<?xml version="1.0" encoding="UTF-8"?>
<StrategicPlan xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:stratml="urn:ISO:std:iso:17469:tech:xsd:stratml_core"><Name>About SEI CERT</Name><Description/><OtherInformation/><StrategicPlanCore><Organization><Name>CERT Division</Name><Acronym>SEICERT</Acronym><Identifier>_75ce8c70-3bd8-11e5-9e7b-547f2dbff78a</Identifier><Description>The CERT Division is a trusted provider of operationally relevant cybersecurity research and innovative and timely solutions to our nation's cybersecurity challenges. Through our operationally relevant cybersecurity research, innovative and timely responses to cybersecurity challenges, and broad transition to our stakeholder communities, the CERT Division develops, executes, and evolves a technical agenda that brings unique solutions to cybersecurity challenges that measurably improve the security of the cyber environment.</Description><Stakeholder StakeholderTypeType="Organization"><Name>Software Engineering Institute</Name><Description>Begun with a simple handshake and a fundamental mission, the CERT Division of the Software Engineering Institute (SEI) has evolved dramatically since it was created in 1988 as the CERT Coordination Center in response to the Morris worm incident. The small organization established to coordinate response to internet security incidents now has more than 150 cybersecurity professionals working on projects that take a proactive approach to securing systems.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Government</Name><Description>Recognized as a trusted, authoritative organization dedicated to improving the security and resilience of computer systems and networks, the CERT Division is a national asset in the field of cybersecurity. We regularly partner with government, industry, law enforcement, and academia to develop advanced methods and technologies to counter large-scale, sophisticated cyber threats.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Industry</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Law Enforcement Agencies</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Academia </Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Carnegie Mellon University</Name><Description>The CERT Division is enriched by its connection to the internationally respected Carnegie Mellon University. Our proximity to other world-class researchers and practitioners enables numerous collaboration opportunities and strengthens our research focus. And because the CERT Division is located within the SEI, a federally funded research and development center at Carnegie Mellon University, the majority of our work contributes to government and national security efforts.</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Department of Homeland Security</Name><Description>The CERT Division works closely with the Department of Homeland Security (DHS) to meet mutually set goals in areas such as data collection and mining, statistics and trend analysis, computer and network security, incident management, insider threat, software assurance, and more. The results of this work include exercises, courses, and systems that were designed, implemented, and delivered to DHS and its customers as part of the SEI's mission to transition SEI capabilities to the public and private sectors and improve the practice of cybersecurity.</Description></Stakeholder></Organization><Vision><Description/><Identifier>_75ce8e78-3bd8-11e5-9e7b-547f2dbff78a</Identifier></Vision><Mission><Description>To develop, execute, and evolve a technical agenda that brings unique solutions to cybersecurity challenges</Description><Identifier>_75ce8f36-3bd8-11e5-9e7b-547f2dbff78a</Identifier></Mission><Value><Name>Cybersecurity</Name><Description/></Value><Goal><Name>Security Problems</Name><Description>Understand security problems</Description><Identifier>_75ce8fe0-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>The Value of Knowledge and Experience -- 

Our diverse group of researchers, software engineers, security analysts, and digital intelligence specialists relies on both theoretical and empirical knowledge to understand security problems. In addition to our scientific research, collecting actual, real-world data helps us to gain insight into the current climate. By analyzing network traffic, we can help organizations to identify patterns that may indicate attacks.

