About Machine Translation

This site uses machine translation. Please note that it may not always be accurate and may differ from the original Japanese text.
This website uses a generative AI

Awareness training for Guidance for CSIRT Formulation and Incident Handling (23rd January 2026)

The awareness training “Guidance for CSIRT Formulation and Incident Handling” was conducted on 23rd January 2026 in Phnom Penh, targeting Government Organizations, Critical Information Infrastructure Operators, and Educational Institutes in Cambodia.

A part of the project activities, reference materials have been developed to strengthen the operational capacity of CSIRT (Computer Security Incident Response Team) across organizations in Cambodia and to promote awareness of cybersecurity practice. This training was organized based on the contents of these two materials currently being prepared, the “CSIRT Formulation Guide” and the “Incident Handling Manual” with officers from the Ministry of Post and Telecommunications (MPTC) taking the lead in planning and delivering the training.

The materials under development include the following:
(1) CSIRT Formulation Guide
The document outlines a seven-phase implementation framework to formulate a CSIRT, including preparation and strategy, governance, team formation, technology and tools, operational process development, training and simulation, and operational launch and improvement.

(2) Incident Handling Manual
The manual explains the basic processes of incident handling for CSIRTs; detection and analysis, containment, eradication, recovery, and post-incident activities, based on international standards.

(3) Incident Handling Playbook
A set of Standard Operating Procedures (SOPs) that provides concrete step-by-step actions for different types of incidents, enabling practitioners to respond promptly and effectively when incidents occur.

The awareness training saw the participation of a total of 29 participants. This included MPTC officers from various departments involved cybersecurity, as well as representatives from other ministries such as the Ministry of Economy and Finance (General Department of Taxation), the Ministry of Commerce, and the National Bank of Cambodia. It also included Critical Information Infrastructure operators such as Electricite du Cambodge, financial institutes, telecommunications companies, and from educational institutions such as the Cambodia Academy of Digital Technology and so on.

During the training, participants learned about the seven-phase implementation framework for CSIRT formulation project and the full cycle of incident handling, from detection to recovery and post-incident review, using general examples drawn from government CSIRT operations. In particular, significant time was dedicated to a practical exercise on developing a CSIRT masterplan, enabling participants to envision concrete CSIRT formulation projects within their respective organizations.

It is expected that the knowledge and experience gained through this training will support the formulation and enhancement of CSIRT operations across the organizations. Furthermore, the training is anticipated to promote coordination among CSIRTs across different organizations and sectors, contributing to the overall strengthening of national cybersecurity framework in Cambodia.

In addition, strengthening Cambodia’s national cybersecurity framework in this manner is expected to contribute to Japan’s growth strategy goal of “realizing safe and secure digital transformation,” and to promote not only the stability of cyberspace in the Asia region, including Japan, but also the development of the cybersecurity industries in Japan and Cambodia.

photo

photo

photo

photo

photo