SECURITY SIG IN MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011 Berlin, 15 December 2011 update.

Slides:



Advertisements
Similar presentations
The International Security Standard
Advertisements

Geneva, Switzerland, September 2014 ETSI TC Cyber Charles Brookson Chairman ETSI TC Cyber Zeata Security Ltd and Azenby Ltd ITU.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
National Institute of Standards and Technology 1 NIST Guidance and Standards on System Level Information Security Management Dr. Alicia Clay Deputy Chief.
SECURITY SIG IN MTS 28 TH JANUARY 2015 PROGRESS REPORT Fraunhofer FOKUS.
EOSC Generic Application Security Framework
The Value of Common Criteria Evaluations Stuart Katzke, Ph.D. Senior Research Scientist National Institute of Standards & Technology 100 Bureau Drive;
Standards Certification Education & Training Publishing Conferences & Exhibits 1Copyright © 2006 ISA ISA-SP99: Security for Industrial Automation and Control.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ETSI Conformance and Interoperability Testing Jørgen Friis VP ETSI SES (Standards Enabling Services)
SeON WG (GISFI #8) Agenda GISFI # 08, Mar 26-28, 2012, Patna Chair: Parag Pruthi, NIKSUN Chair-Delegate: Ashutosh Dutta, NIKSUN Vice-Chair: Debabrata Nayak,
Fostering worldwide interoperabilityGeneva, July 2009 Intelligent Transport Systems Presenter: Soeren Hess Chairman TC ITS Global Standards Collaboration.
Cybersecurity Presented by Charles Brookson OBE CEng FIET FRSA
© Cloud Security Alliance, 2015 March 2, Agenda © Cloud Security Alliance, 2015 The SecaaS Working Group Recent Activity Charter Category outline/templates.
Technology Services – National Institute of Standards and Technology Conformity Assessment ANSI-HSSP Workshop Emergency Communications December 2, 2004.
Update on ETSI Cyber Security work Charles Brookson OCG Security Chairman Largely based on presentations given by Judith E. Y. Rossebø ETSI TISPAN WG7.
Standards Certification Education & Training Publishing Conferences & Exhibits 1 Copyright © ISA, All Rights reserved ISA99 - Industrial Automation and.
SECURITY SIG IN MTS 02 ND OCTOBER 2013 PROGRESS REPORT Fraunhofer FOKUS.
Jeju, 13 – 16 May 2013Standards for Shared ICT ETSI Conformance and Interoperability Testing Jørgen Friis ETSI Chief Services Officer (CSO) Document No:
MEM Cybersecurity Working Group Update to PCD Technical Committee
Jürgen Großmann, Fraunhofer FOKUS
Smart Grid cyber security within IEC TC57 WG15
Security SIG#6‘ in MTS 26th November 2012 Agenda & report
SNOMED CT Education SIG: Strategic Plan Review
MEM Cybersecurity Working Group Update to PCD Technical Committee
ISO Smart and Sustainable Cities developments
Security SIG in MTS 05th November 2013 DEG/MTS RISK-BASED SECURITY TESTING Fraunhofer FOKUS.
Security SIG in MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011.
Status Report November 2007
Discussion on the Scope of TR- Trust Management in oneM2M
Berlin, 15 December 2011 update
Technical Organization and approval procedures
ETSI Conformance and Interoperability Testing
HIS Smart Grid – Summary (1)
Frances Cleveland Convenor WG15
Glenn Parsons, GTSC-9 Chair, ISACC
Security in MTS 14th May2013 SIG Report
Sophia Antipolis, 25 January 2012
Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON |
ارائه كننده: شاهين انتصاري
ISO/IEC 27001:2005 A brief introduction Kaushik Majumder
Cybersecurity Presented by Charles Brookson OBE CEng FIET FRSA
Security in MTS 19th September 2012 SIG Report
Security SIG in MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011.
9th International Common Criteria Conference Report to IEEE P2600 WG
Intelligent Transport Systems
TISPAN work on METHODS Security methods.
Smart Grid cyber security within IEC TC57 WG15
Berlin, 15 December 2011 update
Berlin, 15 December 2011 update
Informal document GRSG
ETSI role in Identity Management and Identification Systems
Security SIG#4 in MTS 10th August 2012
Smart Grids activities in ETSI
Security SIG#4 in MTS 10th August 2012 Report
Security SIG#5 in MTS 19th September 2012 Agenda
ISO Smart and Sustainable Cities developments
Group Meeting Ming Hong Tsai Date :
Security SIG#7 in MTS 18th January 2013 draft Agenda
Security SIG in MTS 27th January 2016 Progress Report
ETSI Standardization Activities on Smart Grids
Security SIG#6 in MTS 19th November 2012 draft Agenda
ESO response to EU RFID Mandate M/436
TIA TR-50 M2M-Smart Device Communications
ESO response to EU RFID Mandate M/436
Report of User WG Meeting
ETSI MTS#76 Meeting 23-Jan-2019
Name of Speaker, Title and Organization
Glenn Parsons, GTSC-9 Chair, ISACC
Recent Standardization Activities on Cloud Computing
Security in MTS 19th September 2012 SIG Report
Presentation transcript:

SECURITY SIG IN MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011 Berlin, 15 December 2011 update

Agenda Round Call Presentation Collection Introductory Presentation Motivation & „History“ (Tallinn meeting) Contribution by Scott Next steps, perspectives: Discussion of NWI drafts 2 Security SIG in MTS, 15 December 2011

