CSIRT emergency contact: csirt@ucc.edu.gh Report an Incident

UCC CSIRT

The Computer Security Incident Response Team the Cybersecurity Section runs for the University of Cape Coast. This page is what a peer CERT, a national authority or a member of the university needs in order to know what the UCC CSIRT does, who it serves, and how to reach it.

Mandate

What the UCC CSIRT is authorised to do.

The UCC CSIRT is the Computer Security Incident Response Team of the University of Cape Coast. It is run by the Cybersecurity Section, which sits within the Directorate of Information and Communication Technology Services.

The team is authorised to:

  • receive, record and triage reports of security incidents affecting the University;
  • coordinate the response to those reports with the people who run the systems concerned;
  • publish security advisories, and the policies and guidance the University community is asked to follow;
  • exchange incident information with peer response teams, national authorities and network operators on the University's behalf.

Constituency

Who the UCC CSIRT serves and defends.

The UCC CSIRT serves the students and staff of the University of Cape Coast, and the systems and networks the University runs across its campuses.

A report from outside that constituency is still accepted and still read. It is simply outside the team's remit to action directly.

Contact the UCC CSIRT

One address reaches the team. Anything sensitive should be encrypted to the key below.

Hotline

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

Hours

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

PGP public key

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

Partners

The teams and networks the UCC CSIRT exchanges information with.

  • The Shadowserver Foundation

    A non-profit that reports observed compromises, exposed services and malicious activity to the networks they affect, free of charge.

  • GARNET

    The Ghanaian Academic and Research Network, which connects the University of Cape Coast to its peer institutions and to the wider research and education community.

  • Cyber Security Authority, Ghana

    Ghana's national cybersecurity authority, which runs the national CERT and to which incidents of national significance are escalated.

Partner marks appear here once each organisation supplies its logo.

How we share information

The UCC CSIRT marks what it sends with the Traffic Light Protocol (TLP), and honours the marking on what it receives. The marking is always written out in words as well as shown in the standard protocol colour.

Marking What the recipient may do
TLP:RED For the named recipients only. Not to be shared with anyone outside the specific exchange, meeting or conversation in which it was disclosed.
TLP:AMBER+STRICT May be shared within the recipient's own organisation only, and only with those who need to know.
TLP:AMBER May be shared within the recipient's organisation and with its clients, on a need-to-know basis.
TLP:GREEN May be shared within the community, but not through publicly accessible channels.
TLP:CLEAR May be shared without restriction, subject to standard copyright rules.

Only TLP:CLEAR and TLP:GREEN advisories are published on this site. Anything marked TLP:AMBER or above is, by definition, not for a public web page.

Severity and response targets

The priority the UCC CSIRT assigns to a report, and what it aims for at each level.

Priority Response target
P1

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

P2

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

P3

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

P4

Not yet published The Cybersecurity Section has not published this yet. Email the CSIRT if you need it now.

These are published aims, not a service-level agreement. Nothing in this system measures or enforces them.

RFC 2350 profile

The standard description of a CSIRT — its constituency, its charter, its policies and its contact details — in the form every peer team publishes it.

Download the RFC 2350 profile (plain text)

1. Document information

This is the RFC 2350 description of the UCC CSIRT. It is a first published draft, maintained by the Cybersecurity Section, University of Cape Coast.

  • Distribution list for notifications: none. Changes are published on this page.
  • Locations where this document may be found: the CSIRT page of the Cybersecurity Section website, and the plain-text copy linked from it.
  • Authenticating this document: a signed copy will be offered once the team's PGP key is published. Until then this document is authenticated only by the site it is served from.

2. Contact information

  • Name of the team: UCC CSIRT, the Computer Security Incident Response Team of the University of Cape Coast.
  • Address: Cybersecurity Section, Directorate of Information and Communication Technology Services, University of Cape Coast, Cape Coast, Ghana.
  • Time zone: GMT (UTC+0), observed year round.
  • Electronic mail address: csirt@ucc.edu.gh. This address reaches the whole team and is the preferred way to contact it.
  • Telephone number: not yet published.
  • Public keys and encryption information: not yet published.
  • Team members: the team is staffed by the Cybersecurity Section. Individual members are not listed.
  • Hours of operation: not yet published.

3. Charter

Mission statement: to receive, triage and respond to reports of computer security incidents affecting the University of Cape Coast, and to help its community prevent them.

Constituency: the students and staff of the University of Cape Coast, and the University's systems and networks across its campuses. A report from outside the constituency is accepted and read, but is outside the team's remit to action directly.

Sponsorship and affiliation: the UCC CSIRT is funded and operated by the University of Cape Coast, through the Cybersecurity Section of its Directorate of Information and Communication Technology Services.

Authority: the team operates with the authority of the University and coordinates its response with the owners of the systems affected.

4. Policies

Types of incidents and level of support: the team accepts reports of any security incident affecting its constituency. The level of support given depends on the type and severity of the incident and on the resources available at the time. Published response targets are not yet agreed, and this document does not state any.

Co-operation, interaction and disclosure of information: the team exchanges information with peer response teams, national authorities and network operators where doing so helps resolve or prevent an incident. Information received is handled under the Traffic Light Protocol (TLP), version 2.0, and information sent is marked with it. Markings on information received are honoured. The identity of a person who reports an incident is treated as personal information and is not disclosed outside the team.

Communication and authentication: electronic mail is the normal channel. Sensitive material should be encrypted; the team's key is not yet published, so anything sensitive should be arranged with the team first.

5. Services

Incident response: the team receives reports through the report form on this website and by electronic mail, triages them, and coordinates the response with the system owners concerned. A reporter is issued a reference with which they can check what has happened to their report.

Proactive services: the team publishes security advisories, and a library of policies and guidance for the University community.

6. Incident reporting forms

Use the incident report form on this website. It is the fastest route to the team and it records the report where the team works it. If you cannot reach the form, send electronic mail to csirt@ucc.edu.gh describing what happened, when it happened, and which systems or accounts are involved.

7. Disclaimers

While every precaution is taken in the preparation of the information published by the UCC CSIRT, the team assumes no responsibility for errors, omissions, or damages resulting from the use of the information it contains.