Our databases of information about software vulnerabilities and malicious code, coupled with our understanding of the software development lifecycle, serve as a basis for developing remediation strategies and solutions and working with developers to improve new software. We also focus on improving organizations' security by helping them identify security gaps and internal threats. Malicious insiders pose a serious threat to organizations, and our database of information about over 800 actual insider threat cases helps us to identify motivations and warning signs.</OtherInformation><Objective><Name>Attack Patterns</Name><Description>Help organizations identify patterns that may indicate attacks.</Description><Identifier>_75ce9080-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Remediation</Name><Description>Develop remediation strategies and solutions.</Description><Identifier>_75ce9120-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Software</Name><Description>Working with developers to improve new software.</Description><Identifier>_75ce91c0-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Software Developers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Organizations</Name><Description>Improving organizations' security by helping them identify security gaps and internal threats.</Description><Identifier>_75ce9260-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Motivations &amp; Warnings</Name><Description>Identify motivations and warning signs.</Description><Identifier>_75ce930a-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>1.4.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Impact</Name><Description>Develop practical, applicable solutions to relevant problems.</Description><Identifier>_75ce93aa-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Organizations</Name><Description>Organizations can choose from our many assessments and models to enhance their security profiles through activities such as identifying information security gaps, improving resilience, and measuring susceptibility to insider threats. We document our insights in a variety of publications, including technical reports, white papers, journal articles, conference presentations, blog posts, and podcasts.</Description></Stakeholder><OtherInformation>Creating Impact in the Community</OtherInformation><Objective><Name>Solutions</Name><Description>Make solutions available to the people who need them.</Description><Identifier>_75ce9454-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>We use the insights gained through our research and analysis of these data collected across the CERT Division to develop practical, applicable solutions to relevant problems. Then we make these solutions available to the people who need them.</OtherInformation></Objective><Objective><Name>Standards</Name><Description>Contribute to standards efforts to improve software security.</Description><Identifier>_75ce94fe-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>We also contribute to standards efforts to improve software security.</OtherInformation></Objective><Objective><Name>Tools</Name><Description>Publish open source tools for a range of activities.</Description><Identifier>_75ce95a8-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>We publish numerous open source tools for a range of activities, including discovering vulnerabilities, analyzing network traffic, and facilitating digital investigations.</OtherInformation></Objective><Objective><Name>Vulnerabilities</Name><Description>Discover vulnerabilities.</Description><Identifier>_75ce968e-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.3.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Analysis</Name><Description>Analyze network traffic.</Description><Identifier>_75ce9738-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.3.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Investigations</Name><Description>Facilitate digital investigations.</Description><Identifier>_75ce97e2-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.3.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Federal Law Enforcement Agencies</Name><Description>In the area of digital intelligence and investigation, we work closely with federal law enforcement and intelligence agencies to provide operational support, identify and develop tools that address gaps not met by commercial tools, and provide training to improve the state of the practice among digital forensic analysts. Our staff members help agencies craft strategies for executing search warrants when the subject is known to be employing particularly sophisticated, technical countermeasures. We also provide the analytical support that law enforcement needs to successfully prosecute some of the nation's largest credit card theft cases.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Federal Intelligence Agencies</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Training</Name><Description>Develop training to increase the preparedness of cybersecurity professionals.</Description><Identifier>_75ce98aa-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Cybersecurity Professionals</Name><Description>Geographically dispersed team members can work together on customized scenarios to improve and hone their skills. </Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Educators</Name><Description>Our staff has also collaborated with educators from a number of other universities to develop a curriculum in software assurance, which will join our existing survivability and information assurance curriculum.</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Carnegie Mellon University</Name><Description>In addition, many of our staff members teach courses in information security at Carnegie Mellon University.</Description></Stakeholder><OtherInformation>To increase the preparedness of other cybersecurity professionals faced with these issues, we developed training. In addition to traditional classroom-based courses, we offer course materials through STEPfwd, our virtual training environment that allows users to access a variety of online resources at their own pace, at any time and from any location.</OtherInformation></Objective></Goal><Goal><Name>Network Security</Name><Description>Provide support to the Department of Defense (DoD) through projects designed to improve the security of networks.</Description><Identifier>_75ce995e-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Department of Defense</Name><Description/></Stakeholder><OtherInformation>Contributing to National Security Efforts -- 

