RFC2350

1. Document Information

1.1 Date of last update: This is the latest version 3.0 dated March 18, 2025.

1.2 Distribution Lists: Changes to this document are announced in   and through the Cybolt SGIC Portal.

1.3 Document Location: The latest version of the document is published at: https://beaconlab.us/es/RFC2350-3/

2. Contact Information

2.1 Team Name: “BeaconLab”, Cybolt Cyber Incident Response Center

2.2 Address: Centro Tecnológico Metepec. Adolfo López Mateos 1956. Bellavista Metepec, 52148, Edo. Méx

2.3 Time Zone: CDMX, Mexico (GMT-6)

2.4 Phone Number: (+52) 8007374357 , (+52) 5550157483

2.6 Other Communications: The preferred form of communication is via email, telephone, videoconference, and other telecommunications options that can be coordinated upon request.

2.7 Email Addresses:

  • Exchange of information related to incidents: abuse@beaconlab.mx
  • General inquiries: info@beaconlab.mx
  • Other email addresses to contact are published at https://beaconlab.us/es/contacto/

2.8 Public Keys and information encryption: The contact emails and associated PGP keys are published at https:/es/contacto/ and are also stored at https://keys.openpgp.org

  • abuse@beaconlab.mx
    Fingerprints: 86DFD0305467D291829ED929B5B1C7292F28D349
  • info@beaconlab.mx
    Fingerprints: 97825B7D624250966FD7CEE8D11B075E3B25E7B7

2.9 Team Members:

Head: Luis Alfredo Herrera Camacho, luis.herrera@cybolt.com

The names and information of the members that make up BeaconLab are not publicly disclosed. In the event that a report is made, staff will identify themselves with their full name through formal communication.

2.10  More Information: General information about the services provided by BeaconLab is published on the web portal https://beaconlab.us/es/nosotros/ and at https://www.cybolt.com

2.11 Hours of Service: BeaconLab is available at the following hours:

  • Service inquiries: office hours (Monday to Friday 08:00 to 18:00 hours)
  • Incidents classified with low and medium criticality: office hours
  • Incidents classified with high criticality: 24×7

For operational inquiries (for example, the status of an existing ticket), contact abuse@beaconlab.mx

For general inquiries (for example, comments or how to subscribe to a mailing list), contact info@beaconlab.mx

2.12 Contact points for the community: Communication between the BeaconLab team and the community at large is through the following means:

3. Constitution

3.1 Mission:

3.2 Community served – “Target Community”:

It includes organizations, both national and international, with which Cybolt establishes a contractual relationship. The scope and coordination actions of each managed incident depend on the type of contract subscribed.

3.3 Sponsorship, Affiliation and Authority: BeaconLab is an entity dependent on the Security Managed Services Business Unit of Cybolt. The authority is given by an official mandate from the CEO of Cybolt.

4. Policies

4.1 Type of Incidents and level of support:

BeaconLab responds to all types of cyber security incidents that are reported to it by any client organization, in accordance with the client’s contract.

The scope of a cyber incident management by BeaconLab could include:

  • Preliminary analysis of the cyber incident.
  • Notification, coordination, and guidance to the actors involved and responsible for the affected systems for taking pertinent actions.
  • The proposal of pertinent recommendations for correction and future prevention.
  • Depending on the terms and conditions of the contract, the nature of the incident, the request and/or cooperation of the actors involved in the incident, and the established procedures, BeaconLab may collaborate in the application of immediate containment actions, as well as in the investigation and analysis of the compromised system.
    In those cases where the response to an incident has derived in recommendations for actions on assets, resources, or processes that are not managed by Cybolt or BeaconLab, or that are not included in the terms and conditions of the contract, they will be outside the scope of the service.
    In those cases where the response to an incident implies any corrective or preventive action on a product or service that is provided and managed by Cybolt, this will be included as part of the scope of the incident management.

4.2 Cooperation, interaction, and disclosure of Information:

The information handled by BeaconLab is treated with absolute confidentiality in accordance with the information security policies and procedures of BeaconLab and Cybolt’s policies, regulations, and standards.

BeaconLab does not publish or share with third parties detailed information about cyber incidents that have been reported to it, unless explicitly authorized by those affected or when requested through judicial channels.

Information about incidents will be shared only on a legitimate need-to-know basis for the incident management itself, both with the victim, the administrators of affected systems, or other CSIRTs, as long as there is a legitimate need to control, remedy, or prevent incidents. Whenever possible, this information will be shared in an anonymized manner and/or without revealing data that could identify victims.

BeaconLab may publish or share statistical information, as well as anonymized information about specific incidents for awareness and training purposes only, without revealing data that could identify victims or disclosing details that put actors involved at risk.

4.3 Communication and Authentication: The means available for communication with BeaconLab are:

5. Services

5.1 Incident Management

5.1.1 Incident Triage

BeaconLab offers technical and operational support in the various stages of the Incident Management process: detection, analysis, notification, containment, eradication, and recovery. This process includes the evaluation of available information and its prioritization (triage), validation and verification of the same, the scope, the collection of additional necessary evidence, and communication with the pertinent parties.

5.1.2 Incident Coordination

BeaconLab makes its best effort to determine the nature, scope, impact, and those affected by an incident, facilitating contact with other organizations that may be involved and/or affected.

It provides practical and actionable information, guidance, and recommendations to victims so that they can mitigate the cybersecurity incidents that affect them in the best way and provide policies and guides to improve their detection and prevention strategies.

BeaconLab collaborates with other Incident Response Centers (CERT/CSIRT) or Security Operations Centers (SOC) in all sectors through the exchange of information relevant to their target communities.

 

5.1.3 Recovery and Post-Incident actions

BeaconLab guides those involved with recommendations aimed at containing, mitigating, and remedying the incident, as well as with recommendations to avoid similar incidents in the future.

Likewise, it advises the client on the most appropriate actions, follows up on the Incident Management and the measures that the organization must take to prevent future cyber incidents.

According to the contractual terms, BeaconLab could provide technical and legal advice regarding forensic expertise, digital evidence preservation with chain of custody, digital forensic laboratory, and training in cybercrime investigation.

 

5.2 Prevention

BeaconLab provides different services in order to raise awareness and prevent any incident. Among them are:

  • Cybersecurity monitoring (SOC)
  • Managed cybersecurity services: It consists of the administration, monitoring, and operation of the client’s security platforms, for a quick and timely response to the alerts they generate, and also for their proper management and protection.
    • Managed SIEM
    • Managed Endpoint Protection
    • Managed Firewall
    • Managed Hardening
    • Managed Information Security
    • Identity Management
    • Vulnerability Management
  • Audits or vulnerability analysis of systems, networks, and software (code)
  • Reports, alerts, and notices about new threats and vulnerabilities of Threat Information Systems, collected from various recognized sources, including their own, as well as open sources (OSINT).
  • Research and dissemination of best practices on Information Security.
  • Development of Security Guides with regulations, procedures, and good practices.
  • Participation in Seminars, Conferences, Workshops, and Cybersecurity awareness events.
 
6. Incident reporting methods

Incident reporting can be done through the specific email mailbox: abuse@

7. Disclaimer

The BeaconLab Team is not responsible for any misuse that may be made of the information contained herein.

8. Code of Ethics:

The BeaconLab team adheres to the Ethics FIRST working group code of ethics: https://ethicsfirst.org/FIRST_EthicsfIRST_es.pdf

RFC2350 File in Spanish