ABSTRACT

In this chapter, we will examine the requirements for a captive in-house investigative team. These “cyber SWAT teams” are referred to as Computer Incident Response Teams (CIRTs), or Computer Emergency Response Teams (CERTs). Most organizations prefer the “CIRT” over “CERT,” to distinguish them from public response teams, such as the “official” CERT at Carnegie-Mellon University.