Version 1.1 - December 18, 2025

IservicesCSIRT RFC 2350

Mandate and official description of IservicesCSIRT, the computer security incident response team of Iservices Systems SAS.

Download the PDF

Document information

Drafted by
Ezeckiel DADJO, DOPEX/CSIRT, 21/11/2025
Updated by
Jean-Robert HOUNTOMEY, 18/12/2025
Validated by
Edouard HOUNTOMEY, CODIR, 07/01/2026
Version 1.0
21/11/2025, initial version
Version 1.1
18/12/2025, update

This document contains a description of IservicesCSIRT according to RFC 2350. It provides essential information about IservicesCSIRT, its communication channels, its role and its responsibilities.

Distribution list

There is no distribution list.

Where to find this document

The current version of this document is available on request from IservicesCSIRT. It can also be downloaded as a PDF file from this page.

Document authenticity

The authenticity of this document can be confirmed on request from IservicesCSIRT.

Document identification

Title: IservicesCSIRT Mandate - RFC 2350. Expiration: this document is valid until a new version is published.

References and standards

IservicesCSIRT relies on recognized references and standards to ensure regulatory compliance, operational efficiency and the robustness of its practices:

  • The Security Incident Management Maturity Model (SIM3): a maturity model used to assess and improve the capabilities of computer security incident response teams (CSIRTs) across 4 main areas: organization, human, tools and processes.
  • The Security Operations Center Capability Maturity Model (SOC-CMM): a free, open-source framework to assess and improve SOC performance across the Business, People, Process, Technology and Services domains, using maturity levels (0-5) and capability levels (0-3). It also aligns with frameworks such as the NIST CSF.
  • The FIRST CSIRT Services Framework: an international reference defining the essential services a CSIRT should provide: incident management, security monitoring, threat intelligence analysis, vulnerability management, forensic assistance, and communication and coordination with stakeholders.
  • The AfricaCERT Guidelines: a set of operational recommendations to harmonize the operation of African CSIRTs and strengthen regional cooperation (threat information sharing, use of TLP, coordinated handling of cross-border incidents, threat-intel infrastructure such as MISP, and good practices for communication, coordination and confidentiality).

Contact

Name
IservicesCSIRT, Iservices Computer Security Incident Response Team
Address (Benin)
Plot 6170-1065, Parcel "J", Cadjèhoun, Cotonou
Address (Togo)
Boulevard de la Victoire, Tokoin Protestants, Lomé
Time zone
UTC/CET
Telephone
+229 01 21 38 71 43, +229 01 66 20 18 83
Business hours
Monday to Friday, 8 am to 6 pm (UTC)
Fax
Not available
Other communication channel
Not available
Email address
csirt@iservices.africa

Public key and encryption information

Email is the preferred means of communication. Sensitive information is encrypted before being sent. Depending on the parties involved, IservicesCSIRT uses PGP to guarantee the confidentiality and integrity of exchanged documents. PGP may also be used to authenticate exchanged files.

Key ID
C30F561942F253CB
Fingerprint
209D 71C9 E64C D159 43DD D1C0 C30F 5619 42F2 53CB

The public key can be retrieved at any time from public key servers such as https://keys.openpgp.org. It must be used whenever information needs to be sent to IservicesCSIRT securely.

Team members

For confidentiality reasons, the list of team members is not publicly disclosed. More information is available on request from IservicesCSIRT.

Customer contact point

It is preferable to contact IservicesCSIRT by email. In emergencies, it can be reached by telephone, Monday to Friday, 9 am to 6 pm (UTC).

Charter

Mission

The mission of IservicesCSIRT is to protect, detect, analyze and respond effectively to security incidents affecting the information systems, digital services and critical assets of its clients and partners. The goal is to ensure a high level of resilience against cyber threats, while providing operational, strategic and preventive support adapted to the needs of the African and international context.

