SL Benfica Logo

Total

0,00€

Buy

CSIRT

RFC 2350

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512


1. Document Information
This document describes the coordination service for Information Security incident response of Sport Lisboa e Benfica, in accordance with RFC 2350.


1.1 Date of Last Update
Version 4.0 published on 21/08/2025.


1.2 Notification Distribution List
There is no distribution channel to notify changes to this document.


1.3 Locations Where This Document Can Be Found
The updated version of this document is available at www.slbenfica.pt/apoio/csirt.


1.4 Authenticity of This Document
This document is signed with the PGP key of Benfica CSIRT.


2. Contact Information
2.1 Team Name

Benfica CSIRT


2.2 Address
Estádio do Sport Lisboa e Benfica – Gate 18
Av. Eusébio da Silva Ferreira 1500-313 Lisbon, Portugal


2.3 Time Zone
Portugal (UTC+0 standard time, UTC+1 daylight saving time)


2.4 Telephone Number
+351 217 219 500


2.5 Fax Number
Not available


2.6 Other Communications
Not available


2.7 Email Address
csirt@slbenfica.pt – Email address for reporting security incidents


2.8 Public Keys and Encryption Information
PGP KEY ID: 4D96 FB29 6CAD DDDA
PGP Fingerprint: 79CB 8CA7 5286 BF9B 9F1A AAE8 4D96 FB29 6CAD DDDA


2.9 Team Members
Confidential


2.10 Other Information
All public information about Benfica CSIRT is available at www.slbenfica.pt/apoio/csirt


2.11 Contact Points for Users
Sport Lisboa e Benfica provides the contact means listed in sections 2.2 and 2.4 to 2.7 (inclusive).


3. Team Charter
3.1 Mission

Benfica CSIRT is responsible for monitoring, detecting, and responding to information security incidents in the served community. Forensic audits and security awareness are also the responsibility of Benfica CSIRT.


3.2 Constituency
Benfica CSIRT is responsible for responding to information security incidents related to employees, assets, and all domains of Sport Lisboa e Benfica, namely: domain and subdomains slbenfica.pt, benficaplay.pt, museubenfica.pt, 83.240.140.70/32, 88.157.149.90/32, 88.157.224.200/29, 62.48.176.96/27, 195.23.64.32/27.


3.3 Affiliation
Benfica CSIRT is a team of Sport Lisboa e Benfica.


3.4 Authority
Benfica CSIRT is mandated by the CSSO (Chief Safety & Security Officer) of Sport Lisboa e Benfica.


4. Policies
4.1 Types of Incidents and Level of Support

Benfica CSIRT responds to all types of Information Security incidents, particularly those that result in a security breach of the following types:

  • Malicious Code
  • Availability
  • Information Gathering
  • Intrusion
  • Attempted Intrusion
  • Information Security
  • Fraud
  • Abusive Content
  • Vulnerability
  • Other ("Unspecified" or "Undetermined")


4.2 Cooperation, Interaction and Information Disclosure
Internal policies of Sport Lisboa e Benfica state that sensitive information may only be shared with third parties in case of necessity and with the prior and explicit authorization of the individual or entity concerned.


4.3 Communication and Authentication
Among the communication means provided by Benfica CSIRT, telephone and unencrypted email are considered sufficient for non-sensitive information. For sensitive information, PGP encryption is mandatory.


5. Services
5.1 Incident Response

Benfica CSIRT will assist with the technical and organizational details of security incidents. In particular, it will provide support and advice regarding the following aspects of incident coordination.


5.1.1 Incident Triage
Verification of the authenticity of a reported incident and determination of its criticality and priority.


5.1.2 Incident Coordination
Identification of the root cause of the incident, facilitating contact with third parties and judicial authorities. Benfica CSIRT will also report to other national and international CSIRTs and collaborate with them.


5.1.3 Incident Resolution
Correction of vulnerabilities, removal of preventive measures, and preservation of data collected during the previous phases.


5.2 Proactive Activities
Benfica CSIRT performs the following proactive activities:

  • Security Tools
  • Awareness
  • Education and Training
  • Regular Alerts to the Community


6. Incident Reporting Form
There is currently no specific form for reporting incidents. Reports should be sent via email to csirt@slbenfica.pt, containing all relevant information.


7. Legal Notice
Although all precautions are taken in preparing the disclosed information, Benfica CSIRT does not assume any responsibility for errors or omissions, or for damages resulting from the use of this information.


-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQR5y4ynUoa/m58aquhNlvspbK3d2gUCaKw56QAKCRBNlvspbK3d 2iCxAP9MoSOf/6BZ2OgJUwgty9BD3Q2rxT5+WiXba+Sn5XeIUAEAnCGTuFJlCgQK wWbB2KgHPRBHzGNipIozl+0vKh5y2A4= =OQp3
-----END PGP SIGNATURE-----