BlackDogs CSIRT Andorra · Team description

RFC 2350

This document describes BlackDogs CSIRT Andorra in accordance with the structure proposed by RFC 2350, "Expectations for Computer Security Incident Response".

1. Document Information

1.1 Date of Last Update

Version 1.0 — 11 September 2026.

1.2 Distribution List for Notifications

There is currently no distribution list for notifications about changes to this document. Questions about updates may be addressed to [email protected].

1.3 Locations where this Document May Be Found

The current version of this document is available at https://blackdogs.io/csirt/andorra/rfc2350.

Spanish and Catalan versions are available at /csirt/andorra/rfc2350/es and /csirt/andorra/rfc2350/ca. In case of discrepancy, the English version prevails.

1.4 Authenticating this Document

This document is published on the official BlackDogs Security website over TLS. The PGP key of BlackDogs CSIRT Andorra is published in section 2.8 and may be used to verify signed communications from the team.

2. Contact Information

2.1 Name of the Team

Full name
BlackDogs CSIRT Andorra
Short name
BD-CSIRT-AD

2.2 Address

BlackDogs CSIRT Andorra
BlackDogs Security Andorra, S.L.
Carrer Bonaventura Riberaygua, 36, 6è 3a
AD500 Andorra la Vella
Andorra

2.3 Time Zone

Europe/Andorra (CET, UTC+01:00; CEST, UTC+02:00 during daylight saving time).

2.4 Telephone Number

+34 930 18 66 17

2.5 Facsimile Number

Not available.

2.6 Other Telecommunication

Additional secure communication channels may be agreed bilaterally with constituents and partner teams.

2.7 Electronic Mail Address

[email protected] — this address reaches the team responsible for handling incident reports and coordination requests.

2.8 Public Keys and Other Encryption Information

Key ID
0x881C5CE5806EE9B3
Key type
RSA 4096
Fingerprint
05D9 A242 CE24 E6D0 13F2  A060 881C 5CE5 806E E9B3
Public key
csirt-blackdogs.asc

Sensitive material should be encrypted to this key before being sent by email.

2.9 Team Members

BlackDogs CSIRT Andorra is staffed by security specialists of BlackDogs Security Andorra, S.L. Individual team members are not published. Points of contact for a specific incident are communicated directly to the parties involved in that incident.

2.10 Other Information

General information about BlackDogs CSIRT Andorra is published at https://blackdogs.io/csirt. Machine-readable security contact information is published at /.well-known/security.txt in accordance with RFC 9116.

2.11 Points of Customer Contact

The preferred method for contacting BlackDogs CSIRT Andorra is email to [email protected]. For incidents requiring immediate attention, the telephone number in section 2.4 may be used in addition to the email report.

BlackDogs CSIRT Andorra operates Monday to Friday, 09:00–18:00 Europe/Andorra, excluding public holidays. Outside these hours, incidents affecting constituents whose agreement provides for it are handled through an on-call escalation process.

Written communication is accepted in English, Spanish and Catalan.

3. Charter

3.1 Mission Statement

The mission of BlackDogs CSIRT Andorra is to support the prevention, detection, analysis, containment and coordination of cybersecurity incidents affecting BlackDogs Security Andorra, S.L. and its constituency.

The team facilitates communication between affected parties, security providers, researchers and other CSIRTs when coordination is required.

3.2 Constituency

  • BlackDogs Security Andorra, S.L.'s own infrastructure, systems and services.
  • Organizations established, or with a permanent establishment, in the Principality of Andorra holding active agreements that explicitly include incident response, security monitoring, MDR, vSOC, DFIR or CSIRT-related capabilities within the agreed scope.
  • Other organizations may contact BlackDogs CSIRT Andorra regarding incidents or vulnerabilities involving BlackDogs infrastructure or customers.

Response capabilities, authority and service levels may differ depending on the applicable agreement with each constituent.

Organizations purchasing other BlackDogs Security Andorra, S.L. services are not automatically considered constituents of BlackDogs CSIRT Andorra unless incident response or coordination capabilities are included within the applicable agreement.

Incidents affecting entities established in the Principality of Andorra are coordinated with CSIRT-AD, the national reference team of the Principality, where the nature of the incident makes that coordination appropriate.

3.3 Sponsorship and/or Affiliation

BlackDogs CSIRT Andorra is operated and funded by BlackDogs Security Andorra, S.L., a cybersecurity and managed infrastructure company established in Andorra la Vella, Principality of Andorra.

BlackDogs CSIRT Andorra is a sister team of BlackDogs CSIRT, which is operated by BlackDogs Security, S.L. in Barcelona, Spain, and serves a separate constituency. The two teams share group infrastructure, including the contact address and the PGP key published in section 2.8, but hold separate mandates, constituencies and lines of authority.

BlackDogs CSIRT Andorra does not currently claim membership of, or accreditation by, any incident response community or trust group.

3.4 Authority

BlackDogs CSIRT Andorra operates under the authority granted by BlackDogs Security Andorra, S.L. and, where applicable, by contractual agreements established with its constituents.

Depending on the agreed service model, BlackDogs CSIRT Andorra may perform investigation, containment or remediation actions directly, or provide recommendations requiring approval from the affected organization.

The specific authority applicable to each constituent is defined contractually and may range from advisory and coordination-only functions to pre-authorized containment and remediation actions.

BlackDogs CSIRT Andorra does not perform intrusive actions against third-party systems without appropriate authorization.

3.5 Operating Model

BlackDogs CSIRT Andorra operates as a distributed and virtual CSIRT. Team members operate through controlled and secured access mechanisms to centralized incident response, monitoring and collaboration platforms.

The distributed operating model does not alter the team's authority, responsibilities, information handling requirements or incident management procedures.

