Service Area: Higher Education & Research

Services for the
Academic Network

Academic CSIRT provides a coordinated framework for managing cybersecurity within the Montenegrin academic sector We operate as an advisory and coordinating entity, facilitating collaboration among higher education institutions and acting as an interface toward national and international cybersecurity stakeholders

01. Information Security Event Management (ISEM)

This service area focuses on coordinating and providing expert advice related to the management of information security events Academic CSIRT does not operate a SOC, but guides its constituents on the proper handling, reporting, and analysis of security events

Key Outcome:

Constituents receive expert guidance that helps them implement effective monitoring and detection processes

// Log & Sensor Advisory

Guiding constituents in selecting and maintaining appropriate event sources, log management, and sensor capabilities

// Detection Use Case Guidance

Providing expert advice on developing and refining detection scenarios to prioritize critical alerts

02. Information Security Incident Management

Report Acceptance

Providing secure channels (email, portal) for receiving potential incident reports and ensuring they are properly validated and categorized

>> STATUS: OPERATIONAL

Incident Analysis

Advising constituents on incident evaluation, root cause understanding, and response strategies in coordination with external experts

>> STATUS: ADVISORY_ONLY

Artefact Advisory

Guidance on safe collection, storage, and interpretation of digital artefacts (malware, memory dumps) to ensure forensic integrity

>> STATUS: EXPERT_SUPPORT

// Mitigation & Recovery

Supporting constituents in developing response plans, recommending immediate containment measures, and guiding secure system restoration

Note: "Academic CSIRT does not perform direct technical mitigation, but facilitates response through coordination with external entities and vendors"

03. Vulnerability Management

Service Component Description of Advisory
Discovery Identification of new vulnerabilities through monitoring public sources and databases
Coordination Acting as a liaison among vulnerability reporters, vendors, and academic system owners
Disclosure Coordinated dissemination of vulnerability information through official advisories after analysis
Response Advising on detection methods (scanning) and remediation priorities for system owners

CVD Framework

We manage the Coordinated Vulnerability Disclosure (CVD) process to ensure responsible information sharing without compromising academic network stability

<< Return to Main Console