The STEAM-CIRT acts as the "triage" center for all event reports it receives. These event reports, correspondence, supporting data, and information requests are prioritized for handling.
Any event which could be considered an IT Incident, as defined by the IT Incident Response Policy, should be reported to the STEAM-CIRT.
Please note that for each IT Incident processed, the STEAM-CIRT will assign it a unique tracking number. This tracking number should be referenced in all correspondence regarding the IT Incident.
The STEAM-CIRT provides IT Incident notification and coordination as one of its most important core services. The STEAM-CIRT maintains a master contact list of Purdue Security Contacts (PSCs) which represent each IT department. When an IT Incident occurs, the STEAM-CIRT notifies and works with the appropriate PSCs to remediate the IT Incident.
To aid in the response to IT Incidents, the STEAM-CIRT provides IT Incident analysis support to PSCs responding to an IT Incident in addition to its initial analysis performed at Incident Triage.
The depth at which the STEAM-CIRT analyzes IT Incidents will vary for each one and is dependent on many factors including scope, severity, chance of repeat occurrence, and identification of new activity. In most cases, once the scope, severity, and remediation strategy has been determined, no further analysis will be performed unless new data becomes available.
The STEAM-CIRT provides support to PSCs and IT support staff who are directly involved with an IT Incident. This support is provided via telephone, email, or documentation, and includes interpretation of evidence, and response and remediation techniques.
Limited response support is provided to users of Purdue University resources who may be affected by an IT Incident. This support is provided exclusively through email and is limited to the recommended recovery procedures. Users who require more in-depth support should contact their department's IT staff (for Purdue-owned equipment), or local computer repair shops/consultants for personal equipment.
An IT Incident post mortem analysis reviews the efficacy of response to an IT Incident, and seeks to find prevention methodologies to prevent future occurences, as well as whether or how to improve IT Incident Response procedures.
The STEAM-CIRT manages post mortems for all IT Incidents which significantly impact Purdue University's IT Resources, or as requested by management or PSCs. Requested post mortems are performed on a first-come first-serve basis and are dependent upon available resources.
Complementary to its Incident Analysis services, the STEAM-CIRT provides malware analysis to its constituents to determine the threats posed by the malware in question. Users of Purdue University IT Resources may contact abuse@purdue.edu for details on this service.