FIRST CSIRT and PSIRT Services Frameworks · A mature incident and vulnerability capability, made adopt-ready · Evidence & Implementation Kit
Meet the FIRST CSIRT and PSIRT Services Frameworks, without decoding the frameworks yourself.
Every requirement handed to you as an adopt-ready control, event and incident management through vulnerability management to situational awareness and knowledge transfer, with the evidence an assessor examines.
Ready in a weekend, not a quarter.
Here is the honest situation. The FIRST CSIRT Services Framework v2.1 and PSIRT Services Framework v1.1 define the services an incident response and product security team provides, across event management, incident management, vulnerability management, situational awareness and knowledge transfer. Alongside them sit CVSS v4.0 for severity scoring, TLP v2.0 and the Information Exchange Policy for information handling, and multi-party coordinated vulnerability disclosure. A team with tools but no defined service model is exactly where organizations fall short.
This Kit removes the guesswork. It is the FIRST CSIRT and PSIRT Services Frameworks written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.
What you get, the moment you buy
18
Requirements as adopt-ready controls. Every requirement, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where organizations fall short, so you close the gap first.
1
Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each requirement and the workbook returns your readiness as a single percentage, and exactly what to fix next.
Grounded in the FIRST CSIRT and PSIRT Services Frameworks. Editable Word and Excel files.
A tool set is not a service model
Owning a SIEM and a ticket queue is not a defined incident and vulnerability capability. This Kit builds the FIRST service areas, CVSS, TLP and coordinated disclosure into controls with the evidence an assessor asks for.
What one control looks like
This is the opening control, where the program begins. All 18 are built to this depth.
FCS-1 Adopt the CSIRT and PSIRT services frameworks SCOPE
Put this control in place
Adopt the FIRST CSIRT Services Framework and, where product security applies, the PSIRT Services Framework as [your organization name]'s reference for the incident and vulnerability services it provides, and document the services in scope, so scope is defined and the organization can evidence its adoption.
Framework note.
The FIRST CSIRT Services Framework v2.1 and PSIRT Services Framework v1.1 define the service areas an incident response and product security team can provide.
Evidence an assessor examines
- The CSIRT and PSIRT frameworks adopted
- Services in scope documented
- Records of the adoption
Common finding they raise: The team operates without a defined service framework.
Why this is not another template pack
- The evidence is the point. A requirement you cannot evidence is a gap waiting to be found. This tells you what an assessor examines and where organizations fall short, for every requirement.
- The specifics built in. The framework's distinctive requirements are written into the controls, not left generic.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. This work shares its shape with related security and safety frameworks, so it feeds your wider program.
Who buys this
CSIRT, SOC and PSIRT leads and their incident response and vulnerability teams. Whether it is standing up a team or maturing one, you save weeks and walk in with your event, incident and vulnerability services, CVSS, TLP and coordinated disclosure structured.
By the end of the weekend you will have
✓ An adopt-ready control for all 18 requirements
✓ A completed control matrix
✓ The evidence an assessor examines
✓ Your core controls in place
✓ A readiness percentage and a fix list
✓ The highest-risk gaps closed
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this just for a formal CSIRT? No. Any team doing incident and vulnerability response benefits. It also covers PSIRT services for product security.
Does it cover CVSS v4.0 and TLP v2.0? Yes. Scoring with CVSS v4.0 and handling under TLP v2.0 are built as controls.
What if it is not for me? A 30-day money-back guarantee.
Do not face an assessor with requirements you cannot show.
Every requirement is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com