IservicesCSIRT pursues in particular the following objectives:

  1. 1Ensure a fast, coordinated and effective response to security incidents, applying procedures consistent with international good practice (ISO 27035, NIST 800-61, FIRST CSIRT Services Framework).
  2. 2Provide continuous monitoring and anticipation capability, detecting malicious activity, vulnerabilities and abnormal behavior likely to impact supported organizations.
  3. 3Produce and distribute threat intelligence (CTI) adapted to the local and regional context, to help partner entities improve their security posture and prevent emerging attacks.
  4. 4Support organizations in cyber crisis management, ensuring coordination, technical communication and decision support during major incidents or complex attacks.
  5. 5Strengthen cybersecurity capabilities within the African ecosystem, promoting collaboration, information sharing (TLP), cyber exercises, and aligning with AfricaCERT and AF-ISAC recommendations.
  6. 6Contribute to continuous security improvement through vulnerability management, technical audit, awareness, training and post-incident review activities.

Constituency

The scope of IservicesCSIRT covers the information systems of Iservices Systems SAS and its associated entities, as well as those of client organizations that have subscribed to an incident response or security monitoring service (CSIRT/SOC) from Iservices Systems SAS. For a complete list and detailed information on the covered entities, refer to the service contracts in force and the official documentation provided to clients as part of the CSIRT/SOC offers.

Policies

1. Types of incidents and level of support

IservicesCSIRT handles all types of cybersecurity incidents affecting its constituency.

2. Cooperation, information exchange and confidentiality

IservicesCSIRT supports operational coordination and information exchange between CERTs, CSIRTs, SOCs and similar entities. It considers that such actions are beneficial to itself and to third parties, and help carry out their duty and resolve security incidents more effectively. IservicesCSIRT attaches crucial importance to data confidentiality and the need-to-know principle.

IservicesCSIRT applies the Traffic Light Protocol version 2.0. Information is therefore classified CLEAR, GREEN, AMBER, AMBER+STRICT and RED. It also applies the Permissible Actions Protocol (PAP), which defines the actions allowed when exchanging sensitive information with partners, formalizing rules for the use, sharing and handling of data, and thus guaranteeing confidentiality, integrity and a secure approach to collaboration.

IservicesCSIRT operates under the Beninese legal framework.

3. Communication

IservicesCSIRT protects sensitive information according to the policies and regulations of Benin, of its clients' countries of residence and of the African Union. Secure communications, including encryption and authentication, are carried out using a PGP key or the Bluefiles and ZED tools, depending on sensitivity and context.

Services

IservicesCSIRT offers its members the following services:

1. Cyber incident management

  • Incident severity assessment.
  • Incident categorization.
  • Incident resolution: carries out investigations and forensics to determine the root cause of the incident; shares information with legal and institutional authorities when necessary; proposes containment, eradication and recovery plans; collects evidence for legal and institutional purposes.
  • Provides the technical elements needed by the crisis cell.

2. Threat intelligence

The IservicesCSIRT CTI service is responsible for monitoring threats and vulnerabilities likely to impact its constituency.

  • Provides knowledge of the threat landscape to guide CSIRT actions.
  • Monitors and collects information relevant to the CSIRT constituency.
  • Capitalizes on and contextualizes raw information collected.
  • Analyzes collected data to support decision-making.
  • Shares intelligence with stakeholders at strategic, tactical and operational levels, according to the TLP.
  • Provides intelligence on vulnerability exploitation by threat actors.
  • Provides the intelligence needed by the crisis cell.
  • Shares relationships with other CSIRTs, CERTs and communities according to the need-to-know principle.
  • Develops detection rules and signatures.

3. Cyber event management (service partly delegated to the SOC)

IservicesCSIRT is responsible for circumstance detection, in order to anticipate and manage incidents based on identified threats that may target its clients.

4. Vulnerability management

  • Assesses the exposure of targeted assets.
  • Assesses the criticality of vulnerabilities and their technical components.
  • Provides recommendations related to vulnerabilities.

5. Service level commitments

To date, IservicesCSIRT has no service level commitments.

Incident reporting

IservicesCSIRT encourages incidents to be reported using encrypted emails, with the following information:

  • Contact and organization information;
  • A summary of the incident, emergency or crisis;
  • The date and type of event;
  • The source of the information;
  • The affected systems;
  • The impact assessment;
  • Details of the observations that led to the discovery of the incident;
  • Relevant technical data;
  • The TLP/PAP.

Disclaimer

Not applicable.

Ready to Work With Us?

Join hundreds of satisfied clients who trust Iservices with their technology needs. Let's discuss how we can help transform your business.

Get our alerts by email

Subscribe to receive our security alert bulletins and our latest articles straight to your inbox.