Vancouver SecSig, (ISC)2, and ISSA Vancouver Chapters It’s a Cloudy Day
January 2 1 , 2 0 1 5
British Columbia
Vancouver SecSig, (ISC)2, and ISSA Vancouver Chapters Its a Cloudy - - PowerPoint PPT Presentation
Vancouver SecSig, (ISC)2, and ISSA Vancouver Chapters Its a Cloudy Day British Columbia January 2 1 , 2 0 1 5 Welcome Agenda Time Topic Speaker 8:30 8:45 Welcome & Review Days Agenda Glen Bruce 8:45 9:15 ISO 27000
January 2 1 , 2 0 1 5
British Columbia
3 Time Topic Speaker 8:30 – 8:45 Welcome & Review Day’s Agenda Glen Bruce 8:45 – 9:15 ISO 27000 standards overview and Update Glen Bruce 9:15 – 10:30 ISO Cloud Security Standards Eva Kuiper 10:30 – 11:00 Coffee Break 11:00 – 12:00 Cloud Security Certification Glen Bruce 12:00 – 1:00 Lunch Break – Sponsored by Deloitte 1:00 – 2:00 Feeling Security in the Cloud Alvin Madar 2:00 – 3:00 Cloud Considerations: A Developer’s Point of View Imraj Pasricha 3:00 – 3:30 Coffee Break 3:30 – 5:00 Panel Discussion – Current and Future State of Cloud Security Eric Paynter, Chester Wisniewski, Joost Houwen, Orvin Lau 5:00 Wrap up
4 Time Topic Speaker 8:30 – 8:45 Welcome & Review Day’s Agenda Glen Bruce 8:45 – 9:15 ISO 27000 standards overview and Update Glen Bruce 9:15 – 10:30 ISO Cloud Security Standards Eva Kuiper 10:30 – 11:00 Coffee Break 11:00 – 12:00 Cloud Security Certification Glen Bruce 12:00 – 1:00 Lunch Break – Sponsored by Deloitte 1:00 – 2:00 Feeling Security in the Cloud Alvin Madar 2:00 – 3:00 Cloud Considerations: A Developer’s Point of View Imraj Pasricha 3:00 – 3:30 Coffee Break 3:30 – 5:00 Panel Discussion – Current and Future State of Cloud Security Eric Paynter, Chester Wisniewski, Joost Houwen, Orvin Lau 5:00 Wrap up
5 Vancouver SecSig Security Management
6 Vancouver SecSig Security Management
I SO/ I EC 2 7 0 0 0 Fam ily Standards Process
International Organization for Standardization (ISO) International Electrotechnical Commission (IEC) Joint Technical Committee 1 (JTC1) Subcommittee 27 (SC 27) Security Techniques Working Group 1 (WG1) Information Security Management Systems ISO 27000 ISMS Family
maintenance of the ISO/ IEC 27000 ISMS standards family
for future ISMS standards and guidelines
WG1 standing document SD WG1/ 1 (WG1 Roadmap)
working Groups in SC 27, in particular WG4 – Security Controls and Services
7 Vancouver SecSig Security Management
Structure of ISO 27000 series
27000 Fundamentals & Vocabulary 27001:ISMS 27003 Implementation Guidance 27002 Code of Practice for ISM 27004 Metrics & Measurement 27005 Risk Management 27006 Guidelines on ISMS accreditation 27007 Guidelines for ISMS auditing 27008 Guidance for auditors on ISMS controls (TR) 27014 Information Security Governance
8 Vancouver SecSig Security Management
The I SO 2 7 0 0 0 Standards Available Today
ISMS
27002
ISO/ IEC 20000-1
services
information (PII) in public clouds acting as PII processors
systems for the energy industry
9 Vancouver SecSig Security Management
The I SO 2 7 0 0 0 Standards Available Today
implementation of network security
threats, design techniques and control issues
networks using security gateways
networks using Virtual Private Networks (VPNs)
Overview and concepts
Requirements
Guidelines for ICT supply chain security
preservation of digital evidence
1 0 Vancouver SecSig Security Management
The Rem aining I SO 2 7 0 0 0 I SMS Fam ily
professionals
Guidelines for security of cloud services
Prevention] Systems (IDPS)
investigative methods
1 1 Vancouver SecSig Security Management
I SO 2 7 0 0 1 : I SMS Certificates
Certificates – 2 2 ,2 9 3 in 1 0 5 countries Japan – 7 ,0 8 4 China – 1 ,7 1 0 UK – 1 ,9 2 3 I ndia – 1 ,9 3 1 USA – 5 6 6 Canada – 6 6
112 212 322 329 435 552 712 1064 1432 2172 3563 4800 5289 6379 7950 4210 5550 5807 7394 8788 9665 10422 10748 383 519 839 1303 1328 1497 1668 2061 71 128 206 218 279 332 451
,0 5,000 10,000 15,000 20,000 25,000 2006 2007 2008 2009 2010 2011 2012 2013
I SO/ I EC 2 7 0 0 1 - W orldw ide total
Middle East Central and South Asia East Asia and Pacific Europe North America Central / South America Africa
1 2 Vancouver SecSig Security Management
Other Related I SO Standards
Terminology Terms and definitions
Systems and Software Engineering – Software life cycle processes
security
Financial services – Information security guidelines
Non-repudiation
Systems and Software Engineering – System life cycle processes
Common Criteria for Information Technology Security Evaluation
Concepts
Requirements for Bodies Providing Audit and Certification of Management Systems
systems
1 3 Vancouver SecSig Security Management
Other Related I SO Standards continued
Guidelines for Auditing Management Systems
Software Asset Management
requirements
service management systems
applicability of ISO/ IEC 20000-1
management
recovery services
1 4 Vancouver SecSig Security Management
I SO 2 7 0 0 0 series : Benefits/ Obstacles
BENEFI TS
OBSTACLES
15 Time Topic Speaker 8:30 – 8:45 Welcome & Review Day’s Agenda Glen Bruce 8:45 – 9:15 ISO 27000 standards overview and Update Glen Bruce 9:15 – 10:30 ISO Cloud Security Standards Eva Kuiper 10:30 – 11:00 Coffee Break 11:00 – 12:00 Cloud Security Certification Glen Bruce 12:00 – 1:00 Lunch Break – Sponsored by Deloitte 1:00 – 2:00 Feeling Security in the Cloud Alvin Madar 2:00 – 3:00 Cloud Considerations: A Developer’s Point of View Imraj Pasricha 3:00 – 3:30 Coffee Break 3:30 – 5:00 Panel Discussion – Current and Future State of Cloud Security Eric Paynter, Chester Wisniewski, Joost Houwen, Orvin Lau 5:00 Wrap up