4. Policies

4.1 Types of Incidents and Level of Support

BlackDogs CSIRT Andorra handles reports concerning security incidents, suspected compromises, malware, phishing campaigns, credential compromise, unauthorized access, vulnerabilities involving BlackDogs infrastructure, incidents involving BlackDogs-managed environments and requests for incident coordination.

Incidents are prioritized according to business impact, affected assets, scope, active exploitation, potential lateral movement, data exposure, operational disruption and regulatory implications. Four levels are used, with the following target times to acknowledge a report and begin triage: Critical — 4 hours; High — 1 business day; Medium — 2 business days; Low — 5 business days.

These are initial-response targets, not resolution times. Critical incidents are handled 24x7 where the applicable agreement provides for it; the remaining targets apply during the operating hours stated in section 2.11. Where a specific agreement establishes different service levels, that agreement prevails.

The level of support provided to a given party depends on the applicable agreement with that party. Reports from outside the constituency concerning BlackDogs infrastructure or customers are reviewed and acknowledged, and are acted upon at the discretion of the team.

4.2 Co-operation, Interaction and Disclosure of Information

BlackDogs CSIRT Andorra supports cooperation and information exchange with other CSIRTs, CERTs, security vendors, researchers, service providers and relevant authorities when required for effective incident coordination.

BlackDogs CSIRT Andorra may coordinate with national, governmental and sectoral CSIRTs and competent cybersecurity authorities in jurisdictions where its constituents operate, when required by the nature, severity, impact or regulatory implications of an incident.

Information received and shared is classified using the Traffic Light Protocol (TLP) 2.0. The designations TLP:CLEAR, TLP:GREEN, TLP:AMBER, TLP:AMBER+STRICT and TLP:RED are recognised and honoured. Reporters are encouraged to apply an appropriate TLP designation when sharing information. Where no TLP designation is provided, BlackDogs CSIRT Andorra determines the appropriate handling and disclosure restrictions based on the sensitivity and context of the information received.

Information sharing is performed according to applicable confidentiality requirements, contractual obligations and information classification. Information that identifies a constituent is not shared outside the incident without that constituent's consent, except where disclosure is required by law.

4.3 Communication and Authentication

Email is the primary communication channel. Sensitive material should not be transmitted through unencrypted email. Where email is used, sensitive material should be encrypted using the PGP key published in section 2.8. Alternative secure transfer mechanisms may be agreed with BlackDogs CSIRT Andorra.

Telephone is considered sufficient for non-sensitive coordination and for confirming the authenticity of email communication.

4.4 Evidence and Information Handling

BlackDogs CSIRT Andorra maintains appropriate controls for the collection, storage, access and transfer of incident-related information and digital evidence.

Access to incident information is restricted according to operational need and applicable contractual, legal and confidentiality requirements.

Where forensic evidence is collected, appropriate integrity verification and chain-of-custody procedures may be applied according to the requirements of the incident.

5. Services

5.1 Incident Response

  • Incident Triage — initial assessment, classification and prioritization of reported security incidents.
  • Incident Analysis — technical investigation of indicators, logs, endpoint activity, network events and suspicious artifacts.
  • Incident Response Support — support for containment, eradication, remediation and recovery activities.
  • Incident Coordination — coordination between affected organizations, service providers, security vendors and external CSIRTs.
  • Post-Incident Review — analysis of significant incidents to identify root causes, lessons learned, control improvements and opportunities to improve detection and response capabilities.

5.2 Proactive and Supporting Activities

  • Digital Forensics — forensic acquisition and analysis when required as part of incident response.
  • Malware Analysis — static and dynamic analysis of malicious or suspicious software.
  • Threat Intelligence — enrichment and contextualization of indicators, campaigns and adversary activity.
  • Vulnerability Coordination — coordination of vulnerabilities affecting BlackDogs infrastructure, services or constituency.
  • Threat Hunting — proactive investigation based on indicators, hypotheses and adversary techniques.

BlackDogs CSIRT Andorra may use the capabilities of the BlackDogs vSOC, DFIR and Threat Intelligence practices, but operates as a function distinct from the vSOC, which provides continuous monitoring, detection and operational security services.

5.3 Vulnerability Disclosure

Security researchers who identify a vulnerability affecting BlackDogs Security Andorra, S.L. infrastructure or services may report it to [email protected]. BlackDogs CSIRT Andorra encourages responsible and coordinated disclosure and requests that researchers provide sufficient time for investigation and remediation before public disclosure. The full Coordinated Vulnerability Disclosure Policy — scope, permitted research, disclosure timeline and safe harbour — is published at https://blackdogs.io/csirt/vulnerability-disclosure.

6. Incident Reporting Forms

BlackDogs CSIRT Andorra does not provide a structured reporting form. Incidents should be reported by email to [email protected], including the following information when possible:

  • Organization and contact details
  • Date and time of detection
  • Affected systems
  • Description of observed activity
  • Indicators of compromise
  • Relevant logs or evidence
  • Actions already performed
  • Impact or suspected impact
  • Preferred secure communication channel
  • TLP designation of the report

Passwords, private keys and unnecessary personal data should not be included in a report.

7. Disclaimers

While every precaution is taken in the preparation of information, notifications and alerts, BlackDogs CSIRT Andorra assumes no responsibility for errors, omissions, or for damages resulting from the use of the information contained within.

This document is provided for informational purposes and does not create contractual obligations. The services, response capabilities and service levels applicable to a given organization are governed exclusively by the agreement established between that organization and BlackDogs Security Andorra, S.L.

BlackDogs CSIRT Andorra does not claim accreditation, certification or membership of any incident response community. Any such status will be published in this document once formally granted.