1. Task Meetings
|Date (dd/mm/yyyy)||Url Indico Agenda||Title||Outcome|
|23/08/2012||https://www.egi.eu/indico/conferenceDisplay.py?confId=1148||EGI CSIRT team Monthly meeting||Review activities of the previous month and plan for the coming month|
|17/09/2012||https://www.egi.eu/indico/conferenceDisplay.py?confId=1160||EGI CSIRT team face to face meeting at EGI Technical Forum, Prague||Review all current activities and plan for the future|
|25/10/2012||https://www.egi.eu/indico/conferenceDisplay.py?confId=1227||EGI CSIRT team monthly meeting||Review activities of the previous month and plan for the coming month|
|Weekly EVO meetings (every Monday)||Minutes recorded in EGI CSIRT private wiki (not publicly accessible)||IRTF weekly meeting||Operational security issues are reviewed weekly|
2. Main Achievements
The incident response team handled one security incidents during the quarter and issued xx security advisories.
Good progress has been made on preparing for SSC6. The execution of this has been postponed until next quarter as integrating the CMS CRAB job management system into the SSC Framework took longer than anticipated.
Preparations have been made for the next EGI-CSIRT security tutorial to happen at the GridKa summer school (August) and at the Technical Forum (September). These will include hands-on forensics exercises.
The Software Vulnerability Group handled xx new vulnerabilities during the quarter and issued two advisories.
Discussions between CSIRT, SVG, and OMB agreed the approach to sites running software for which security support has ended. A general advisory on this was issued by CSIRT and a further advisory has been drafted on the timeline for migration away from gLite 3.2 middleware components.
3. Issues and Mitigation
|Issue Description||Mitigation Description|
4. Plans for the next period
Work will continue on the improvements of the RT/RTIR ticketing system, e.g. to facilitate better reporting.
Work will continue on the monitoring of the migration from unsupported gLite 3.1/3.2 software and the handling and possible suspension of sites who fail.
Work will continue on Pakiti V3 and the move to site-wide security monitoring.
More NGIs will perform the national SSC (2012).
Security training will be prepared for the ISGC2013 conference. This will include hands-on training in forensics.
Work will continue on the annual review of the SVG issue handling procedure.