yxwvutsrponmlkihgfedcbaYWUTSRPONMLKIHFEDCBA How Big is Your Digital - - PowerPoint PPT Presentation

yxwvutsrponmlkihgfedcbaywutsrponmlkihfedcba
SMART_READER_LITE
LIVE PREVIEW

yxwvutsrponmlkihgfedcbaYWUTSRPONMLKIHFEDCBA How Big is Your Digital - - PowerPoint PPT Presentation

yxwvutsrponmlkihgfedcbaYWUTSRPONMLKIHFEDCBA How Big is Your Digital Footprint? Can U Help? FISSEA Mark Loepker Defense-wide Information Assurance Program Office of the DoD Chief Information Officer Office of the Secretary of Defense


slide-1
SLIDE 1

yxwvutsrponmlkihgfedcbaYWUTSRPONMLKIHFEDCBA

Can U Help?

Footprint? Your Digital How Big is

FISSEA

Mark Loepker

Defense-wide Information Assurance Program Office of the DoD Chief Information Officer Office of the Secretary of Defense

slide-2
SLIDE 2

Today’s Discussion: DoD’s Challenges

2

It is Up to Us to Find Opportunities

slide-3
SLIDE 3

3 12/8/2015

How Can You…

The warfighter expects and deserves access to information – from any device, anywhere, anytime…

Measure What U Can’t C?

slide-4
SLIDE 4

4

…and this is HOW & WHERE we fight

slide-5
SLIDE 5

bersecurity Must Not Stifle Innovation

proving information security while …

 Increasing information sharing efficiency  Enhancing mission effectiveness  Progressing towards compatibility  Boosting collaboration  Ensuring Confidentiality, Integrity, Availability, Non-repudiation & Authentication

Think For A Change: The Cycle of Innovation

slide-6
SLIDE 6

bersecurity: What Keeps DoD Up @ Night?

Sh d R ibili i O C ll i Ch ll

Digital Persona Protection ider Threat/Continuous Monitoring Commercial Mobile Devices DIB/Supply Chain Management Cloud Services Cyber Workforce

slide-7
SLIDE 7

v

Digital Persona Protection

mbers of the DoD are coming under attack in cyber D CIO is developing a directive assigning responsibilities & outlining procedures eraging the lessons learned from past incidents Proposes 2 types of coverage (both consent-based): ctive - Protection of DoD-affiliated individuals for whom a ble threat has been identified & determined to be due to ation w/ DoD ctive - Pre-emptive protection of selected senior DoD

  • nnel
slide-8
SLIDE 8

DPP Risk & Mitigation Matrix

Risk Level Low High ustry ual

Courses of Action

Web‐based Education & Awareness Employee procured Commercial Credit Monitoring (e.g. LifeLock) Government‐subsidized Insurance (e.g. Liability Insurance) Government‐procured Commercial Full‐Service Personal PII and technical assistance Government‐procured Commercial Limited Personal PII and technical assistance Unavoidable online risk

Medium

Government/LE Full‐Service Personal PII and technical assistance Government/LE Limited Personal PII and technical assistance ( g ) Government‐procured Commercial Credit Monitoring (e.g. LifeLock)

Move from REACTIVE to PROACTIVE!

slide-9
SLIDE 9

as follows:ywvutsrponmlkjihgfedcbaI , such as their , date and place of birth, ’s maiden name, etc. w USG defines PII nformation which can be used to distinguish or trace n individual's identity name, social ecurity number biometric records, etc. alone, or hen combined with other personal or identifying nformation which is linked or linkable to a specific ndividual, such as mother

slide-10
SLIDE 10

PII as follows:ywvutsrponmlkjihgfedcbaI mean yutsrponmlihgfedcbaSIFEA any identifiable natural person person is , in particular number or to his social identity; d EU defines ersonal data' shall information relating to n identified or ('data ubject'); an identifiable

  • ne who can be

entified, directly or indirectly by reference

  • an identification
  • ne or more factors

pecific to physical, physiological, mental, conomic, cultural or

slide-11
SLIDE 11

where in the World is Your PII Stored? In the Cloud?

slide-12
SLIDE 12

Credit Reporting Agencies : They sell data points of your credit file

  • f Risk: Experia, Equifax Trans-Union

redit bureaus sells PII to 300 outside firms/Overseas/No US law High (ties directly to physical address) review for errors and fraud your credit profile from internal and external threats share records through marketing authorized access UNKNOWN - $$$$$ em: m: ial Risk ial Risk e e C C evel: vel:

  • ns:

ns: uiring your 3 credit reports to iring your 3 credit reports to ure re not sell or

  • t sell or

for un for un

slide-13
SLIDE 13

em: Medical Records ial Risk: T hey sell data points of your credit file e of Risk: Medical Information Bureau (MIB) Outlets All of your medical history in one repository /Access life and medical Ins evel: High (your health details, physical address, family members)

