Services for the
Academic Network
Academic CSIRT provides a coordinated framework for managing cybersecurity within the Montenegrin academic sector We operate as an advisory and coordinating entity, facilitating collaboration among higher education institutions and acting as an interface toward national and international cybersecurity stakeholders
01. Information Security Event Management (ISEM)
This service area focuses on coordinating and providing expert advice related to the management of information security events Academic CSIRT does not operate a SOC, but guides its constituents on the proper handling, reporting, and analysis of security events
Key Outcome:
Constituents receive expert guidance that helps them implement effective monitoring and detection processes
// Log & Sensor Advisory
Guiding constituents in selecting and maintaining appropriate event sources, log management, and sensor capabilities
// Detection Use Case Guidance
Providing expert advice on developing and refining detection scenarios to prioritize critical alerts
02. Information Security Incident Management
Report Acceptance
Providing secure channels (email, portal) for receiving potential incident reports and ensuring they are properly validated and categorized
Incident Analysis
Advising constituents on incident evaluation, root cause understanding, and response strategies in coordination with external experts
Artefact Advisory
Guidance on safe collection, storage, and interpretation of digital artefacts (malware, memory dumps) to ensure forensic integrity
// Mitigation & Recovery
Supporting constituents in developing response plans, recommending immediate containment measures, and guiding secure system restoration
Note: "Academic CSIRT does not perform direct technical mitigation, but facilitates response through coordination with external entities and vendors"
03. Vulnerability Management
| Service Component | Description of Advisory |
|---|---|
| Discovery | Identification of new vulnerabilities through monitoring public sources and databases |
| Coordination | Acting as a liaison among vulnerability reporters, vendors, and academic system owners |
| Disclosure | Coordinated dissemination of vulnerability information through official advisories after analysis |
| Response | Advising on detection methods (scanning) and remediation priorities for system owners |
CVD Framework
We manage the Coordinated Vulnerability Disclosure (CVD) process to ensure responsible information sharing without compromising academic network stability