CCN-CERT policy on the exchange and processing of information

As the Spanish National Government CERT, the CCN-CERT must share information with various communities and entities. To this end, mandatory terms of use are established for all recipients, specifying how this information (whether technical or otherwise) should be shared and managed.

Therefore, the CCN-CERT maintains a dual-labeling policy using two internationally recognized classifications:

  • TLP (Traffic Light Protocol) labeling
  • PAP (Permissible Actions Protocol) labeling

NOTE: These classifications do not replace protection classifications (such as "Restricted" or "Limited Dissemination") or classified information classifications (such as "Confidential", "Reserved" or "Secret").

TLP Labeling

Available at www.first.org/tlp for information dissemination. The assigned color determines the conditions:

 TLP:RED  For designated recipients only. Do not share with anyone else. If sharing is deemed necessary, explicit consent from the author must be obtained.
 TLP:AMBER+STRICT  Limited disclosure; recipients may only disseminate this information based on need-to-know within their organization.
 TLP:AMBER  Limited disclosure; recipients may only disseminate this information based on need-to-know within their organization and partner organizations.
 TLP:GREEN  Limited disclosure; recipients may disseminate it within their community. Recipients may share TLP:GREEN information with peers and partner organizations within their community, but it should not be shared on public channels (such as social media, websites, or open mailing lists).
 TLP:CLEAR  Recipients may disseminate it worldwide; there are no limits to its dissemination.

PAP labeling

The TLP protocol must be complemented by PAP, which defines what can be done with the shared information, beyond who can see it:

 PAP:RED  Information can only be used in a way that does not generate traceability or alerts visible to third parties.
 PAP:AMBER  Only passive actions are allowed, such as analysis or verification with third-party sources (e.g., VirusTotal). Direct interaction with the target is not permitted.
 PAP:GREEN  Active actions are allowed, such as blocking communications or interacting with the target in a controlled manner.
 PAP:CLEAR  No restrictions.