Our efforts extend to the national and global levels as well. Over the years, we have provided direct support to the Department of Defense (DoD) through projects designed to improve the security of networks.</OtherInformation><Objective><Name>Situational Awareness</Name><Description>Provide core analytical systems to increase global situational awareness.</Description><Identifier>_75ce9ae4-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Defense Information Systems Agency</Name><Description/></Stakeholder><OtherInformation>Working with the Defense Information Systems Agency in an effort to increase global situational awareness, we provide core analytical systems that are used across the DoD.</OtherInformation></Objective><Objective><Name>Processes &amp; Systems</Name><Description>Compile analytical processes and systems to address threats to DoD networks.</Description><Identifier>_75ce9bc0-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Community Data Center</Name><Description>Our technical staff members have also been at the center of the engineering and development activities for the Community Data Center, an initiative created to compile an array of analytical processes and systems to address threats to DoD networks.</Description></Stakeholder><OtherInformation/></Objective><Objective><Name>Remediation</Name><Description>Develop a proof-of-concept vulnerability remediation capability that will use standards-based remediation processes for the first time.</Description><Identifier>_75ce9c7e-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Navy</Name><Description>We are working with partners in the Navy's Space and Naval Warfare Systems Center and the MITRE Corporation to develop a proof-of-concept vulnerability remediation capability that will use standards-based remediation processes for the first time.</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Space and Naval Warfare Systems Center</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>MITRE Corporation</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Malicious Code</Name><Description>Understand and counter the malicious code threat to national systems.</Description><Identifier>_75ce9d3c-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>DoD</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Intelligence Community</Name><Description/></Stakeholder><OtherInformation>In the area of malicious code analysis, CERT analysts are providing critical support to DoD and intelligence community partners to understand and counter the malicious code threat to national systems.</OtherInformation></Objective><Objective><Name>DCISE</Name><Description>Provide core analytical support to the Defense Industrial Base Collaborative Information Sharing Environment (DCISE).</Description><Identifier>_75ce9e0e-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.5</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Defense Industries</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>DoD</Name><Description>In this project, CERT analysts work with multiple DoD agencies to produce threat information products for industry partners who share relevant information to more effectively protect critical data.</Description></Stakeholder><OtherInformation>We also provide core analytical support to the Defense Industrial Base Collaborative Information Sharing Environment (DCISE), the focal point and clearinghouse for referrals of intrusion events on defense organizations' unclassified corporate networks.</OtherInformation></Objective><Objective><Name>CSIRTs</Name><Description>Build a network of computer security incident response teams</Description><Identifier>_75ce9ed6-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.6</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>We have been instrumental in building a network of more than 50 computer security incident response teams (CSIRTs) with national responsibility ...</OtherInformation></Objective><Objective><Name>US-CERT</Name><Description>Create US-CERT capabilities.</Description><Identifier>_75ce9f9e-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.7</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Department of Homeland Security</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>US-CERT</Name><Description>Although the CERT Division and US-CERT are two distinct organizations, CERT staff work closely with the staff at US-CERT and have contributed content to their website, as well as the Build Security In and Software Assurance Community Resources and Information Clearinghouse websites.</Description></Stakeholder><OtherInformation>... we worked with the Department of Homeland Security (DHS) to create US-CERT, work that draws on CERT/CC capabilities to help prevent cyber attacks, protect system, and respond to the effects of cyber attacks across the internet.</OtherInformation></Objective><Objective><Name>Prevention</Name><Description>Prevent cyber attacks.</Description><Identifier>_75cea07a-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.7.1</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Protection</Name><Description>Protect systems.</Description><Identifier>_75cea142-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.7.2</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Responses</Name><Description>Respond to the effects of cyber attacks across the internet.</Description><Identifier>_75cea214-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.7.3</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Cyber Threats</Name><Description>Assist government agencies with projects that strengthen our nation's resistance to cyber threats.</Description><Identifier>_75cea2fa-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.8</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Government Agencies</Name><Description/></Stakeholder><OtherInformation>Our involvement with DHS extends beyond US-CERT, however. Various agencies within DHS, as well as other government entities, regularly seek our experience and insights to assist them with projects that strengthen our nation's resistance to cyber threats.</OtherInformation></Objective><Objective><Name>Smart Grid</Name><Description>Improve the efficiency of the power grid while reducing the impact to the environment.</Description><Identifier>_75cea3cc-3bd8-11e5-9e7b-547f2dbff78a</Identifier><SequenceIndicator>3.9</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Software Engineering Institute</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Energy Suppliers</Name><Description/></Stakeholder><OtherInformation>We are also involved with the Software Engineering Institute's Smart Grid effort. This project focuses on improving the efficiency of the power grid while reducing the impact to the environment.</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><PublicationDate>2015-08-05</PublicationDate><Source>http://www.cert.org/about/</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>