CCIRN meeting, Cairns, 3 July 2004 Computer security co-operation in Europe Karel Vietsch Based on materials provided by TERENA TF-CSIRT.

Slides:



Advertisements
Similar presentations
1 European Research Networking Development Activities Karel Vietsch TERENA
Advertisements

Clara CSIRTs in Latin America and the Caribbean CCIRN 2004 Cairns, Australia July 2004 Michael Stanton CLARA Technical Committee RNP- Brazil (material.
Content of the Presentation WHY - What are the benefits of Transnational Projects? HOW- LAG taking a proactive approach -Using the existing mechanisms.
TF-PR Overview of the work Maria Ristkok, Bruges, May 2008.
Malta Council for Science and Technology Seventh Framework Programme (FP7) 15 July, 2008 Anthea Frendo FP7 National Contact Point.
Putting Research Evidence to Work Research Seminar 14 th January 2009.
Media Management and Distribution Workshop Next Step… Media Management and Distribution Workshop Zurich, Switzerland January, 2009 Peter Szegedi.
Academic and Research Network of Slovenia 1 The CSIRT initiative Gorazd Božič ARNES SI-CERT, Jamova 39, Ljubljana, Slovenia NATO.
1 Financial education initiatives of the European Commission International Conference on Financial Education Washington, 7-8 May 2008 Daniel Kosicki, European.
TechSec WG: Related activities overview Information and discussion TechSec WG, RIPE-45 May 14, 2003 Yuri Demchenko.
Association for Educational Assessment - Europe Purpose Activities Membership.
Networks ∙ Services ∙ People John DYER TF-MSP Video Conference Community Procurement Support Building on the SPOT-ON Proposal Smart Procurement,
First part: Objectives (15 minutes) Second part: Work groups (20 minutes) Third part: Proposal of work groups (10 minutes) REPORT OF WORK METHODOLOGY.
Welcome to the TC Rainbow Show Brasov, 20 October 2005 European YOUTH Programme.
European Quality in Individualized Pathways in Education.
Giandonato CAGGIANO ENISA MANAGEMENT BOARD REPRESENTATIVE LEGAL ADVISER ON EUROPEAN AFFAIRS OF THE MINISTRY OF COMMUNICATIONS U. OF ROMA TRE LAW FACULTY.
Bratislava October 2007 PAR - AC CoP Meeting Anti Corruption Regional Programme Regional Programme.
1 João Delgado DG Education and Culture Unit B4, Professional training; « Leonardo da Vinci » Strasbourg, 8 July 2010 Mobility for Apprentices Status and.
John Dyer Business & Technology Strategist TERENA 10 February 2014 TF-MSP Meeting ACOnet, Vienna Aggregation of Demand Collaborative.
CEBP Learning Institute Fall 2009 Evaluation Report A collaborative Partnership between Indiana Department of Corrections & Indiana University November.
EMAC – Network and Support of National Contact Points solitander:
Introduction to the Workshop from TERENA Performing Arts Production Workshop July 2009 Trieste, Italy Valentino Cavalli TERENA
1 Women Entrepreneurs in Rural Tourism Evaluation Indicators Bristol, November 2010 RG EVANS ASSOCIATES November 2010.
PARTNER VIEWS AT THE START OF TULIP TULIP evaluator Kari Seppälä Tallin
WOMEN ENTREPRENEURS IN RURAL TOURISM Sustainability Report by PRISMA Centre for Development Studies Parnu, September 2012.
Evaluation Plan New Jobs “How to Get New Jobs? Innovative Guidance and Counselling 2 nd Meeting Liverpool | 3 – 4 February L Research Institute Roula.
European Commission - DG Research - Directorate B – “Structuring the European Research Area” Jean-David MALO – Bucharest, February 12-13, NOT LEGALLY.
IRT Co-ordination in Europe Brian Gilmore The University of Edinburgh.
Jean-Michel Courades, DG AGRI F3 European Rural Development Network
Association for Educational Assessment - Europe Purpose Activities Membership.
ECOLEAD 1 Jermol/JSI © Jermol/JSI Training activities WP7 Mitja Jermol Jozef Stefan Institute (JSI)
