UCC CSIRT — RFC 2350 profile ============================ Date of last update: 24 August 2026 1. Document information This is the RFC 2350 description of the UCC CSIRT. It is a first published draft, maintained by the Cybersecurity Section, University of Cape Coast. - Distribution list for notifications: none. Changes are published on this page. - Locations where this document may be found: the CSIRT page of the Cybersecurity Section website, and the plain-text copy linked from it. - Authenticating this document: a signed copy will be offered once the team's PGP key is published. Until then this document is authenticated only by the site it is served from. 2. Contact information - Name of the team: UCC CSIRT, the Computer Security Incident Response Team of the University of Cape Coast. - Address: Cybersecurity Section, Directorate of Information and Communication Technology Services, University of Cape Coast, Cape Coast, Ghana. - Time zone: GMT (UTC+0), observed year round. - Electronic mail address: csirt@ucc.edu.gh. This address reaches the whole team and is the preferred way to contact it. - Telephone number: not yet published. - Public keys and encryption information: not yet published. - Team members: the team is staffed by the Cybersecurity Section. Individual members are not listed. - Hours of operation: not yet published. 3. Charter Mission statement: to receive, triage and respond to reports of computer security incidents affecting the University of Cape Coast, and to help its community prevent them. Constituency: the students and staff of the University of Cape Coast, and the University's systems and networks across its campuses. A report from outside the constituency is accepted and read, but is outside the team's remit to action directly. Sponsorship and affiliation: the UCC CSIRT is funded and operated by the University of Cape Coast, through the Cybersecurity Section of its Directorate of Information and Communication Technology Services. Authority: the team operates with the authority of the University and coordinates its response with the owners of the systems affected. 4. Policies Types of incidents and level of support: the team accepts reports of any security incident affecting its constituency. The level of support given depends on the type and severity of the incident and on the resources available at the time. Published response targets are not yet agreed, and this document does not state any. Co-operation, interaction and disclosure of information: the team exchanges information with peer response teams, national authorities and network operators where doing so helps resolve or prevent an incident. Information received is handled under the Traffic Light Protocol (TLP), version 2.0, and information sent is marked with it. Markings on information received are honoured. The identity of a person who reports an incident is treated as personal information and is not disclosed outside the team. Communication and authentication: electronic mail is the normal channel. Sensitive material should be encrypted; the team's key is not yet published, so anything sensitive should be arranged with the team first. 5. Services Incident response: the team receives reports through the report form on this website and by electronic mail, triages them, and coordinates the response with the system owners concerned. A reporter is issued a reference with which they can check what has happened to their report. Proactive services: the team publishes security advisories, and a library of policies and guidance for the University community. 6. Incident reporting forms Use the incident report form on this website. It is the fastest route to the team and it records the report where the team works it. If you cannot reach the form, send electronic mail to csirt@ucc.edu.gh describing what happened, when it happened, and which systems or accounts are involved. 7. Disclaimers While every precaution is taken in the preparation of the information published by the UCC CSIRT, the team assumes no responsibility for errors, omissions, or damages resulting from the use of the information it contains.