Scoping, aims and context of the workshop. Agreement on the agenda
Target Audience Analysis
2.1 Identify communication endpoints, for example: Management, Peer Infras, Site/NGI Security Endpoints
2.2 for these endpoints define
Why are we sending the notification.
Who should get an advisory, incident notification
What should be the content of this communication
Definition of Performance Indicators, for ex.
Time from issue (Incident, Vulnerability, etc) report till final assessment
Time from issue (Incident, Vulnerability, etc.) report till report to clients
How to get a transparent Risk Assessment? Adapted CVSS-3?
Discussion Risk Levels
Communication Templates (As needed for the Updated Handling Process)
3.1 Vulnerabilities (Recipients as defined at day-1)
3.2 Incidents (Recipients as defined at day-1)
Inventory of tools needed (goc-db, ipmt, rt(-ir) etc etc)