TERENA update Karel Vietsch TERENA CEO Internet2 Fall Meeting, Atlanta 30 October 2000.
EUROSAI Professional Standards – Goal Team 2 Brief introduction Cristina Breden Mária Kysucká Vilnius, September 2012.
YOUTH Programme TC Rainbow by JINT vzw. WHY YOUTH ?  Stimulate the mobility of young people  Active participation in the development of Europe and of.
Slide 1 ROAD TO EUROPE – PROGRAM OF ACCOUNTING REPORTING AND INSTITUTIONAL STRENGTHENING How can the European Federation of Accountants (FEE) Assist ?
“The voice of the commercial occupational health and wellbeing providers – influencing policy development, sharing knowledge and best practice, and promoting.
Steinlova Kvetoslava - MARS Rapporteur. UNECE International Seminar on Product Safety and Counterfeiting (2007) Second UNECE Forum on Market Surveillance.
TI Twelve months oldSlide 1 The Trusted Introducer Concept Brian Gilmore (TERENA)
1 CREATING AND MANAGING CERT. 2 Internet Wonderful and Terrible “The wonderful thing about the Internet is that you’re connected to everyone else. The.
Sofia, 09 June Sofia, 09 June 2010 MINISTRY OF TRANSPORT, INFORMATION TECHNOLOGY AND COMMUNICATIONS Executive Agency “Electronic Communication Networks.
G É ANT2 Development Support Activity and the Republic of Moldova 1st RENAM User Conference Chisinau, Republic of Moldova 14-May-2007 Valentino Cavalli.
First ARF Inter-sessional Meeting on non proliferation Beijing, China 1-3 July 2009 First ARF Inter-sessional Meeting on non proliferation Beijing, China.
15 April 2002 Early results from the TERENA Compendium Survey: some things that will get into the Compendium and others that won't... Bert van Pinxteren,
Networks ∙ Services ∙ People GÉANT Community Innovation Programme DISCUSSION 14th October 2015 GÉANT General Assembly.
European collaboration on research networking development update on TERENA activities Karel Vietsch TERENA CEO Spring 2002 Internet2 Member Meeting Arlington.
WSBI (World Savings Banks Institute) The Global Voice of Savings and Retail Banking Miami, 22 May 2012 Miami, 22 May ISIC Event Presentation.
Key things to consider 1) Understanding the wider context 2) Familiarity with ECML resources 3) Familiarity with format of ECML projects 4) The role of.
Finding a trainee position – advice and tips. If you have trouble finding a trainee position Make sure your CV stands out for the right reasons Your CV.
Community of Practice K Lead Project Team: الالتزامالتحفيز التفكير المؤسسي المرونةالتميزالشراكةالاستقامة.
FINAL EVENT Dublin, 01 June 2016 Welcome Françoise de Viron President of eucen.
Clinical Research Facilities supporting Global Health
Building Global CSIRT Capabilities Barbara Laswell, Ph. D
WISE Information Security for Collaborating E-Infrastructures
WISE 2016 WISE: a global trust community where security experts share information and work together, creating collaboration among different e- infrastructures.
A&M Workplan Objectives
The Forum of Incident Response and Security Teams (FIRST)
CSIRT collaboration in Europe
IFOAM organizations Brief overview of IFOAM Organics International, IFOAM EU Group and IFOAM AgriBioMediterraneo.
The Forum of Incident Response and Security Teams (FIRST)
Eurostat D2 – Regional Indicators and Geographical Information
Civil Protection Financial Instrument – Prevention Projects
The European Union response to cyber threats
Computer Security Cooperation in Europe
The European Bioeconomy Network
STRUCTURE AND METHODS OF CO-OPERATION
The Forum of Incident Response and Security Teams (FIRST)
CSIRT collaboration in Europe
Multi-Stakeholder Workshop on the United Nations Convention against Corruption and its Review Mechanism Addis Ababa, 8-11 April 2019 Mirella Dummar Frahi.
Draft Charter Community of Practice for Direct Access Entities
Presentation transcript:

