“Consorzio RES and IT Security Certifications” 1/22.

Slides:



Advertisements
Similar presentations
New Eligibility and Individualized Educational Program (IEP) Forms 2007 Illinois State Board of Education June 2007.
Advertisements

Technical skills and competences
ENTITIES FOR A UN SYSTEM EVALUATION FRAMEWORK 17th MEETING OF SENIOR FELLOWSHIP OFFICERS OF THE UNITED NATIONS SYSTEM AND HOST COUNTRY AGENCIES BY DAVIDE.
Roadmap for Sourcing Decision Review Board (DRB)
Performance management guidance
Accreditation 1. Purpose of the Module - To create knowledge and understanding on accreditation system - To build capacity of National Governments/ focal.
Effective Design of Trusted Information Systems Luděk Novák,
IAEA International Atomic Energy Agency Responsibility for Radiation Safety Day 8 – Lecture 4.
Part 1 Background Part 2 The RISAS Board Accreditation Agency RISABs Suppliers IT Application Scheme Administrator Documentation RISAS001/01 RISAS002/01.
Welcome! Internal Auditing CHAPTER 1. Definition Internal auditing is an independent, objective, assurance and consulting activity designed to add value.
CBR Faculty Fellows Program Presented by: Brenda Marsteller Kowalewski September 16, 2009.
CSCU 411 Software Engineering Chapter 2 Introduction to Software Engineering Management.
EFFECTIVE DELEGATION AND SUPERVISION
Dr. Julian Lo Consulting Director ITIL v3 Expert
Security Controls – What Works
UGDIE PROJECT MEETING Bled September WP6 – Assessment and Evaluation Evaluation Planning  Draft Evaluation plan.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
1 Conformity Assessment Schemes Presented by Andrew Kwan ITU Consultant Conformity and Interoperability Training for ARB Region on Type Approval Testing.
ISO 9001 Interpretation : Exclusions
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Purpose of the Standards
ZHRC/HTI Financial Management Training
Fraud Prevention and Risk Management
Customs broker. Definition Customs generally deals with the importation or exportation of goods into or out of a country. Customs brokers or brokerages.
GLOBAL REGULATORY STRATEGY CONSIDERATIONS SCIENTIFIC SARAH POWELL EXECUTIVE DIRECTOR, REGULATORY STRATEGIES SEPTEMBER 14-17, 2008 BOSTON, MA.
Internal Auditing and Outsourcing
Continuation From Chapter From Chapter 1
1st MODINIS workshop Identity management in eGovernment Frank Robben General manager Crossroads Bank for Social Security Strategic advisor Federal Public.
Practical IS security design in accordance with Common Criteria Security and Protection of Information 2005 František VOSEJPKA S.ICZ a.s. June 5, 2005.
Slide 1 D2.TCS.CL5.04. Subject Elements This unit comprises five Elements: 1.Define the need for tourism product research 2.Develop the research to be.
PwC Internal Control Reports: Facts, Myths and Best Practices FIRMA National Risk Management Training Conference – San Francisco, CA Wednesday March 31,
Entrepreneurship & Small Business Management 10/2/
Setting up an Internal Audit Program By
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
ETICS2 All Hands Meeting VEGA GmbH INFSOM-RI Uwe Mueller-Wilm Palermo, Oct ETICS Service Management Framework Business Objectives and “Best.
Grant Writing 101 Information and Tips for Preparing and Submitting an Application Debbie Kalnasy Bryan Williams Office of Safe and Drug-Free School s.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
FAR Part 10 Market Research. FAR Part 10 - Prescribes policies and procedures for conducting Market Research.
Prime Responsibility for Radiation Safety
Welcome to Session 3 – Project Management Process Overview
Programme Objectives Analyze the main components of a competency-based qualification system (e.g., Singapore Workforce Skills) Analyze the process and.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
SUPERVISION FRAMEWORK FOR CLEARING AND SETTLEMENT SYSTEMS: MAIN ELEMENTS AND SOME ISSUES TO INCLUDE IN THE OVERSIGHT OF THE SYSTEMS Global Payments Week.
Session Objectives Analyze the key components and process of PBL Evaluate the potential benefits and limitations of using PBL Prepare a draft plan for.
FINAL PRESENTATION OF ORGANIZATIONAL BEHAVIOUR AND ANALYSIS Prepared for : Dr. S. Kumar Group : Dollar 2 A. R. S. BANDARA - PGIA / 06 / 6317 B. A. G. K.
IAEA International Atomic Energy Agency Methodology and Responsibilities for Periodic Safety Review for Research Reactors William Kennedy Research Reactor.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
SAM-101 Standards and Evaluation. SAM-102 On security evaluations Users of secure systems need assurance that products they use are secure Users can:
Sales & Marketing Do’s & Don’ts For The Entrepreneur CINA October 30, 2004.
ISO 9001:2015 Subject: Quality Management System Clause 8 - Operation
WORKSHOP ON ACCREDITATION OF BODIES CERTIFYING MEDICAL DEVICES INT MARKET TOPIC 9 CH 8 ISO MEASUREMENT, ANALYSIS AND IMPROVEMENT INTERNAL AUDITS.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
BIMILACI 2007 Partners for Quality Infrastructure: The FIDIC Vision Washington, May 10, 2007 Dr. Jorge Díaz Padilla FIDIC President.
Differences between customs brokers and customs carriers Differences between customs brokers and customs carriers Baku, April 8, 2016 TAIEX Workshop on.
Overview of Financial Planning By: Associate Professor Dr. GholamReza Zandi
Technology Services – National Institute of Standards and Technology Conformity Assessment ANSI-HSSP Workshop Emergency Communications December 2, 2004.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
H-CARE: “Launching of Sector Skills Alliance for Training & Apprenticeship of Health Care and Food Supplements Salespersons” LLP TR-LEONARDO-LMP.
Software Engineering Process - II 7.1 Unit 7: Quality Management Software Engineering Process - II.
Internal Audit: panacea or distraction? Philip Ratcliffe President 29 January 2009 Managing Partners’ Forum for risk management professionals.
CMMI Certification - By Global Certification Consultancy.
EFFECTIVE DELEGATION AND SUPERVISION
Chapter 8 Outcome Identification and Planning Fundamentals of Nursing: Standards & Practices, 2E.
 Planning an audit of cost statements, records and other related documents is considered necessary to ensure achievement of audit objectives with available.
SIMONA MURRONI Bruxelles - June 27th 2013 Bridging lessons learned from the past with new planning and delivery approaches in the energy sector.
ISO Certification Consultancy Information regarding various International management systems and certification consultancy offered by Punyam Management.
Emulsion Task Force Meeting
Taking the STANDARDS Seriously
Roles and Responsibilities
Presentation transcript:

“Consorzio RES and IT Security Certifications” 1/22

the Consorzio RES operates as Consorzio RES originates in 1997 in response to the ICT market growing needs in the framework of security processing and maintenance of electronic data Security Evaluation Laboratory (LVS) qualified by the OCSI (ISTICOM) Evaluation Centre (CE.VA.) qualified by ANS (the Italian National Security Authority) Global Consultant in the physical, organizational and ICT security 2/22

Scheme managed by OCSI, the certification body for security Evaluation an Certification of commercial systems and products (DPCM of the 30/10/2003) Scheme managed by ANS, the certification body for security Evaluation and Certification of systems and products dealing with classified information concerning the National Security (DPCM of the 11/04/2002) Consorzio RES is a laboratory qualified to perform Security Evaluation Processes according to the following National Schemes What is an Evaluation Process ? 3/22

An Evaluation Process is part of a Certification Process and has the purpose to produce a Final Evaluation Report. On the base of this report the Certification Body produces the Certification Report and, eventually, the Certificate So, the target seems to be achieving the Security Certificate …and this target MUST be achieved… in a while with money savings at high assurance level 4/22

… these are Customers usual requests! ? ! 5/22

6/22 Our approach punctually answers to the main problems of the ones who are disposed to engage a certification process Consequently Consorzio RES has consolidate an operative metodology with certain benefits for the Customers Experience taught us to respect the Customers needs

Why certify What certify How much spend … and the presumptions of our Customers are… 7/22

Why certify It is necessary to sell our product… Our direct competitor has just achieved the security certificate for his product… We have some left-over money in our project… 49% 2% 8/22

All We don’t know… 50% What certify 9/22

Few money We have this available amount…do what you can! 50% How much spend 10/22

Consorzio RES intervention, since the Certification is only an hypothesis, allows the Customers to resolve to their advantage the previous problems Analysis of these needs has driven the Consorzio RES in the development of a working metodology that attends the Customers since before the Evaluation Process start-up Followed approach answers to the Customers needs though respecting all procedures of the reference scheme as well as used security standard for the system/product evaluation 11/22

Why certify Since before the starting of Evaluation Process, Consorzio RES cooperates with the Customers in a clear definition of : So that data requiring protection can be managed in a security context appropriate to real environment “ ” Real security needs Most suitable operating environment Strictly necessary countermeasures 12/22

What certify Only the components (HW/SW) that, implementing Security, are effectively contrasting the supposed threats “ ” One of the major activities of Consorzio RES is to support Customers to clearly mark off the boundaries of : Target of Evaluation Everything else Operating environment items 13/22

How much spend The bare minimum after having correctly answered to the questions: Why certify? What certify? ” “ 14/22

It is frequent that Security Problem ambiguities are transposed in a cautionary extention of the boundaries of Target of Evaluation and its Operating Environment, as well as in the definition of Security Procedures onerous for the workaday users operations Confusion about true Security Objectives Certification time increasing Certification cost increasing Rules/Standards Modifications HW/SW Obsolescence 15/22

Evaluation Assistance Phase Evaluation Preparation Phase Evaluation Phase Certificate Emission certification Evaluation Starting Evaluation Ending Consorzio RES Intervention Areas 16/22

Critical Success Factors (1/2) Evaluation Assistance Phase Evaluation Phase Evaluation Preparation Phase certification 17/22

Evaluation Preparation Phase Identification of Security Aspects strictly related to the Security Problem Evaluation Assistance Phase Very well written evaluation documents compliant with referential Security Standard Critical Success Factors (2/2) 18/22 Paying attention to these Critical Success Factors remarkably reduces the risk to cumulate considerable delays during a certification process, in behalf of costs and operatives engagements for system/product under certification

Evaluation Assistance Phase Evaluation Preparation Phase Evaluation Phase Turn key solutions Consorzio RES is able to offer all these services during a same certification process, having the availability of highly qualified personnel in a sufficient number to guarantee the independency expected by national scheme 19/22

Every human resource of Consorzio-RES is also qualified, by both certification bodies, for the respective schemes, to hold the Evaluator role during the evaluation process Common Criteria v.3.1 (ISO/IEC 15408) Every human resource of Consorzio RES is skilled according to the most recent security standard, recognized by an international board: 20/22

the Customers trust has allowed us to achieve primacy goals First Italian LVS to have completed an evaluation process according to the National Scheme managed by OCSI First Italian laboratory to have completed several Common Criteria evaluation processes according to the National Scheme managed by Italian National Security Agency First Italian LVS to obtain required qualification to carry out products/systems or protection profiles evaluation process according to the National Scheme managed by OCSI...all unavoidable results of the care and the skills by which “Consorzio RES” answers to the Customers needs 21/22

Other information on: Contact: 22/22