  • ns:

uire your medical report to see what it contains/Review for errors/fraud ure your medical profile file from unauthorized access y Access to your Medical Record for a given time UNKNOWN - $$$$$

slide-14
SLIDE 14

tly to physical address, desc

  • rized access
  • $$$$$

tem: em: Drivers License & Drivers License & Motor Vehicle Bureaus Records Motor Vehicle Bureaus Records tial Risk: ial Risk: They sell every data point of your file They sell every data point of your file e of

  • f Ri

Risk: k: Your State’s Driver’s License & Your State’s Driver’s License & Motor Vehicle Department Motor Vehicle Department Most States rely on the selling of your data for their budgets Most States rely on the selling of your data for their budgets evel: vel: High High (ties direc (ties direc ript riptio ion, fac facial image al image

  • ns

ns: : uest your State not sell your records est your State not sell your records nitor for for unau unauth th UNKN UNKNOWN OWN

slide-15
SLIDE 15

Tax Assessor Records : They sell data points of your credit file : Your independent City’s Reco dent City Sells your records and sends a copy to physical address) sell your records from the official public facing website. $$$$$ em: m: Real Property & Real Property & ial Risk ial Risk e of

  • f Risk

Risk rd Office/State Government rd Office/State Government Your Indepen

  • ur Indepen

the state the state l where they sell your record where they sell your record evel: vel: High (ties directly to High (ties directly to

  • ns:

ns: ues est your City & State not t your City & State not

  • ve your records
  • ve your records

UNKNOWN - UNKNOWN -

slide-16
SLIDE 16

dent physical address) em: m: Voters Records Voters Records ial Risk ial Risk: : They They sell data points of sell data points of your credit file your credit file e of

  • f Risk

Risk: : Your indepen Your indepen city’s voters record office city’s voters record office Name, address, SSN, Party Affiliation, Voting History ame, address, SSN, Party Affiliation, Voting History evel: vel: High (ties directly to High (ties directly to & Other PII & Other PII

  • ns:

ns: ues est your Voter’s t your Voter’s Registration Registration office not sell your records

  • ffice not sell your records
  • ve from
  • ve from public facing websites

public facing websites UNKNOWN - UNKNOWN - $$$$$ $$$$

slide-17
SLIDE 17

at? The DS-11/Application - c cy contacts linking others to you ment of State PIERS System ary Screening at Airports ccess/compromise physical address, other PII have an ea cess both within $$$$$ em: m: Passport Records Passport Records ial Risk ial Risk: : Insider Thre Insider Thre

  • ntains
  • ntains not

not only your

  • nly your

I I but also emergen but also emergen e of

  • f Risk

Risk: : Depart Depart and DHS’s Cust and DHS’s Custom and

  • m and

r Patrol Secon Patrol Second d 100s of 00s of doc documented unauthorized a mented unauthorized a leaked outside leaked outside evel: vel: High (ties directly to High (ties directly to and Emergen and Emergency ICE y ICE

  • ns:

ns: quest S uest State Department to ate Department to rly warning placed on rly warning placed on your records your records any unauthorized ac any unauthorized ac the PIERS system and hard copy pull the PIERS system and hard copy pull UNKNOWN - UNKNOWN -

slide-18
SLIDE 18

em: Credit Reporting Agencies ial Risk: Insider Threat; 80% of fact find e of Risk: US Census Bureau Most US Census employees and contractors have a minimal National y Check/Spotty- the amount of PII and relatives PII evel: High (ties directly to PII)

  • ns:

quest the Census Bureau to have an early warning placed on any unauthorized access quest the Census Bureau not share or sell your PII UNKNOWN - $$$$$ ers and server staff=contractors ers and server staff=contractors exposed is profound exposed is profound your records your records

slide-19
SLIDE 19

dit Cards : Insider Risk-Main/Backup servers in multiple countries : Nothing makes one more “place & where and when you charge on your card- also a Theft sells PII to 300 outside firms/Overseas/No US and place & time predictability) firms to place an early warning on al access + DO NOTshare or sell your PII. $$$$$ em: m: Cre Cre ial Risk ial Risk /US Law? /US Law? e of

  • f Risk

Risk time predictable” then the time predictable” then the e record of record of major major ce ce into ID into ID Credit bureaus redit bureaus law law evel vel: : High (ties into PII High (ties into PII

  • ns:

ns: ues est your credit card t your credit card your record for your record for nauthorized intern authorized intern UNKNOWN - UNKNOWN -

slide-20
SLIDE 20

em: Internet Service Providers (ISP) ial Risk: Insider Threat: Many Telephony employees have released mer profile records (credit information) along with call logs e of Risk: Your ISP & their Partners Records reveal who occupies the residence , artifact residue of your internet transmissions & determines you are HOME? evel: High (ties into PII, place/time & time predictability & address

  • ns:

