telephone number
Electronic email address
Other telecommunication
Public keys and encryption information
3 Charter 3
Mission statement
Constituency
Sponsorship and/or affiliation
Authority
4 Policies
Types of incidents and level of support
Co-operation, interaction and disclosure of information
Communication and authentication
5 Services
6 Incident reporting
7 Disclaimer
1 Document information
This document contains a description of Omni-CSIRT in accordance with RFC 2350. It provides basic information about Omni-CSIRT, its channels of communication, and its roles and responsibilities.Distribution list for notifications
N/A.Locations where this document may be found
The current version of this document can be found at: https://omnient.ro/rfc2350Authenticating this document
This document has been approved by Daniel Broasca, the CEO of Omnient.Document identification
| Title | RFC2350 |
| Version | 1.2 |
| Document date | 6 June 2024 |
| Expiration | This document is valid until superseded by a later version |
2 Contact information
Name of the team
| Full name | Omni-CSIRT |
| Short name | Omni |
Address
Omnient S.R.L. 169 Calea Floreasca, IPA Building, 3rd Floor, Bucharest, RomaniaTime zone
EET/EESTTelephone number
+40 21 3117 808Electronic email address
For notifications, incident reporting and operational matters, please contact us at: [email protected] This email address is monitored by a duty officer during hours of operation. For non-operational matters, such as administration-related topics and general inquiries, please send us an email at: [email protected] This email address is monitored by the administrative staff of Omnient during office hours. In case of an emergency, please contact us by phone at +40 21 3117 808. Our days/hours of operation are from 09:00 to 17:00 EET/EEST on business days. We may operate out of these hours and days in case of an emergency only.Other telecommunication
N/A.Public keys and encryption information
We use PGP for functional exchanges (notifications, incident reporting, etc.) with our peers, partners and constituents.| Fingerprint | A424 3BF3 70E3 C5B2 586D 4CE5 48DA 3B6F 8A51 CD1B |
| UID | Omni <[email protected]> |
3 Charter
Mission statement
Established in 2006, Omnient SRL is a leading cybersecurity provider headquartered in Bucharest, Romania. Omnient’s service offerings include risk and compliance management, security assessments, cybersecurity defenses, targeted training and awareness programs, and seamless system integration. Omnient’s experts hold certificates from recognized bodies such as Offensive Security, ISC2, ISACA, EC-Council, and Mile2, allowing us to deliver superior cybersecurity services. Omni-CSIRT’s mission is to manage cybersecurity incidents within Omnient and ensuring the protection of our clients digital assets. The scope of our activities covers prevention, detection, response and recovery. We operate according to the following key values:• Collaboration – Leadership is a team effort based on respect, honesty, and accountability. We positively impact employees, customers, suppliers, and communities by demonstrating integrity and trustworthiness.
• Responsibility – We are committed to protecting the health and security of our constituency, ensuring a secure environment for all.
• Excellence – We deliver the highest service levels, exceeding customer expectations. Our commitment is to serve every customer with flexibility and agility.
• Integrity – Our employees act with honesty and integrity in all incident response. We adhere to ethical practices, comply with regulations and support our communities.
• Partnership – Success relies on loyal, trusting partnerships with other CSIRTs. We commit to fair and collaborative relationships, enhancing our collective cybersecurity capabilities.
Constituency
Internal Constituency: Includes all Omnient departments, employees, infrastructure, and operations within Romania. This encompasses corporate offices, data centers, manufacturing facilities, and any other premises operated by Omnient in the country, as well as remote and virtual work environments. External Constituency: Consists of Omnient’s external stakeholders in Romania, including:• Private sector clients, spanning various industries like finance, energy, and retail.
• Business partners and other organizations that have a contractual relationship with Omnient for the provision of cybersecurity services.
