How to Share Best Security Practices Urpo Kaila, EUDAT Security - - PowerPoint PPT Presentation

how to share best security practices
SMART_READER_LITE
LIVE PREVIEW

How to Share Best Security Practices Urpo Kaila, EUDAT Security - - PowerPoint PPT Presentation

How to Share Best Security Practices Urpo Kaila, EUDAT Security Officer urpo.kaila@csc.fi, security@eudat.eu WISE W orkshop for I nformation S ecurity for E -infrastructures 2015-10-22, Barcelona This work is licensed under the Creative Commons


slide-1
SLIDE 1

EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No. 654065

www.eudat.eu

How to Share Best Security Practices

Urpo Kaila, EUDAT Security Officer urpo.kaila@csc.fi, security@eudat.eu WISE Workshop for Information Security for E-infrastructures 2015-10-22, Barcelona

This work is licensed under the Creative Commons CC-BY 4.0 licence. Attribution: EUDAT – www.eudat.eu

slide-2
SLIDE 2

Standard Building Blocks of Information Security

Access ¡ Controls ¡ Security ¡and ¡Risk ¡ ¡Management ¡ ¡ Opera9onal ¡Security ¡ Network ¡Security ¡ So<ware ¡and ¡Service ¡ Development ¡Security ¡ ¡ Computer ¡Security ¡ Security ¡Reviews ¡ and ¡Tes9ng ¡ Asset ¡Management ¡ Several ¡ ¡frameworks ¡available ¡ ¡

Confiden9ality ¡ Integrity ¡ Availability ¡

Governance ¡ ¡ & ¡ITSM ¡

Assets ¡-­‑> ¡Risks ¡-­‑> ¡Controls ¡-­‑> ¡Metrics ¡

slide-3
SLIDE 3

Different kind and levels of security skills

Auditors IT Security Managers Service Managers Programmers Administrators, Operators Security Managers, Operating Engineers IT - Support Users Directors Experts on technical security

slide-4
SLIDE 4

Security Management (ISC)² CBK ISACA COBIT PECB … Technical Security SANS CEH BoK …

Well known legacy professional security skills definitions and certifications

Generic CISSP CISM GCED GCIH GSNA … Vendor specific (includes security) MTA RHCSE …

slide-5
SLIDE 5

By bragging? By experience? CV? By trainings obtained? By certifications achieved? Skills certifications are standard requirements in the private sector Obtaining and maintaining such certification is somewhat expensive A certification shows that a person knows at least the basics of the trade – it does not prove that the person is a senior professional, which requires more experience.

How do you measure security skills?

slide-6
SLIDE 6

It is difficult to apply them efficiently in your organisation

A common problem with generic

security skills and security guidelines

Proceed from outlining to to implementation

slide-7
SLIDE 7

The principles and theoretical skills must be adapted in your context in an reasonable and in an efficient way Best practices should be implemented Definition (wikipedia): A best practice is a method that has consistently shown superior. Best practices are used to maintain quality and can be based on

  • benchmarking. Best practices are a feature in

many of accredited management standards.

How can skills become practice?

slide-8
SLIDE 8

Necessary prerequisites Skills Management support A plan with check-ups Leadership (it will not just happen) Share experiences on how to implement with your peers Also cover confidential/sensitive information Informal information often more crucial than formal documents Apply the House of Chatham rule One size does not fit all

How could implementation be easier?

slide-9
SLIDE 9

I’ve had rewarding experiences in sharing best practices with

  • Several government agencies
  • Private companies
  • NREN’s
  • Universities
  • Research infrastructures

It would probably have been extremely difficult for us to achieve ISO 27001 without sharing best practices earlier

  • The standards and frameworks tell you what to do
  • Best practices tells you, by examples, how to do it

A successful track record

slide-10
SLIDE 10

Articles, books Presentations Trainings Reviews and audits Guidelines Site visits Workshops Informal communication

Methods of sharing best practices

N.B. Everything does not need to be formalised, informal f2f meetings are also very valuable

slide-11
SLIDE 11

Joint skills transfer program on operational security A training kit for Site Security Officers A non-profit lightweight skills certification for Site- Security Officers A voluntary practice sharing program for Site visits for ISMS sharing Peer reviews/audits of ISMS Articles on current ISMS practices Develop a multilateral NDA covering all of above An effort to apply resources and funding for all above I personally volunteer to contribute if feasible

Suggestions for joint ISMS activities

slide-12
SLIDE 12

www.eudat.eu

Thank you!

All comments are welcome to:

urpo.kaila@csc.fi

EUDAT related security incidents -> csirt@eudat.eu Other EUDAT security related -> security@eudat.eu