multi university partnerships
play

Multi-University Partnerships The CanSSOC Proof of Concept Welcome - PowerPoint PPT Presentation

Improved Cyber Security Through Multi-University Partnerships The CanSSOC Proof of Concept Welcome and Introductions Panel Gordie Mah Chief Information Security Officer University of Alberta Paul Weber Supervisor, IT Security Ryerson


  1. Improved Cyber Security Through Multi-University Partnerships The CanSSOC Proof of Concept

  2. Welcome and Introductions Panel Gordie Mah Chief Information Security Officer University of Alberta Paul Weber Supervisor, IT Security Ryerson University Mike Wiseman Associate Director, Information Security University of Toronto Moderator Isaac Straley Acting Director, CanSSOC / Chief Information Security Officer University of Toronto

  3. Canadian Shared Security Operations Centre (CanSSOC) is: • A shared proof of concept project • Based in part on a model initiated in the US higher education system • Being pursued in partnership with six Canadian universities: • The University of British Columbia, • University of Alberta, • McMaster University, • McGill University, • Ryerson University, • University of Toronto. • In Partnership with the National Research & Education Network • CANARIE – federal • Cybera - Alberta • ORION - Ontario • RISQ – Quebec • BCNET – British Columbia

  4. Value of a shared SOC “Together we see more” Global profile Attracting talent Economies of scale Higher Ed focus

  5. c c c c

  6. POC Operational Considerations Incident Infrastructure Threat Intel Log Ingestion Analysis Management Hardware platform(s) Identifying intel Location log Alerting based on Alerting mechanism sources known IOCs (email, ticketing, API, inventory On-prem vs Cloud etc.) Curation Asset identification Baseline of log Log collectors sources for prioritized alerts Incident tracking Formatting Events per second Alert volume & risk How to get updates Log schema (“EPS”) and Indicator of appetite Compromise (“IOC”) Incident resolution & throughput Deploying log considerations sharing collectors Real time analysis disposition Data retention Intel back to SOCs & Location Portal / ISACs Dashboard Monitoring

  7. Proposed Threat Intelligence

  8. Sample Analysis Architecture Collect Enrich Analyze Normalize

  9. Panel Discussion and Audience Questions

  10. Thank you! Stay informed and learn about the outcome of the CanSSOC Proof of Concept! CanSSOC website: https://canssoc.ca/ Contact: CanSSOC@utoronto.ca

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend