Organization:TR-CERT

From HandWiki
Computer Emergency Response Team of Turkey (TR-CERT)
Ulusal Siber Olaylara Müdahale Merkezi (USOM)
USOM logo.svg
Logo of TR-CERT
Agency overview
Formed27 May 2013 (2013-05-27)
TypeNational computer emergency response team (CERT)
JurisdictionRepublic of Turkey
HeadquartersÇankaya, Ankara
Parent agencyInformation and Communication Technologies Authority
Websitehttps://www.usom.gov.tr/

TR-CERT (Computer Emergency Response Team of the Republic of Turkey, Turkish: Ulusal Siber Olaylara Müdahale Merkezi (USOM)) is an organization within the Information and Communication Technologies Authority (ICTA) which is the national regulatory authority of the Turkish electronic communication sector. It is responsible for the analysis and risk mitigation of large-scale cyber threats and vulnerabilities, communicating information regarding malicious cyber activity or possible vulnerabilities to computer security incident response teams (CSIRT) and the public.[1]

Background

TR-CERT was established on 27 May 2013 within the ICTA, in accordance with the 4. clause "National Cybersecurity Strategy and 2013-2014 Action Plan" (Turkish: Ulusal Siber Güvenlik Stratejisi ve 2013-2014 Eylem Planı) [2] issued by the Cabinet of Turkey and published in the Official Gazette of the Republic of Turkey.[3]

Mission

The mission of TR-CERT is to protect the Turkish government's and its citizens' cyberspace, taking measures for the protection of critical infrastructures, both public and private, such as the energy production and distribution, water management, and telecommunication institutions and facilities in Turkey. TR-CERT also takes both proactive and reactive actions toward cyber incidents that would affect the country as a whole, such as botnets,[4] malware,[5] and distributed denial-of-service (DDoS) attacks.[6]

There are over 1300 CSIRTs and over 4000 cyber security professionals[7] in nearly every sector in Turkey that coordinate with TR-CERT regarding cyber incidents. These CSIRTs are mostly institutional CSIRTs (such as the CSIRT of a bank), but there are also industry-specific CSIRTs that coordinate with TR-CERT (such as the CSIRT of the finance industry).[3]

Activities

The Cyber Star (Turkish: Siber Yıldız), a 24-hour online capture-the-flag cybersecurity competition organized by TR-CERT,[8] had over 20,000 contestants working in either teams or individually, during the latest competition held in February 2019. In the previous Cyber Star event held in January 2017, TR-CERT had nearly 15,000 contestants and some of the most successful contestants were hired by TR-CERT later on.[9]

In December 2019, TR-CERT organized the "Cyber Shield 2019", an international cybersecurity exercise[10] with simulated cyber attacks, malware, phishing, and industrial control systems (ICS).[11] Held at the ICTA headquarters in Ankara,[12] contestants from 17 countries[11] competed to identify cybersecurity emergencies and take the necessary measures within the scenarios and technical infrastructure prepared by TR-CERT. The exercise was supported by International Telecommunication Union (ITU) agency of the United Nations and the Cybersecurity Alliance for Mutual Progress (CAMP). International Cyber Shield 2019 was organized to increase preparedness to combat against cybersecurity incidents and foster international cooperation in dealing with them.[10]

On 10 February 2020, TR-CERT's security operations center (SOC) was officially opened, with the attendance of the President of Turkey, Recep Tayyip Erdoğan. Speaking at the opening ceremony, Recep Tayyip Erdoğan said

"We aim for Turkey to not only be a consumer of technology, but also be a country that designs, develops, produces, and markets technologies to the world. The security dimension of digital transformation is at least as important as the physical defense of countries.[13]"

Cooperating with "ICTA Academy" (Turkish: BTK Akademi), TR-CERT has given various cybersecurity trainings,[14] ranging from web application security to computer forensics. Similarly, TR-CERT gives one-on-one, hands-on training to cybersecurity enthusiasts in the Fetih Cyber Drill Field[15]

Some of the other events organized and/or attended by TR-CERT include:

  • TR-CERT - CSIRT Advisory Meetings[16]
  • Energy Sector CSIRTs Meeting[17]
  • NATO CMX-2017[9] and CMX-2019[18] Crisis Management Exercises

Due to TR-CERT's contribution to the cybersecurity ecosystem in Turkey, between the years 2017 and 2018, the ranking of Turkey on the Global Cybersecurity Index (GTI) published by ITU went up by 23 ranks, going from 43[19] to 20[20] within a year.

