VJ-CSIRT - RFC 2350 Description =============================== Vandens Jega Computer Security Incident Response Team 1. Document Information ----------------------- This document contains a description of VJ-CSIRT according to RFC 2350. It provides basic information about the team, its channels of communication, its roles and responsibilities. 1.1 Date of Last Update Version 1.0, 2026-09-08 1.2 Distribution List for Notifications There is no distribution list for notifications. Changes to this document are announced on the VJ-CSIRT website. 1.3 Locations where this Document May Be Found The current version of this document is available at: https://vandensjega.lt/csirt/rfc2350-en.txt A Lithuanian version is available at: https://vandensjega.lt/csirt/rfc2350-lt.txt 1.4 Authenticating this Document Both versions are signed with the VJ-CSIRT PGP key. The signature files are available at the same location with the extension .asc. The key is described in section 2.8. 1.5 Document Identification Title: VJ-CSIRT - RFC 2350 Description Version: 1.0 Document date: 2026-09-08 Expiration: this document is valid until superseded by a later version. 2. Contact Information ---------------------- 2.1 Name of the Team Short name: VJ-CSIRT Full name: Vandens Jega Computer Security Incident Response Team 2.2 Address VJ-CSIRT Atsakinga vandentvarkos asociacija "VANDENS JĖGA" Savanorių pr. 212 LT-03154 Vilnius Lithuania 2.3 Time Zone Europe/Vilnius EET (UTC+2) in winter, EEST (UTC+3) in summer. 2.4 Telephone Number +370 620 21915 2.5 Facsimile Number None. 2.6 Other Telecommunication Signal: +370 620 21915 2.7 Electronic Mail Address soc@vandensjega.lt This is the team mailbox. It is monitored by VJ-CSIRT staff and is the preferred channel for incident reports. 2.8 Public Keys and Encryption Information VJ-CSIRT uses OpenPGP for secure communication. Team key: User ID: VJ-CSIRT Fingerprint: 9EE8 1368 366F B2DC 64BE 5255 EC83 2BB4 DC60 E483 Valid until: 2030-09-08 The public key is available at https://vandensjega.lt/csirt/vj-csirt.asc and on public key servers (keys.openpgp.org). Please encrypt sensitive information sent to soc@vandensjega.lt with the team key. Signed messages from VJ-CSIRT are signed with the team key or with a team member key listed below. Team member keys (fingerprints): Vytis Radvila - D464 05F4 78BE D6DB 2A62 7C0A B60F 1B0D 5F96 BFFF Tomas Būdvytis - 6219 1822 D603 B76F B8A8 C7B2 97DB 3001 F056 AE5A 2.9 Team Members Head of team: Vytis Radvila Deputy: Tomas Būdvytis, Senior SOC Analyst The full list of team members is not published. Management, liaison and supervision are provided by the head of team. 2.10 Other Information General information about VJ-CSIRT and the sector SOC: https://vandensjega.lt/kibernetinis-saugumas/soc In April 2026 VJ-CSIRT was assessed by the National Cyber Security Centre of Lithuania (NKSC) against the SIM3 maturity model and meets the ENISA intermediate maturity level. 2.11 Points of Customer Contact The preferred method for reporting an incident is e-mail to soc@vandensjega.lt. Please use the team PGP key for sensitive content. For urgent matters, call the telephone number in section 2.4. Hours of operation: Monitoring of constituent infrastructure runs 24/7. Incident reports from external parties are handled on working days from 08:00 to 17:00 EET/EEST. Outside these hours an on-call procedure is in place; for urgent incidents please call the telephone number in section 2.4 or use Signal (section 2.6). 3. Charter ---------- 3.1 Mission Statement VJ-CSIRT strengthens the cyber resilience of the Lithuanian water supply and wastewater sector. The team provides continuous monitoring of IT and OT infrastructure, detects and coordinates the response to security incidents, and shares knowledge so that a threat detected in one organisation becomes protection for the whole sector. 3.2 Constituency The constituency of VJ-CSIRT consists of: - member organisations of Atsakinga vandentvarkos asociacija "VANDENS JĖGA" (Lithuanian water utilities association), listed at https://vandensjega.lt/asociacijos-nariai, - other Lithuanian water supply and wastewater operators that have concluded a SOC service agreement with the association. Services are provided to each constituent under a separate SOC service agreement. A formal description of the constituency (domains, IP ranges, AS numbers) is maintained internally and provided to trusted partners on request. 3.3 Sponsorship and/or Affiliation VJ-CSIRT is the Cyber Security Department (Kibernetinio saugumo skyrius) of Atsakinga vandentvarkos asociacija "VANDENS JĖGA", registered in Lithuania (company code 306128807). It was established in 2026 and is funded by the association and by service agreements with constituents. VJ-CSIRT cooperates with the National Cyber Security Centre of Lithuania (NKSC) under the Ministry of National Defence and takes part in the NKSC KSIS information-sharing network. The association is a member of the Lithuanian Cyber Security Experts Association and has a cooperation agreement with Klaipėda University. 