security policy update
play

Security Policy Update Mike Stanfield OSG Security Team OSG - PowerPoint PPT Presentation

Security Policy Update Mike Stanfield OSG Security Team OSG Council Face-to-Face October 11 th , 2019 OSG Security Team Security Team Members: Susan Sons, CACR Indiana University Adrian Crenshaw, CACR Indiana University Josh Drake,


  1. Security Policy Update Mike Stanfield OSG Security Team OSG Council Face-to-Face October 11 th , 2019

  2. OSG Security Team Security Team Members: • Susan Sons, CACR Indiana University • Adrian Crenshaw, CACR Indiana University • Josh Drake, CACR Indiana University • Zalak Shah, CACR Indiana University • Mike Stanfield, CACR Indiana University 2 11 October 2019 | OSG Council Face-to-Face

  3. Policy Updates 3 11 October 2019 | OSG Council Face-to-Face

  4. Why are we updating policies? • IRIS-HEP Deliverable: − Realign the OSG Cybersecurity Program with the Open Science Cybersecurity Framework • Step one is a refresh of the OSG Security policies 4 11 October 2019 | OSG Council Face-to-Face

  5. Updated Policies • Master Information Security Policy & Procedures • Incident Response Policies & Procedures • Service Container Security Policy 5 11 October 2019 | OSG Council Face-to-Face

  6. Master Information Security Policy & Procedures • Describes the roles and priorities of the Security team. • Defines security expectations of OSG staff and users. • Moved exception management into a single source of truth. • Greatly reduced size (~10 pages). https://drive.google.com/file/d/1BfZb3il57Wn1NVnnLzvOCCHFOLhiI1-L/view?usp=sharing 6 11 October 2019 | OSG Council Face-to-Face

  7. Incident Response Policies & Procedures • Explicitly defining the process the OSG Security team uses during an incident. • Tested via a tabletop exercise, gaps identified and addressed. • Tested recently again during an incident (2019-10-03_001). − Some minor adjustments still to be made. https://drive.google.com/file/d/1radhu-qz8sNSWuEkL5Ykrx8-huUup844/view?usp=sharing 7 11 October 2019 | OSG Council Face-to-Face

  8. Service Container Security Policy • Addressing a need within OSG and the larger community. • Defines how we handle creation and validation of service containers. • Recently shared with EGI − Any WLCG container policies will use this as a starting point. https://drive.google.com/open?id=1yKjSSAIlHMeRxEAN45ltki1z_BBZbaaq 8 11 October 2019 | OSG Council Face-to-Face

  9. Evolving policies • These policy documents are in a draft state (but are nearly final). • Policy shouldn’t be stagnant - should review at least annually. • Still waiting final ET approval: please send us your feedback! 9 11 October 2019 | OSG Council Face-to-Face

  10. Questions? 10 11 October 2019 | OSG Council Face-to-Face

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend