RFC 2350 · BEST CURRENT PRACTICE · 1998

Expectations for Computer Security Incident Response

Overview

RFC 2350, “Expectations for Computer Security Incident Response”, is a Best Current Practice document published in June 1998 by N. Brownlee, E. Guttman. The canonical text is published by the RFC Editor.

Abstract

The purpose of this document is to express the general Internet community's expectations of Computer Security Incident Response Teams (CSIRTs). It is not possible to define a set of requirements that would be appropriate for all teams, but it is possible and helpful to list and describe the general set of topics and issues which are of concern and interest to constituent communities. CSIRT constituents have a legitimate need and right to fully understand the policies and procedures of 'their' Computer Security Incident Response Team. One way to support this understanding is to supply detailed information which users may consider, in the form of a formal template completed by the CSIRT. An outline of such a template and a filled in example are provided.

Abstract as published in the RFC, via rfc-editor.org.

What “Best Current Practice” means

Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.

Read this RFC

The canonical text of RFC 2350 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 1998

Who Is Online

In total there are 47 users online: 0 registered, 41 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Googlebot Other Bot Other Crawler SemrushBot

Users active in the past 15 minutes. Total registered members: 354