Rome, 04.21.2009
A modern approach to ICT security in pubblic administration
- Cap. G.di F. Gabriele Cicognani
- CERT-SPC -
CERT-SPC: role and mission Cap. G.di F. Gabriele Cicognani - - - PowerPoint PPT Presentation
A modern approach to ICT security in pubblic administration CERT-SPC: role and mission Cap. G.di F. Gabriele Cicognani - CERT-SPC - Rome, 04.21.2009 Agenda SPCs architetture Scenario: security threats The CERT-SPC: role and
Rome, 04.21.2009
Scope
In compliance with Article 117(2)(r) of the Constitution, and in compliance with the autonomy of the internal organisation
autonomies, the public connection system, hereinafter referred to as “SPC”, shall be defined and regulated in order to ensure information and computer coordination of data between central, regional and local administrations and to promote uniformity in the creation and transmission of data, intended for the exchange and dissemination of information between public administrations and the creation of integrated services.
Scope
Architecture
Domini/sottoreti delle PAC Numero Accessi 28 7360 12 2.669 14 1.737 7 854 61 12620
QXN QXN Big Internet Big Internet
Intranet PA PA-
Infranet Internet PA PA-
2 PA PA-3 3 PA PA-4
Fornitore Fornitore -
2 Fornitore Fornitore -
1 QXN QXN Big Internet Big Internet
Intranet PA PA-
Infranet Infranet Internet Internet PA PA-
2 PA PA-3 3 PA PA-4
Fornitore Fornitore -
2 Fornitore Fornitore -
1
Architecture
Architecture
QISP1 AMM.n QXN QCN1
CG-SPC
QCNn ULS ULS ULS ULS ULS CG-SIC
IRT PKI
GESTORE CONTRATTO RS
CERT
SOC SOC SOC SOC
COMMISSIONE DI COORDINAMENTO
Architetture
Rome, 02.09.2009
Source: X-FORCE
Vulnerabilities disclosures
Source: X-FORCE Vulnerabilities ranking
Source: X-FORCE Web apps vulnerabilities 1998-2008 Percentage of disclosures that are Web apps vulnerabilities in 2008
Remotly exploitable vulnerabilities Source: X-FORCE
l
Source: X-FORCE Malware by categories
Handbook for Computer Security Incident Response Teams (CSIRTs)
CSIRT
Without providing at least a component of the incident handling service, the team cannot be called a CSIRT. Consider the analogy with a fire department. A fire department may provide a range of services (fire prevention, awareness, training), and it may undertake fire safety inspections. But at the core is the emergency response component. By providing the emergency fire department, it stays up-to-date and in touch with reality, and it gains community trust, respect, and
incidents through early detection and reporting or to prevent incidents, a team can be proactive through awareness, training, and other services; but without the incident handling service, the team is not a CSIRT.
Handbook for Computer Security Incident Response Teams (CSIRTs)
CSIRT
Other CERTs
CG-SIC Centri servizio
CERT
CERT-SPC
CSIRT
CG-SIC
Centri servizio
CERT
External community
The Common Vulnerability Scoring System v.2 is an industry standard for assessing the severity of computer system security vulnerabilities.It attempts to establish a measure of how much concern a vulnerability warrants, compared to other vulnerabilities, so efforts can be prioritized. The score is based
assessment. CVE is a dictionary of publicly-known information security vulnerabilities and exposures. This dictionary is maintained by MITRE Corporation
CG-SIC
Centri servizio
CERT
CG-SIC
Centri servizio
CERT
CG-SIC
Centri servizio
CERT