Security Standardization bodies International, e.g. ISO, ITU European, e.g. ETSI, ENISA National, e.g. NIST, AFNOR, DIN Industrial communities, e.g. IEEE, OMG Security SIG in MTS, 4-5 October

Terminology (1): Standards The Common Criteria for Information Technology Security Evaluation (CC) is the driving force for the widest available mutual recognition of secure IT products. This web portal is available to support the information on the status of the CCRA, the CC and the certification schemes, licensed laboratories, certified products and related information, news and events.Common Criteria for Information Technology Security Evaluation (CC) The ISO series of standards have been specifically reserved by ISO for information security matters. This of course, aligns with a number of other topics, including ISO 9000 (quality management) and ISO (environmental management).ISO series Security SIG in MTS, 4-5 October

Terminology (2): Recommondations RFC2828RFC2828 (191 pages of definitions and 13 pages of references) provides abbreviations, explanations, and recommendations for use of information system security terminology. OUSPG/CodenomiconOUSPG/Codenomicon Glossary of Vulnerability Testing Threat modeling frameworkThreat modeling framework (Trike): security.org/dl/articles/Trike_v1_Methodology_Document- draft.pdf ETSI ISG on Security indicators ETSI ISG on Security indicators (ISI) starting with R2GS Club terminology … Security SIG in MTS, 4-5 October

Sample terms Asset: Anything that has value to the organization (27000) Entities that the owner of the TOE presumably places value upon (CC). Data, or occasionally a physical object, which is featured in the business Rules of the System.CC Attack: Attempt to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset (27000) A task which, if it worked, would help accomplish a threat (Trike).Trike … Control, Continuous Checking, Information Security Risk, Incident, Resilience, Security Event, Security Objective, Security level, … Security SIG in MTS, 4-5 October

Case studies experiences Industrial approaches validated in industry lead case studies, coming from ETSI members, e.g.: ITEA DIAMONDS project case studies: Smart Cards Industrial Automation Radio Protocols Transport/Automotive Telecommunication Security SIG in MTS, 4-5 October

TVRA framework - objectives TVRA is a method for use by ETSI standards developers undertaking an analysis of the threats, risks and vulnerabilities of a telecommunications system. Builds from (and complements) the Common Criteria (ISO/IEC 15408). 8 Security SIG in MTS, 4-5 October 2011

TVRA in ETSI technical commitees TISPAN WG7 (future WG “Risk management” on Privacy and Security technologies?) TR part 1, v4.2.3 ( ): method and proforma for TVRA part 2, v4.2.1 ( ): Protocol Framework Definition; Security Counter Measures TR v3.1.1 ( ): NGN Security TR v2.1.1 ( ): eSecurity, user guide to eTVRA STF 415 Security support to NGN: smart meter ITS: TR v1.1.1 ( ): Intelligent Transport Systems; Security: TVRA of 5,9 GHz radio communication in an ITS (vehicle-to-vehicle and vehicle-to-roadside) 9 Security SIG in MTS, 4-5 October 2011

Next steps Contributions in MTS Start Special Interest Group (SIG) for “security [testing]” First meeting 15 th December 2011 in Berlin: NWI TS focusing on security testing terminology (methodology etc.)? Similar to ongoing performance testing work NWI TR focusing on security including industrial case studies? Similar to ETSI TR (Application of Model-Based Testing in the Telecoms Domain) Collaboration with INT new work item on Security/Benchmarking test plan (using MSF inputs) Collaboration with TISPAN TVRA lacks on test methods Enrichment with (model-based) testing techniques? Latest news: TC TISPAN final meeting planned for February 2012, new group planned 10 Security SIG in MTS, 4-5 October 2011, updated 15 December 2011

More Steps & Perspectives Contribution to new ETSI Industrial Specification Group (ISG) on Information Security Indicators (ISI) Transfer to other international committees (e.g. ISO)  using PAS (public available specification) criteria to  initiate further international NWI (e.g. via DIN) ETSI members support: FOKUS, Conformiq, TestingTech, Codenomicon, FSCOM, … 11 Security SIG in MTS, 4-5 October 2011

Discussion “security” scope in MTS: Model / Specification, system risks Risk Analysis (paper-based) guidance “Testing” (to break the system) Scanning (libs) “known attacks” Functional / traditional testing Neg. testing, unknown vul., config mistakes fuzzing -> product (units,…) (light) penetration -> system (=deployed product) 12 Security SIG in MTS, 15 December 2011

Discussion (2) LifeCycle Activity Mapping (Slides presented by Ian Bryant) Risk analysis (refer to e.g. ISO/IEC 27005) Specification (refer to ISO/IEC SAF SP) Assurance: what you want to achieve (refer to ISO/IEC 15026) Verification (refer to ISO/IEC 15408) 13 Security SIG in MTS, 15 December 2011

Discussion (3) Links presented by Ari: Microsoft Security development lifecycle Microsoft.com/security/sdl SSDL Security Testing bsimm.com/online/ssdl/st Open Software security model Opensamm.org 14 Security SIG in MTS, 15 December 2011

Discussion (4) MTS(11)0091 Modelling and design for security (Document presented by Scott) UML diagrams for basic terms (objectives, requirements) Role for an extendd TPLan 15 Security SIG in MTS, 15 December 2011

Results Security “plan” in MTS: Three NWIs: Terminology “Educational” material Case study experiences Security design guide enabling test and assurance (V&V) To be uploaded online 16 Security SIG in MTS, 15 December 2011