Request ISP place an early warning on your record for any horized internal access and to not sell your data even to UNKNOWN - $$$$$ s about your laptop s about your laptop “trusted partners “trusted partners” ”

slide-21
SLIDE 21

: Internal Risk: Utilities have released consum : Utility Companies & their Partners: Water, Gas, Electricity main or backup servers overseas where US laws-ID insight into near real-time tracking and place in time predictability) place an early warning on your record for any al access and to not sell your data even to $$$$$ em: m: Utilities Utilities ial Risk ial Risk er profile records er profile records e of

  • f Risk

Risk Utility companies tility companies do not apply. Your flow rate =

  • not apply. Your flow rate =

evel: vel: High (ties into PII High (ties into PII

  • ns:

ns: st your utilities t your utilities horized intern

  • rized intern

“trusted partners “trusted partners” ” UNKNOWN - UNKNOWN -

slide-22
SLIDE 22

: Telephony employ des credit information) ne Service Provider- place an project another party or em: m: Telephony Telephony Records Records ial Risk ial Risk: : Internal Risk Internal Risk ees have released ees have released consumer consumer e records (which records (which inclu inclu along with call logs along with call logs e of

  • f Risk

Risk: : Telepho Telepho Verizon, Sprint, AT&T Verizon, Sprint, AT&T, & , & Vonage Vonage Makes one “place and time predictabl akes one “place and time predictable” and shows all your call looping e” and shows all your call looping

  • ur risk stream

ur risk stream evel: vel: High (ties into PII High (ties into PII plus place and time predictability plus place and time predictability) )

  • ns:

ns: ues est your telephony firm t your telephony firm early warning/No Change/No PII early warning/No Change/No PII Sale Sale e your home telephone your home telephone telephone # telephone # UNKNOWN - UNKNOWN - $$$$$ $$$$

slide-23
SLIDE 23

ss Confidentiality : Your true address- if used for mailings will be access : USPS your residenc actual people showing up at your door! ) and UPS divert your items to a CMRA s as your actual address running surveillance at this alternate site $$$$$ em: m: Addre Addre ial Risk ial Risk ible via net ible via net e of

  • f Risk

Risk A physical nexus directory to physical nexus directory to e and family cloud bring not e and family cloud bring not nwanted mailing but wanted mailing but evel: vel: High (ties into place and time predictability High (ties into place and time predictability

  • ns:

ns: ues est the USPS, FedEx t the USPS, FedEx ect ct the CMRA addres the CMRA addres k for persons for persons UNKNOWN - UNKNOWN -

slide-24
SLIDE 24
  • DoD Designated “Data Repo

s purpose is to emi-regulated FTC, Lexus Nexus, Xiom, West contain PII, your curren , voter info, and much-much more and place and time predictability) yo sell your data to anyone $$$$$ em: m: Information Brokers Information Brokers sitory sitory Org/DROs” Org/DROs” ial Risk ial Risk: : The DRO’s stated busines The DRO’s stated busines gain our PII gain our PII e of

  • f Risk

Risk: : S S la law w Thes hese electronic reports electronic reports t and past address t and past addresses, , n family, vehicles family, vehicles evel: vel: High (ties into PII High (ties into PII

  • ns:

ns: uest DROs place an early warning on est DROs place an early warning on ur record for any unauth ur record for any unauthorized

  • rized

al access l access NOT allow them to OT allow them to UNKNOWN - UNKNOWN -

slide-25
SLIDE 25

: Rampant unauthorized SNS and ISP Risk: All SNS and ISPs name, solicit information from followers High (ruin your good name and exploit others) remove any unauthorized accts investigative reasons and investigate same $$$$$ em: m: Fak Fake social netw social network

  • rk site

sites (SNS) (SNS) and ISP accounts and ISP accounts in your name in your name e of

  • f
  • ns:

ns: ial Risk ial Risk accounts in the high risk accounts in the high risk nnels’ name nels’ name Ruin your good uin your good & purport fraud & purport fraud evel: vel: ues est SNS and ISPs to t SNS and ISPs to erve evidence for rve evidence for UNKNOWN - UNKNOWN -

slide-26
SLIDE 26

yxwvutsrponmlkihgfedcbaYWTSRPONMLIHGFEDCBA

Deploying DPP to the DoD + …

Size, Scope, Diversity and Complexity

IT Systems

  • >$ 38 Billion in FY12
  • >$16 Billion in IT Infrastructure
  • >$3 Billion for Cyber Security
  • 1.4 million active duty
  • 750,000 civilian personnel
  • 1.1 million National Guard and

Reserve

  • 5.5+ million family members and

military retirees

  • 146 + countries
  • 6,000 + locations
  • 600,000 + buildings and

structures

  • >>10,000 Operational systems

(20% mission critical)

  • ~750 Data Centers
  • ~67,000 Servers
  • ~7+ million computers and IT

devices

  • Thousands of networks
  • Thousands of email servers,

firewalls, proxy servers, etc.

  • Mobile Devices

~ 250, 000 Blackberries ~ 3000 iOS Systems (Pilots) ~ 3000 Android Systems (Pilots)

DoD IT User Base Total IT Budget

slide-27
SLIDE 27

mark.loepker@osd.mil