www.enisa.europa.eu 1
Data Collection of Security Incidents Data Collection of Security Incidents and Consumer Confidence and Consumer Confidence
- Is a partnership feasible?
Is a partnership feasible? -
- Carsten Casper
Data Collection of Security Incidents Data Collection of Security - - PowerPoint PPT Presentation
Data Collection of Security Incidents Data Collection of Security Incidents and Consumer Confidence and Consumer Confidence - Is a partnership feasible? - Is a partnership feasible? - - Carsten Casper Senior Expert at ENISA FIRST
www.enisa.europa.eu 1
Is a partnership feasible? -
www.enisa.europa.eu 2
COM(2006) 251
www.enisa.europa.eu 3
Public interest
Partner ship
Secrecy
www.enisa.europa.eu 4
Motif Established relationship Control of environment Control of partners Control of communication Control of storage Competence / expertise Good feeling Legal certainty Accurate labeling Monetary incentive Equal / fair treatment Upon recommendation
www.enisa.europa.eu 5
Violation of law
Motif for abuse Violation of corporate rules Benefits < risks Any suspicions Absence of incentives Unclear or inconsistent partners No time for evaluation Lack of budget Trust not transitive Sensitive data not separable Timing of sharing too difficult
www.enisa.europa.eu 6
and up-to-date statistical and economic data for effective policy making
enforcement can be measured
different countries
countries to get a bigger picture
tune their technical countermeasures
guaranteed benefits (information) without risks (loss of information)
specific benchmarking
harmonize their approaches with others It takes time to create trust between partners. Once achieved, an established partnership can bring benefits continously.
www.enisa.europa.eu 7
www.enisa.europa.eu 8
Click link to visit source
www.enisa.europa.eu 9
Infrastructures – Report 2007
in Europe & the US
www.enisa.europa.eu 10
– Federal Plan for Cyber Security and Information Assurance Research and Development – MELANI – Semi-Annual Reports – Emerging Risks-related information collection and dissemination: A study for ENISA
– CAIDA - Cooperative Association for Internet Data Analysis – ITU Survey on Trust and Cybersecurity 2006 – Secunia Advisory Statistics
www.enisa.europa.eu 11
www.enisa.europa.eu 12
www.enisa.europa.eu 13
“Initially time efforts in participation will probably be a critical success factor – there should be calculable time frames for fostering that framework project, which is not the case for "ongoing efforts" as in mailing lists or wikis – on the other hand, once established – those means are probably necessary to keep things evolving...”
various partners
discuss this topic in private
party can join)
members can veto the entrance of new members)
to store information
www.enisa.europa.eu 14
makers
aggregated data from others
related own projects
security controls
www.enisa.europa.eu 15
harmonization expertise
marketing, branding)
long-term funding)
logistics)
hardware, software)
www.enisa.europa.eu 16
collectively
www.enisa.europa.eu 17
www.enisa.europa.eu 18
www.enisa.europa.eu 19
www.enisa.europa.eu 20
www.enisa.europa.eu 21
www.enisa.europa.eu 22
www.enisa.europa.eu 23
www.enisa.europa.eu 24
www.enisa.europa.eu 25
www.enisa.europa.eu 26
www.enisa.europa.eu 27
Public collaboration Coordination on methodologies
CERTs MSSPs Universities EU/National statistics
National security
Providers IT security vendors National research networks
Closed partnerships Open partnerships No partnerships
Insurances
www.enisa.europa.eu 28
www.enisa.europa.eu 29
Questionnaire still available at http://www.enisa.europa.eu/pages/data_collection ENISA (European Network and Information Security Agency) Carsten CASPER Senior Expert - Information Security Policies, Tools & Architectures Technical Department +30.2810.39.1280 carsten.casper@enisa.europa.eu