Given the nature of the work, the exact identity of said customers is kept confidential.Sponsorship and/or affiliation
Omni-CSIRT is a service within the Omnient SRL company for incident response, research, and expertise in the field of cyber-security for infrastructure and client’s infrastructure. Omni-CSIRT operates with the authority delegated by Omnient and by the members of its constituency through contractual relationships.Authority
The Omni-CSIRT operates under the authority delegated by Omnient SRL, adhering to the directives of designated personnel. All actions and responses by team members regarding cybersecurity incidents and threat intelligence research are conducted in compliance with applicable laws and regulations. These activities are carried out with the explicit approval of Omnient SRL management and responsible team leaders to meet the needs and requirements of our in-scope clients.4 Policies
Types of incidents and level of support
Omni-CSIRT reserves the right to adjust the priority of an incident based on the circumstances and contractual agreements. While customers can set an initial priority for an incident, Omni-CSIRT maintains the authority to modify this priority following the initial assessment. The level of support provided depends on several factors:• Type and Severity of the Incident: The nature and impact of the security incident.
• Number of Entities Affected: The scope and scale of affected parties.
• Available Resources: The resources Omni-CSIRT can allocate at the time of the incident.
Please note that direct support to end users is provided on a voluntary basis and is subject to our availability. There is no Service Level Agreement (SLA) applicable for direct end-user support.Co-operation, interaction and disclosure of information
Omni-CSIRT handles all information received confidentially, regardless of its priority. When communicating sensitive information, please include the word SENSITIVE in the subject line of the email and use encryption. Furthermore, Omni-CSIRT uses and honors the TLP value set. All Information received without a TLP value is automatically assigned a value of “TLP: AMBER.” Unless required by law or by the customer, Omni-CSIRT does not report incidents to law enforcement. Similarly, Omni-CSIRT will cooperate with law enforcement only if either obligated by law or permitted by the customer. Omni-CSIRT will notify the relevant vendors of previously unknown vulnerabilities discovered during incident responses and will handle the disclosure in accordance with its vulnerability disclosure policy.Communication and authentication
Omni-CSIRT uses GPG for its email communications: messages that do not require confidentiality shall be signed with the sender’s key, messages requiring confidentiality or having sensitive content must be encrypted. This latter requires that Omni-CSIRT have received the partners’ public keys, ideally at the beginning of the contracted service. As an alternative, Omni-CSIRT may use Office365 S/MIME based email encryption to communicate with its constituency. Voice communications shall happen only when the identity of the interlocutor may safely be established, for example using a phone number that has been received in person or provided in the service contract. Communications regarding ongoing incident shall be carried preferentially in person, if not possible over Signal using a video conference so the identity of participants may be established.5 Services
- Incident Response
- Service Overview:
- Triage: All incidents go through a triage phase to determine and validate the incident and its potential extent.
- Management: When mandated, an OMNI-CSIRT Incident Manager will lead the response activities and coordinate among the response teams, the customer, third parties, and law enforcement as needed.
- Resolution: Includes root cause analysis, tactics, techniques, and procedures (TTP) assessment, containment, eradication, and recovery from the incident.
- Threat Intelligence: Research threats to support incident response, digital forensic analysis, or threat hunts.
- Lessons Learned: Post-incident debriefing sessions to improve future incident handling.
- Scope: All types of cyber incidents such as unauthorized access, data breaches, malware infections, and denial of service attacks.
- Service Window: regular business hours, 24/7 based on contract.
- Contact Information:
- Phone: +40 741 155 551
- Email: [email protected]
- Vulnerability Handling
- Service Overview: OMNI-CSIRT identifies, analyzes, and disseminates information about system and software vulnerabilities to coordinate remediation efforts.
- Scope: Vulnerabilities in the constituency’s assets; coordination with vendors for patching.
- Service Window: Regular hours, emergency contact for critical vulnerabilities.
- Malware Analysis
- Service Overview: OMNI-CSIRT examines and analyzes suspicious code or software to understand its behavior, purpose, and impact, advising on containment and remediation.
- Scope: Malware affecting the constituency’s systems and network.
- Service Window: Regular hours, priority for widespread incidents.
- Security Advisory and Alerting
- Service Overview: OMNI-CSIRT provides advisories and alerts on emerging cyber threats, ensuring timely and accurate threat awareness.
- Scope: Cyber threat intelligence relevant to the constituency’s operations.
- Service Window: Continuous monitoring alerts as necessary.
- Cybersecurity Awareness and Training
- Service Overview: OMNI-CSIRT offers training programs and campaigns, developed in partnership with Awakeness.ai, to enhance cybersecurity knowledge and practices within the constituency.
- Scope: Customized training, workshops, webinars.
- Service Window: Scheduled sessions, ongoing campaigns.