3.4 Authority The mandate, constituency and responsibilities of VJ-CSIRT are defined in the Regulations of the Cyber Security Department, approved by the director of the association (order V-2026-03 of 2026-04-28), and in the SOC service agreements concluded with each constituent. Within those agreements the team may perform monitoring, investigate incidents and recommend or coordinate response actions. The final decision on actions inside a constituent's infrastructure remains with that constituent. VJ-CSIRT has no regulatory or law-enforcement powers. 4. Policies ----------- 4.1 Types of Incidents and Level of Support VJ-CSIRT handles all types of computer security incidents that occur in, or threaten, the IT and OT infrastructure of its constituency. Priority is given to incidents that may affect the safety or continuity of water supply and wastewater treatment (OT/SCADA systems), followed by incidents affecting confidentiality or integrity of data and availability of business IT. The level of support depends on the type and severity of the incident, the size of the affected constituency and available resources. Incidents are classified according to the internal VJ-CSIRT classification scheme defined in its operational procedures and reflected in the service agreements. VJ-CSIRT does not provide direct support to end users of constituent organisations. End users should contact their own IT department. 4.2 Co-operation, Interaction and Disclosure of Information VJ-CSIRT cooperates with NKSC, other national and sector CSIRTs, TF-CSIRT and Trusted Introducer teams, vendors and service providers, as needed to resolve incidents. External communication follows the Communication and Media Policy of the Cyber Security Department (director's order V-2026-02 of 2026-04-22). Handling of confidential information is governed by the department regulations. Information received by VJ-CSIRT is treated as confidential by default. Information is shared only to the extent necessary to handle an incident, and where possible in anonymised form. Information about a constituent is not disclosed to third parties without that constituent's consent, except where required by Lithuanian law. VJ-CSIRT supports the Traffic Light Protocol (TLP 2.0). Information marked with a TLP label is handled according to that label. Information without a label is treated as TLP:AMBER. 4.3 Communication and Authentication E-mail without encryption is acceptable for low-sensitivity information. Sensitive information must be encrypted with the VJ-CSIRT team PGP key (section 2.8). Telephone and Signal are acceptable for urgent coordination. Where authentication is required, VJ-CSIRT verifies the identity of the caller by calling back a known number or by using an alternative pre-agreed channel. 5. Services ----------- 5.1 Incident Response VJ-CSIRT assists its constituents in handling the technical and organisational aspects of incidents. Incident triage: verifying whether an incident occurred, assessing its scope and impact, assigning priority. Incident coordination: identifying affected organisations and parties, contacting them, coordinating actions between constituents, NKSC, other CSIRTs and vendors, and keeping records. Incident resolution: analysing evidence, recommending containment and recovery actions, supporting the constituent during recovery, and turning lessons learned into detection rules for the whole sector. 5.2 Proactive Activities - 24/7 security monitoring of IT, OT and SCADA systems (SIEM, XDR). - Threat intelligence and sector-specific threat analysis. - Vulnerability management support for constituents. - Honeypot operation and analysis. - Security advisories and warnings to constituents. - Monthly incident and vulnerability trend reports to constituents' technical teams and management. - Awareness and training activities for the sector. - Support for constituents' compliance with NIS2 and related national requirements (together with the association's CISO service). 6. Incident Reporting Forms --------------------------- No specific form is required. When reporting an incident by e-mail, please include where possible: - name of your organisation and a contact person with telephone number, - date and time of the incident (with time zone), - affected systems, IP addresses or hostnames, - description of what happened and its current impact, - any logs, indicators or other evidence (encrypted if sensitive), - the TLP label you want applied to the information. 7. Disclaimers -------------- VJ-CSIRT takes every reasonable precaution in preparing information, notifications and alerts, but assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained herein.