WISE Information Security for Collaborating E-Infrastructures

Slides:



Advertisements
Similar presentations
High level expert meeting to develop the Near East Regional Action Plan to Implement the Global Strategy to improve Agricultural and Rural Statistics.
Advertisements

Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Task force on Communications and Public Relations, TF-CPR (formerly known as TF-PR) Update March – June 2010 TF-CPR Workshop 15 October 2009 Carrie Solomon.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
| FOT-Net is a support action co-funded by the European Commission to network FOT activities at European, national and international level.
Global Action Plan and its implementation in other regions Meeting for Discussion of the draft Plan for the Implementation of the Global Strategy to Improve.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Nova Scotia Falls Prevention Update Preventing Falls Together Conference October 29, 2009 Suzanne Baker.
Office of the Federal Coordinator for Meteorology OFCM Opening Remarks and WG/WIST Activities Update Paul Pisano Mike Campbell WG/WIST Cochairs June 6,
InWEnt | Qualified to shape the future1 Internet based Human Resource Development Management Platform Human Resource Development Programme in Natural Disaster.
“ BIRD Project“ 1 Broadband Access, Innovation & Regional Development” Broadband Access, Innovation & Regional Development” Project Description Ulrich.
WLCG Security: A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) CHEP2013, Amsterdam 17 Oct 2013.
This document produced by Members of the Helix Nebula Partners and Consortium is licensed under a Creative Commons Attribution 3.0 Unported License. Permissions.
Networks ∙ Services ∙ People Alessandra Scicchitano TF-CSIRT meeting – Tallinn, Estonia SIG-ISM Update 24 th September 2015 SIG-ISM Secretary.
National Center for Supercomputing Applications Barbara S. Minsker, Ph.D. Associate Professor National Center for Supercomputing Applications and Department.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
JCN, Justice Cooperation Network European treatment and Transition management of High Risk Offenders.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
1 Item 2.1.b of the agenda IT Governance in the ESS and related issues Renewal of mandates STNE Adam WROŃSKI Eurostat, Unit B5.
The Competitiveness and Innovation framework Programme (CIP) ICT Policy Support Programme (PSP) Call 6 Grant EUROPEAN LOCATION FRAMEWORK Copyright.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
Networks ∙ Services ∙ People Laura Durnford TF-CPR, Cambridge What are other working groups up to? 29 October 2015 GÉANT.
Networks ∙ Services ∙ People GÉANT Community Innovation Programme DISCUSSION 14th October 2015 GÉANT General Assembly.
Scoping the Framework Guidelines on Interoperability Rules for European Gas Transmission Geert Van Hauwermeiren 20 th Madrid Forum, 26 Sept 2011.
Who doesn’t need to be WISE? Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
WP6 – Inter-operability with e-Infrastructures Sergio Andreozzi - WP6 Task Leader Strategy and Policy Manager, EGI.eu Helix Nebula - 1st Year Review 1.
Global Water Information Interest Group meeting RDA 7 th Plenary, 1 st March 2016, Tokyo Global Water Information Interest Group Welcome to the inaugural.
Project: EaP countries cooperation for promoting quality assurance in higher education Maria Stratan European Institute for Political Studies of Moldova.
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
GDB Introduction Ian Collier STFC Rutherford Appleton Laboratory GDB, May 11 th 2016.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Mastering the Art of Collaboration for WISEr Global Security
Security Management Geant SIG-SIM – Alf Moens
WISE 2016 WISE: a global trust community where security experts share information and work together, creating collaboration among different e- infrastructures.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
WISE WG STAA Awareness and Training
WISE people take action on security – Discussion
WISE 2017 Collaborating Communities
Dublin, february th SIG ISM Workshop.
The Integrated Food Security Phase Classification in Sudan –Next Steps
Certification of Trusted Repositories
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
Hannah Short CERN, Computer Security
“CareerGuide for Schools”
Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON |
Marine Strategy Framework Directive (MSFD)
Be WISE! Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
ROB PROW MIPI/MCMI ALTERNATIVE SOLUTIONS LIMITED
Update - Security Policies
Introduction to the Workshop
Projects under DTP Thematic Pole 2 TP2 (Framework Support for RDI)
David Kelsey (STFC-RAL)
Policy Development Processes in the APNIC Region
Marine Strategy Framework Directive (MSFD)
Update on progress since last WG meeting (13-14 June 2002)
Strategy
WORKSHOP “Emerging environmental pollutants: key issues and challenges” Stresa, Italy June 2006.
STRUCTURE AND METHODS OF CO-OPERATION
WISE Information Security for collaborating e-Infrastructures David Kelsey (STFC-RAL, UK Research and Innovation) ISGC2019, Taipei, 2 April 2019 In collaboration.
Tom Barton (WG Chair) University of Chicago and Internet2
NICE has many methods and processes
Closing event 16th July 2019 Technical Assistance for Establishing the Institutional Framework for the Implementation of AIS/AES Project funded by the.
Federated Incident Response
EOSC-hub Contribution to the EOSC WGs
WISE, SCI & policy templates David Kelsey (STFC-RAL, UK Research and Innovation) FIM4R & TIIME, Vienna, 11 February 2019.
9th ARHC Conference Murmansk, Russian Federation September 2019
Future GridPP Security
Presentation transcript:

