Incident Response Security Publications Security Course Training Security Auditing
1 1 2 1
1 7
1 1 8
3 1 2
9 1 5
7 8
1 2
9 1 9
2 5
2 2
1 1 1 0
7 1 5
2 6
1 0 7
1 3
6 6
6 1
2 5
3 1
1 1
2
5 10
15 20
25 30
JAN. FEB.
MAR. APR.
MAY. JUN.
JUL. AUG.
SEP. OCT.
NOV. DEC.
Government sector Private sector
NA
Chart 5: Number of incidents in each month of year 2007, categorized by incident source organization type.
When we considered the statistics of incidents based on their sources categorized as either government sector or private sector as shown in Chart 5, we found that the numbers of incidents
coming from both sectors were almost equal. The governments incidents had 170 cases while the privates ones had 141 cases. Other 31 cases were the cases that we could not identify the sources or
they were associated with both types of the source. In the summary, there is a trend continued in the year 2007 from the previous year that the
computer’s incidents have changed their objectives from destroying valuable information to stealing valuable information especially personal information and e-commerce information. Even though
over all number of incident cases was decreasing, the number of attacking related to the monetary and specific phishing targets was increasing. This trend is likely to grow in the year to come. The
computer users including the ones who use e-commerce should prepare themselves to avoid this type of attacks.
Staff and Structure Update
Nowadays, ThaiCERT has 30 staff working in 4 security fields. Those 4 fields are
-
Infrastructure Security Research and Development and ThaiCERT Services
-
Wireless Broadband Security Research and Development
-
Information Security Standard Research and Development
-
National Security Technology Research and Development Current certifications that our staff had gotten are such as CISSP, CWNA, RHCE, CCNA,
CCNP, MCP, MCSA, CISA, GIAC and ISO27001 AuditorLead Auditor. We have planned to develop our staff’s skill to get more certification.
ThaiCERT Services