TR-CERT is accredited by Trusted Introducer[21] and also is a member of the Forum of Incident Response and Security Teams (FIRST)[22] and Organisation of Islamic Cooperation's (OIC) computer emergency response team, OIC-CERT.[23]

References

  1. "About TRCERT". https://www.usom.gov.tr/hakkimizda.html. 
  2. "Ulusal Siber Güvenlik Stratejisi ve 2013-2014 Eylem Planı" (in tr). T.C. Ulaştırma Denizcilik ve Haberleşme Bakanlığı. https://www.btk.gov.tr/uploads/pages/2-1-strateji-eylem-plani-2013-2014-5a3412cf8f45a.pdf. 
  3. 3.0 3.1 "USOM ve Kurumsal Siber Olaylara Müdahale Ekibi" (in tr). 2017-12-15. https://www.btk.gov.tr/usom-ve-kurumsal-siber-olaylara-mudahale-ekibi. 
  4. "Siber ordudan nefes kesen operasyon" (in tr). 2019-09-11. https://www.milliyet.com.tr/milliyet-tv/siber-ordudan-nefes-kesen-operasyon-video-4648040. 
  5. "BTK-USOM açığı gördü, zararı önledi" (in tr). 2017-05-16. https://www.btk.gov.tr/haberler/btk-usom-acigi-gordu-zarari-onledi. 
  6. "USOM, ulusal siber güvenlikte çok önemli bir adım" (in tr). 2020-04-03. https://www.bthaber.com/usom-ulusal-siber-guvenlikte-cok-onemli-bir-adim/. 
  7. "Siber Güvenlik Üssü Türkiye’de açılıyor". https://www.sabah.com.tr/teknokulis/haberler/2020/02/11/siber-guvenlik-ussu-turkiyede-aciliyor. 
  8. "Yarışma Kuralları" (in tr). TR-CERT. https://siberyildiz.com/kurallar. 
  9. 9.0 9.1 "Global Cybersecurity Index (GCI) 2018". 2019. p. 47. https://www.itu.int/dms_pub/itu-d/opb/str/D-STR-GCI.01-2018-PDF-E.pdf. 
  10. 10.0 10.1 "Cyber Shield 2019". 2019. https://www.itu.int/en/ITU-D/Regional-Presence/Europe/Pages/Events/2019/CyberShield/Cyber-Shield-2019.aspx. 
  11. 11.0 11.1 "International cybersecurity exercise begins in Ankara" (in en). 2019-12-19. https://www.dailysabah.com/turkey/2019/12/19/international-cybersecurity-exercise-begins-in-ankara. 
  12. "Cyber Shield - Practical Information". 2019. https://cybershield.gov.tr/#/practical-information. 
  13. "Cumhurbaşkanı Erdoğan'dan USOM açılışında konuştu: Yerli 5G teknolojisi altyapısını kurmadan 5G'ye geçemeyiz" (in tr-TR). 2020-02-10. https://www.yenisafak.com/gundem/baskan-erdogandan-usom-acilisinda-onemli-aciklamalar-3525085. 
  14. "BTK'den siber güvenlik uzmanlığı eğitimi" (in tr). 2019-06-11. https://www.hurriyet.com.tr/teknoloji/btkden-siber-guvenlik-uzmanligi-egitimi-41366916. 
  15. "Fetih Siber Talimhane". TR-CERT. 2019. https://fetih.gov.tr/#timeline-block. 
  16. "Duyuru Listesi" (in tr). https://www.usom.gov.tr/duyuru.html. 
  17. "Enerji sektörüne yönelik siber güvenlik çalışmaları sürüyor". https://www.epdk.gov.tr/Detay/Icerik/2-152/-enerji-sektorune-yonelik-siber-guvenlik-calismal. 
  18. "NATO Kriz Yönetim Tatbikatı-2019" (in tr). 2019-05-06. https://www.timeturk.com/nato-kriz-yonetim-tatbikati-2019/haber-1082655. 
  19. "Global Cybersecurity Index (GCI) 2017". p. 60. https://www.itu.int/dms_pub/itu-d/opb/str/D-STR-GCI.01-2017-R1-PDF-E.pdf. 
  20. "Global Cybersecurity Index (GCI) 2018". p. 62. https://www.itu.int/dms_pub/itu-d/opb/str/D-STR-GCI.01-2018-PDF-E.pdf. 
  21. "Trusted Introducer: Directory: TR-CERT". https://www.trusted-introducer.org/directory/teams/tr-cert.html. 
  22. "TR-CERT". https://www.first.org/members/teams/tr-cert. 
  23. "OIC-CERT | Organisation of The Islamic Cooperation - Computer Emergency Response Team". https://www.oic-cert.org/en/allmembers.html. 

External links