1 2003-05-19 Experiences from establishing a national Centre for Information Security in Norway TERENA Networking Conference 2003 Maria Bartnes Dahl &

Slides:



Advertisements
Similar presentations
National Infrastructure Security Co-ordination Centre
Advertisements

A safe and robust society – where everyone takes responsibility Norways internal analysis of laws pursuant to IDRL Guidelines Dag Olav Høgvold
Steps towards E-Government in Syria
Computer Emergency Response Teams
Tanzania Communications Regulatory Authority - TCRA Response to Cyber incidences in Tanzania: Where are we? Presented at Cyber Security Mini Conference.
Sociedade Portuguesa de Inovação ChinaFrontier: China’s Realities from a Frontier Research Perspective Overall Objectives of the Project and a Summary.
Jinhyun CHO Senior Researcher Korea Internet and Security Agency.
FACILITY SAFETY: Creating a Safe and Secure Environment in the Community Health Center Presented by Steve Wilder, BA, CHSP, STS Sorensen, Wilder & Associates.
A Framework to Implement a National Cyber Security Structure for Developing Nations ID Ellefsen - SH von Solms - Academy.
DHS, National Cyber Security Division Overview
MINISTRY OF NATIONAL DEFENCE REPUBLIC OF POLAND CLASSIFIED INFORMATION PROTECTION DEPARTMENT COL. PIOTR GRZYBOWSKI, Director, Classified Information Protection.
1 Case Study ESTABLISHING NATIONAL CERT By Saleem Al-Balooshi Etisalat - AE.
Strategy and Policy Unit: Current Activities and Future Tasks
Geneva, Switzerland, September 2014 Overview of Kenya’s Cybersecurity Framework Michael K. Katundu Director, Information Technology Communications.
Inter-Agency Crisis Management,28 June 2012 Inter-Agency Crisis Management in the Netherlands.
Building Public Health / Clinical Health Information Exchanges: The Minnesota Experience Marty LaVenture, MPH, PhD Director, Center for Health Informatics.
1 ENISA’s contribution to the development of Network and Information Security within the Community By Andrea PIROTTI Executive Director ENISA Cyprus, 28.
Peter Burnett Head of Information Sharing National Infrastructure Security Co-ordination Centre.
ICT 1 Towards an Integrated Approach to Access Control to Health Information Presented by: Inger Anne Tøndel SINTEF Co-authors: Per Håkon Meland SINTEF.
Information Literacy in the workplace: implications for trainers By Dr. Mark Hepworth Department of Information Science Loughborough University.
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
October 27, 2005 Contra Costa Operational Area Homeland Security Strategic and Tactical Planning and Hazardous Materials Response Assessment Project Overview.
IT Internal Audit Survey Overview of survey findings May 2009 IT ADVISORY ADVISORY.
Japanese Government’s Efforts to Address Information Security Issues October, 2007 National Information Security Center (NISC)
Resources to Support Training Programs for CSIRTs.
A General Overview of Information Security Senior advisor Mona Naomi Lintvedt
Internet Based Distance Education at the HAS Bratislava, February, 7th-9th
1 1 The improvement of HR management by using Lean UNECE, Budapest, September 6th 2012 Jan Byfuglien & Anne S. Trolie Statistics Norway. Division for human.
Development through Innovation in Science, Technology and Engineering Dr. Bahawodin Baha University of Brighton, UK. August 10, 2009.
Singapore: Benefits from Secure Clouds
Recognition: the national centre and the ENIC Network Seminar on the recognition of qualifications Baku, 22 April 2005 Gunnar Vaht Head of the Estonian.
Australia Cybercrime Capacity Building Conference April 2010 Brunei Darussalam Ms Marcella Hawkes Director, Cyber Security Policy Australian Government.
Towards a European network for digital preservation Ideas for a proposal Mariella Guercio, University of Urbino.
The NIGF CONFERENCE © 2013 ADDRESSING THE VULNERABILITY OF CRITICAL ICT INFRASTRUCTURE by Ernest Ndukwe, OFR Chairman Openmedia Communications Ltd 18 th.
ICT/ICM Status in Jordan Hesham Athamneh & Jordan Team.
2011 East African Internet Governance Forum (EA – IGF) Rwanda Cyber briefing: Positive steps and challenges Didier Nkurikiyimfura IT Security Division.
1 Free Help: State Support Team Technical Assistance Services 2012 MIS Conference February 15, 2012 Corey Chatis, State Support Team Jan Petro, CO Department.
A presentation of The Association of the Pharmaceutical Industry in Norway (LMI)
The World Summit on the Information Society by Eun-Ju Kim, Ph.D. Senior Advisor for Asia and the Pacific UPDATES: March 11, 2002.
InfraGard A Government and Private Sector Alliance Information sharing begins with human relationships – people talking with people whom they trust. Information.
Emergency Management Training and Education System Protection and National Preparedness National Preparedness Directorate National Training and Education.
A Global Approach to Protecting the Global Critical Infrastructure Dr. Stephen D. Bryen.
Regional Collaboration between Companies and the University Catania 20 April 2007 Toril Eikaas Eide, Centre for Continuing Education (SEVU)
How we work as a national CERT in China ZHOU Yonglin CNCERT/CC, China 2 Addressing security challenges on a global scaleGeneva, 6-7 December 2010.
IT Security Policies and Campus Networks The dilemma of translating good security policies to practical campus networking Sara McAneney IT Security Officer.
DEFENCE POLICY AND PLANNING DIVISION
Risk and Safety in the Transport Sector (RISIT) - a research programme covering road-, sea-, air- and the railway sector Finn H. Amundsen, Head of programme.
Regional Collaboration between Companies and the University Belfast 2 April 2007 Toril Eikaas Eide, Centre for Continuing Education (SEVU)
Alun JONES EU Network Manager European Agency for Safety and Health at Work 6 th Framework Programme on Research.
1 CREATING AND MANAGING CERT. 2 Internet Wonderful and Terrible “The wonderful thing about the Internet is that you’re connected to everyone else. The.
15 April Partnership for Entrepreneurship Education 15 April 2011, Dublin Castle Trine Fuglsang, The Danish Enterprise and Construction Authority.
CNCI-SCRM STANDARDIZATION Discussion Globalization Task Force OASD-NII / DoD CIO Unclassified / FOUO.
DG CONNECT NIPS Study – CONSULTATION CONFERENCE 13 November 2013
Joint Information Systems Committee Supporting Higher and Further Education Continuing Access and Digital Preservation: the JISC Strategy Neil Beagrie.
Guro Andersen Senior adviser, information Dept. of Local and Regional Risk Management Directorate for Civil Protection and Emergency Planning National.
European collaboration on research networking development update on TERENA activities Karel Vietsch TERENA CEO Spring 2002 Internet2 Member Meeting Arlington.
Information and Network security: Lithuania Tomas Lamanauskas Deputy Director Communications Regulatory Authority (RRT) Republic of Lithuania; ENISA Liaison.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
DoD Lead Agent: Office of the Assistant Secretary of the Army (Installations and Environment) Department of Defense Voluntary Protection Programs Center.
Department of Education and CultureOrganization of American States Culture in Development: An Inter-American Information Network Project Description and.
Rannís Erasmus+ Data collection, analysis & impact studies.
Facilitating International Collaboration through New Funding Opportunities Maria Uhle Program Director, International Activities GEO Directorate U.S. National.
Preparation of Drought Vulnerability Assessment Study to Develop Iraq National Framework for Integrated Drought Risk Management (DRM) PAVING THE WAY FOR.
Department of Defense Voluntary Protection Programs Center of Excellence Development, Validation, Implementation and Enhancement for a Voluntary Protection.
Cybersecurity, competence and preparedness
Ken Watson 9 Sep 2003 Critical Infrastructure Assurance: Business Case for Public-Private Partnership Ken Watson 9 Sep 2003
California Cybersecurity Integration Center (Cal-CSIC)
Trust and Security Unit
Social Partners involvement in National OSH Strategies Panel 2
Improving Australia’s Competitive Position
Presentation transcript:

Experiences from establishing a national Centre for Information Security in Norway TERENA Networking Conference 2003 Maria Bartnes Dahl & Lillian Røstad Centre for Information Security SINTEF Telecom and Informatics

Background Two major incidents recent years: –Telenor: Main and backup cable cut at the same time Large areas without telephone connection, >5 hrs –EDB Teamco: One human mistake - all Internet banking services unavailable A whole week until normal operation restored Increased focus on information security –Have realised how vulnerable the society is –Vulnerability Committee and a national strategy

Establishment of SIS (I) Commissioned by the Norwegian Ministry of Trade and Industry Preliminary duration: Apr 1 st Dec 31 st 2004 Part of the national strategy for reducing society’s vulnerability within information and communication (ICT) technology

Establishment of SIS (II) Hosted by SINTEF Telecom and Informatics in collaboration with UNINETT in Trondheim SINTEF: –Foundation for Industrial and Technological Research –Vision: “Technology for a better society” –~2000 employees UNINETT: –The Norwegian Network for Research & Education –Computer Emergency Response Team (CERT)

Why SINTEF? Alternatives: –Governmental departments, directorates –Norw. Defense - Norwegian National Security Authority –Private organisations SINTEF: –Large, independent research institution –Experience within the areas of safety and security –Located close to the Norwegian University of Science and Technology (NTNU) and UNINETT

Main objectives To survey the threats towards ICT systems in Norwegian society Spread knowledge and expertise about threats and their countermeasures Network with organisations providing similar services in other countries

Deliverables Threat assessment: a dynamic updated overview of threats Overview of who delivers security services and products Increase awareness about security in both private and public sectors Establish a network of relevant contacts

Long-term objective To be responsible for the national coordination of tasks within incident response, warning, response of threats and attacks, and exchange of expertise. –In trial period not responsible for security and preparedness in emergency situations

SIS complements existing efforts SIS Society at large NO NSA - National security - Critical societal operations - Key industry Staff: SIS + NO NSA  150 people SIS Degree of protection Extent

Current status Premises approved according to the Norwegian Security Act –Approved for handling classified information Fully staffed as of Jan 1 st 2003: –Seven people –Educated and/or work experienced within information security Web page:

Status - main objectives (I) Threat assessment: –formal agreements –based on reported incidents AND –other surveys and information sources –June first publication Challenge: –Evaluate tools and methods for handling and analyzing incident reports –Produce useful reports - determine what constitutes a useful report based on user demands

Status - main objectives (II) Spread knowledge: –Participation in national and international conferences –Student tutoring – Advisories and articles Best practice Checklists Challenge: –Collect, sort out and communicate publicly available information –Supplement where necessary

Status - main objectives (III) Networking: –Established trust relationships - contact networks in Norway –Nordic meeting fall 2003 –UK - NISCC/UNIRAS Challenge: –Identify and establish relationships with key people within important organisations

Main challenge Determine possible functions, goals and working methods of the centre –Identify main users, and –Figure out what is really needed by the users

Results so far June 2003: –Publication of the first threat assessment Formal agreements - information exchange Map of the security industry in Norway Identified key players - both governmental and commercial

Contact SIS: Maria Bartnes Dahl