WISE WG STAA Awareness and Training

Slides:



Advertisements
Similar presentations
David A. Brown Chief Information Security Officer State of Ohio
Advertisements

Supportive Services for Veteran Families (SSVF) Data Bigger Picture Updated 5/22/14.
Security Controls – What Works
Cybersecurity Summit 2004 Andrea Norris Deputy Chief Information Officer/ Director of Division of Information Systems.
SkillsTech Australia Records & Reports Stage 2 Units: UEEPOO1,2,3B
Relentless in the Pursuit of Excellence Highland Technology Services Inc. 1 Section 508 Business Practices.
JPCERT/CC May Fixed-Point Auto Data Collecting System Getting more accurate Scan and Prove data to provide more accurate network traffic analysis.
Information Security Update CTC 18 March 2015 Julianne Tolson.
Network Security Resources from the Department of Homeland Security National Cyber Security Division.
Resources to Support Training Programs for CSIRTs.
Self-Assessment and Formulation of a National Cyber security/ciip Strategy: culture of security.
Security Professional Services. Security Assessments Vulnerability Assessment IT Security Assessment Firewall Migration Custom Professional Security Services.
Quality Assurance. Identified Benefits that the Core Skills Programme is expected to Deliver 1.Increased efficiency in the delivery of Core Skills Training.
1 Crusaders of Learning Overview ©2006 David J. Manley An Electronic Learning Community for Educators, Parents, and Students.
GGF Fall 2004 Brussels, Belgium September 20th, 2004 James Marsteller Pittsburgh Supercomptuing Center
AREVA T&D Security Focus Group - 09/14/091 Security Focus Group A Vendor & Customer Collaboration EMS Users Conference September 14, 2009 Rich White AREVA.
Disaster Recover Planning & Federal Information Systems Management Act Requirements December 2007 Central Maryland ISACA Chapter.
ST-09-01: Catalyzing Research and Development (R&D) Funding for GEOSS Florence Béroud, EC Jérome Bequignon, ESA Kathy Fontaine, US ST Kick-off Meeting.
One Academic Medical Center’s Response to HIPAA David McKelvey DUHS January 12, 2001.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
Reflections “from around the block.” (Security) Ian Neilson GridPP Security Officer STFC RAL.
IPv6 security for WLCG sites (preparing for ISGC2016 talk) David Kelsey (STFC-RAL) HEPiX IPv6 WG, CERN 22 Jan 2016.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
Chapter 3 Pre-Incident Preparation Spring Incident Response & Computer Forensics.
Who doesn’t need to be WISE? Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
Security and resilience for Smart Hospitals Key findings
Safeguarding CDI - compliance with DFARS
WISE Information Security for Collaborating E-Infrastructures
Mastering the Art of Collaboration for WISEr Global Security
Horizon 2020 Secure Societies European Info Day and Brokerage Event
Security Management Geant SIG-SIM – Alf Moens
Sample Fit-Gap Kick-off
WISE 2016 WISE: a global trust community where security experts share information and work together, creating collaboration among different e- infrastructures.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Higher Education Information Security Council
WISE people take action on security – Discussion
Cybersecurity - What’s Next? June 2017
WISE 2017 Collaborating Communities
Dublin, february th SIG ISM Workshop.
Computerized Systems in Clinical Research
Ian Bird GDB Meeting CERN 9 September 2003
Training and Outreach Materials
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
Decrypting Data Compliance in China
Leverage What’s Out There
Internet2 Update CSG at Yale University May 2017
6th SIG-ISM Workshop February 2018, Madrid
Hannah Short CERN, Computer Security
Open Science Grid: What is New?
5G Security Training
Programme Fortify Digital Security
Copyright © SAE International
An EDI Testing Strategy
Be WISE! Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
Cybersecurity Special Public Meeting/Commission Workshop for Natural Gas Utilities September 27, 2018.
David Kelsey (STFC-RAL)
EDUCAUSE Security Professionals Conference 2018 Jason Pufahl, CISO
CIPSEC architecture CIPSEC workshop Frankfurt 16/10/2018
HIT STANDARDS & INTEROPERABILITY COLLABORATIVE
Laia Guinovart Sogeti Luxembourg
Self-Governance Professionals Round Table Discussion April 1, 2019 (3:30 – 5:00 pm)
IT OPERATIONS Session 7.
MAARS Updates March2019.
WORKSHOP “Emerging environmental pollutants: key issues and challenges” Stresa, Italy June 2006.
Report of User WG Meeting
Tom Barton (WG Chair) University of Chicago and Internet2
Federated Incident Response
Future GridPP Security
Presentation transcript:

WISE WG STAA Awareness and Training WISE: a global trust community where security experts share information and work together, creating collaboration among different e-infrastructures Update on workgroup Security Training and Awareness Alf Moens WISE conference March 2017, Amsterdam

STAA: Security Training and Awareness The WISE community we recognise that there is a broad need for security training and for awaress materials We also see there is a lot of material available This working group will: Identify 5 to 10 most relevant training topics for the coming 3 years collect good training practices; collect information about relevant existing trainings by the infrastructures; map out the need for organising joint training events on specific topics; map out the need for developing trainings; set up a basic training and awareness programme for organisations in the WISE community, identifying which trainings are needed. Chairs: Alf Moens (SURFnet) – Jim Marsteller (PSC)

STAA: Some example trainings XSEDE Information Security Training CTSC training materials, NSF Cybersecurity Summit Transit I and II Risk management workshops Géant DDOS workshop End user training / awareness sessions SANS … Your training?

CTSC: Log Analysis Training with CTSC and Bro (Full Day) Federated Identity Management for Research Organizations (Full Day) REN-ISAC Cyberthreat Training Developing Cybersecurity Programs for NSF Projects Building a NIST Risk Management Framework for HIPAA and FISMA Compliance Secure Coding Practices and Automated Assessment Tools Securing Legacy Industrial Control Systems Secure Software Engineering Best Practices

STAA: clarification of the goals We are not going to develop trainings We will work on encouraging the sharing and joint development of trainings: Organise special topic trainings We will identify and recommend a good training practice We will identify good trainings based upon your experience Where should the focus be? Special topics: DDOS mitigation, monitoring, log file analysis End user training and awareness Security management, security governance and compliance

STAA: clarification of the goals (2) We might: Schedule special topic workshops and trainings (DDOS) Negotiate terms and conditions for use of materials or for commercial trainings Trainings can be classroom trainings on location or remote Trainings can be self paced learning or computer assisted (mooc) Or just a book, a reader or a wiki

STAA: training target groups Management/governance Systems management, system administrators Network engineers User coordinators Users Software developers Acquisition

STAA: Training subjects Target group Laws & Regulations (privacy, export) Systems management, users Secure Software development User, user coordinator, contractor System hardening System admin, network engineering Monitoring and logging System admin, network engineering, respnse teams Forensics Response teams Incident respons and analysis

Fill in the gaps Management Sysadmin Network engineer User admin user Software Developers CSIRT Law& regulation Incident respons Transits Systems management Forensics Monitoring and logging Software development NA Sec. SW dev.

Participate in WISE www.wise-community.org Interested in any of the the working group subjects? Contact the workgoup chair and let’s work together Subscribe to the workgroup mailinglist on the WISE website Submit your training ideas to the inventory page or send an e-mail to the list or to alf.moens@surfnet.nl Details on the wiki page: https://wiki.geant.org/display/WISE/STAA-WG www.wise-community.org

Workshop March 28th Finalise a list of target groups Finalise list of training and awareness subjects Draw up outline of security training and awareness training plan (high level plan) Draw up a training matrix: what is available/recommended? Where are the gaps? Where should be priorities? We will need representatives from different e-infrastructures in the workshop tommorrow