WISE Information Security for Collaborating E-Infrastructures

Wise Information Security for Collaborating E- infrastructure What is WISE? Wise Information Security for Collaborating E- infrastructure A trusted forum where security experts can share information on different topics like risk management, tools for operational security and threat intelligence in the context of e-Infrastructures

How everything started Joint effort of GEANT SIG-ISM (Special Interest Group on Information Security Management) and SCI (Security for Collaboration among Infrastructures) Workshop in Barcelona Spain, October 2015 50 participants -an open forum where experts from its community exchange information, knowledge, ideas and best practices about specific technical or other areas of business relevant to the research and education networking community - SCI (Security for Collaboration among Infrastructures) is a collaborative activity of information security officers from several large-scale infrastructures, including EGI, PRACE, EUDAT, WLCG, XSEDE and HBP

How everything started Main idea: 4 big e-infrastructures EGI, EUDAT, GEANT and PRACE getting together to facilitate the exchange of experience and knowledge on security But also NRENs, XSEDE, NCSA, CTSC and communities like HEP/CERN, HBP and many others participated A profound need for a real collaboration became evident

WISE – The new born community WISE Workshop – Barcelona Supercomputing Center – October 2015

Since then June 2016 – BoF (Birds of a Feather meetup) at TNC16, Prague July 2016 – 1 day Workshop at XSEDE, Miami September 2016 – 1 day Workshop at DI4R, Krakow March 2017 – 2 day Workshop hosted by Nikhef, Amsterdam

Activities Working Groups Community of volunteers Led by a Steering Committee Two face-to-face meetings a year, focus on producing practical output Working Groups Updating the SCI framework (SCIV2-WG) Security Training and Awareness (STAA-WG) Risk Assessment WISE (RAW-WG) Security in Big and Open Data (SBOD-WG)

SCIV2-WG Updating the SCI framework: Existing framework created by the SCI (Security for Collaborating Infrastructures) group at ISGC 2013 SCIv2 will become the 1st WISE framework defining best practices, trust and policy standards for collaboration SCIV2-WG is finalising version 2 of the SCI document, which will be presented and endorsed at TNC17 in Linz (Austria) https://wise-community.org/updating-the-sci-framework/ The aim of this work was to establish a common understanding of the security measures each infrastructure has implemented and to start work on guidelines for interoperation such as the exchange of information during security incident handling

STAA-WG Security Training and Awareness: Training is wanted and needed for security professionals, systems and network managers and engineers, users of the infrastructures and for decision makers Main activities of the WG: Documenting good practices in security training Collecting information about existing training courses STAA-WG is defining v1 of the training catalogue for organisations in the WISE Community https://wise-community.org/training-and-awareness/ Several organisations already have some or several trainings in place, but not on all topics. Some others have to get started with a training programme. There is a lot of training in the commercial market and there is a lot of open source material available.

RAW-WG Risk assessment WISE: Large e-infrastructures are vulnerable to high impact security incidents because of the relatively easy way that an incident may spread among partner organizations due to the collaborative services that exist among the constituent organizations The objective of the RAW-WG is to provide e-infrastructures and their member organizations with guidelines on how Risk Assessments can be effectively implemented. RAW-WG is currently producing a draft of a risk management template to be shared among sites and infrastructures. https://wise-community.org/risk-assessment/ It is an important activity as part of the implementation of an Information Security Management System (ISMS). The implementation of effective security controls depends very much on a reliable risk assessment, so that the right measures can be taken. 

SBOD-WG Security in Big and Open Data: The WG focuses on security issues that arise when dealing with Big and Open data especially within the e-infrastructures Main activities of the WG: list and discuss already existing studies and state of the art the starting point for the rest of the work work on a list of issues particularly important for e-infrastructures and on a set of recommendations on how to minimize the impact of these issues https://wise-community.org/security-in-big-and-open-data/ Big data refers to large datasets that are not always public. Open data refers to datasets that are not necessarily large but are available to everyone and can be used and republished without restrictions. Large datasets from scientific research sources. Security issues in this context concentrate on confidentiality, integrity and availability. Confidentiality regulates access to the information, integrity assures that the information is trustworthy, i.e. has not been changed without authorisation, and availability guarantees access to the information by authorised people at any time.

Participate in WISE www.wise-community.org Join the WISE Mailing List Interested in any of the the working group subjects? Subscribe to the workgroup mailing list on the WISE website Contact the workgroup chair and let’s work together www.wise-community.org

Find out more www.wise-community.org

Questions? wise@lists.wise-community.org Thank you Questions? wise@lists.wise-community.org