Botswana CSIRT Service delivery is guided by internationally recognized cybersecurity practices, including the FIRST CSIRT Services Framework, while taking into account Botswana’s legislative, regulatory, and national cybersecurity requirements. Botswana-CSIRT is a member of the Forum of Incident Response and Security Teams (FIRST) and follows the FIRST CSIRT Service Framework
https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1 as a reference for structuring and delivering its cybersecurity incident response services.Botswana-CSIRT is mandated by the Cybersecurity Act to strengthen Botswana’s national cybersecurity resilience by coordinating the prevention, detection, analysis, response, and recovery from cybersecurity incidents affecting the communications sector and designated Critical National Information Infrastructure (CNII). The CSIRT works closely with communication service providers, government institutions, critical infrastructure operators, the private sector, and other relevant stakeholders to facilitate timely incident reporting, information sharing, threat intelligence, technical assistance, and coordinated incident response.
conducting cybersecurity awareness programs, technical training, cyber exercises and drills, workshops, briefings, and stakeholder engagements to strengthen cybersecurity capabilities.
collecting, analysing, and disseminating actionable information on cyber threats, vulnerabilities, malicious infrastructure, compromised systems, leaked credentials, and emerging threats.
Facilitating the timely exchange of threat intelligence, indicators of compromise, technical information, and cybersecurity lessons learned with relevant stakeholders.
supporting constituents with security guidance, baseline security practices, incident preparedness, and recommendations to improve cyber resilience.
monitoring for malware infections, botnet activity, compromised devices, and other indicators of compromise affecting constituents.
issuing cybersecurity alerts, warnings, technical advisories, and recommended mitigation measures in response to emerging or identified threats.
issuing cybersecurity alerts, warnings, technical advisories, and recommended mitigation measures in response to emerging or identified threats.
providing cybersecurity guidance, monitoring, coordination, and incident response support to organizations designated as part of Botswana’s CNII as per the Cybersecurity Act
maintaining collaboration with government institutions, communication service providers, critical infrastructure operators, law enforcement, regional and international CSIRTs, and other cybersecurity stakeholders.
supporting organizations in assessing and improving their incident management capabilities, processes, governance, and operational maturity. Botswana has Security Information Management Maturity Model (SIM3) certified Auditors certified by Open CSIRT Foundation https://opencsirt.org/csirt-maturity/certified-auditors/
Identifying exposed systems, open ports, vulnerabilities, compromised assets, and other security weaknesses within the CSIRT constituency and supporting appropriate remediation.
Providing mechanisms for organizations and constituents to report cybersecurity incidents and facilitating appropriate escalation and coordination.
Receiving, assessing, analysing, coordinating, and supporting the resolution of reported cybersecurity incidents.
Conducting continuous monitoring and analysis of relevant cyber-risk indicators to identify potential threats before they develop into significant incidents