CCIRN meeting, Cairns, 3 July 2004 Computer security co-operation in Europe Karel Vietsch Based on materials provided by TERENA TF-CSIRT

CCIRN meeting, Cairns, 3 July 2004 Agenda Why co-operate? History of co-operation CSIRT Task Force (TF-CSIRT) Benefits: –Contacts –Trends and hot issues Deliverables, including: –Accreditation scheme for CSIRTs –IRT database object –Clearing House for Incident Handling Tools –Training course for new CSIRTs

CCIRN meeting, Cairns, 3 July 2004 Why Co-operate? Security incidents are international –Must work together to solve them No team knows everything –Share knowledge, resources, tools –Compare working practices –Develop best practice & standards –Provide better and faster service

CCIRN meeting, Cairns, 3 July 2004 Historical perspective Pre-1990: CSIRTs in isolation (if at all) During 1990s: FIRST provides binding: –Members meet members –Basic notion of trust –Exchange of operational information –Less powerful in initiating innovation : EuroCERT pilot service: –Top-down approach –Operational work outsourced to third party 2000: TF-CSIRT established

CCIRN meeting, Cairns, 3 July 2004 Influence of NRENs National Research & Education Networks –Traditionally innovative –Low commercial profile Natural “academic” way of working –Achievements based on collaboration –Results shared for society’s benefit –Free dissemination of expertise Since 1986: TERENA (see:

CCIRN meeting, Cairns, 3 July 2004 Creation of TF-CSIRT TERENA Task Force: –Operation defined by Terms of Reference –Two years recurring lifecycle with review –Members and non-members of TERENA –No membership fee, just travel & hotel costs –Active participation by members –Success depends on members’ commitment –TERENA plays role of professional facilitator: Secretarial tasks Logistical support

CCIRN meeting, Cairns, 3 July 2004 TF-CSIRT way of working Meeting every four months Venue rotates among members who volunteer to host Two days: –1st day for seminars and presentations –2nd day for Task Force official meeting Evening in-between: social event organised by the hosting member Contacts between meetings provided by mailing list and project groups

CCIRN meeting, Cairns, 3 July 2004 Who is involved? Academic, Government, Commercial teams 29 countries meeting (3) training (3) both (23)

CCIRN meeting, Cairns, 3 July 2004 Benefits - contacts Operational people talk directly to each other –Trusted contacts for later work Little or no formalities, collaborative atmosphere Ad-hoc subgroups working on concrete deliverables Social event often proves to be a fruitful environment for new ideas

CCIRN meeting, Cairns, 3 July 2004 Benefits – trends and hot issues Supportive peer review of other members’ organisation and operations Members share and consume expertise (a win/win approach) Atmosphere of understanding – no team has to fight common problems alone Discussing trends and hot issues among peers make these trends and hot issues easier to understand and assess

CCIRN meeting, Cairns, 3 July 2004 Wider Co-operation European Commission –Projects (eCSIRT.net, EISPP, TRANSITS) –Legal handbook for CSIRTs –Network & Information Security Agency (ENISA) National governments –Government CSIRTs –Consultation on new legislation Law enforcement –Operations and invited speakers at meetings Other regional initiatives

CCIRN meeting, Cairns, 3 July 2004 Deliverables and Projects Trusted Introducer Service & Directory Incident Object Description & Exchange Format RIPE IRT object Clearing House for Incident Handling Tools CSIRT training course (TRANSITS) Under development Incident Information Exchange (eCSIRT.net) Vulnerability information exchange (EISPP) Assistance to new CSIRTs Incident Handling Procedures

CCIRN meeting, Cairns, 3 July 2004 Deliverables – Trusted Introducer ( Notion of ‘trust’ – is a contact trustworthy? Currently, no scheme generically applicable TF-CSIRT to work out a model of which it believes it fulfills criteria needed at operational level Feasibility and sanity checks Now, outsourced to a third party TF-CSIRT retains control by TI Review Board

CCIRN meeting, Cairns, 3 July 2004 Deliverables – IRT database object Commonly perceived problem: correct points of contact in (RIPE) database Practical approach: –what do we miss now? –how can we design it –how can we implement it? Wishlist followed by discussion in RIPE database group Lots of iterations, but eventually implemented and populated

CCIRN meeting, Cairns, 3 July 2004 Deliverables – CHIHT ( Clearing House for Incident Handling Tools Share information on tools CSIRTs use –Help new and existing teams Website listing tools by category –Evidence gathering & investigation, system recovery, CSIRT operations, remote access, proactive tools –Plan to add procedures and best practice Contents suggested by active CSIRTs

CCIRN meeting, Cairns, 3 July 2004 Deliverables – TRANSITS ( Idea: best transfer of knowledge is from operational people to operational people Conclusion: best people to write it are TF- CSIRT members Two day course developed in modules: –Operational, legal, technical, organisational, vulnerabilities EC funding for delivery and updating –Six presentations over three years –Materials available to members for own use

CCIRN meeting, Cairns, 3 July 2004 Deliverables – TRANSITS (