Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Official information in – managing the risk of leakage ● Reduce risk via protective markings ● Simplify security for end-users ● Whole of Government approach Neville Jones November 2005
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Concept ● PSM rules for ● Keep ICT Security Simple for users ● make system do the hard stuff ● get more value out of system
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED In the beginning there was...
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Official ● as channel – big – useful ● Risks for Government
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED security difficult for users ● Message path hell ● policy hell ● Users are not routing experts! ● Users are not security experts!
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Message path hell ISP Private Individual (Remote) Officer Wireless (Wireless) Officer firewall Your Agency Officer Private network Partner Agency Officer Internet Partner Agency Corporate Network Officer Fax gateway PSTN
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED security can be simpler ● Let system do the work! ● Enforce policy at components ● Use principles of PSM ● How to put protective markings in s?
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Protective markings for RFC2822 MESSAGE RFC2822 BODY RFC2822 HEADER MIME BODY(s) MIME ATTACHMENT(s) Message-ID: Date: Wed, 230 Nov :28: From: "Jane Doe" User-Agent: Microsoft Outlook X-Accept-Language: en-us, en X-Protective-Marking: [VER=2005.6, NS=gov.au, SEC=UNCLASSIFIED, MIME-Version: 1.0 To: "Smith, John" Subject: Hello World [SEC=UNCLASSIFIED] Content-Type: text/plain; charset=ISO ; format=flowed Content-Transfer-Encoding: 7bit
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Creating the marking
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Real world problem
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Risk management implementation ● client enablement ● Encryption invoked by classification level ● End user doesn't have to click “Encrypt”
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Wide scope of application ● Client side rules ● Gateway flow control ● Gateway encryption/decryption ● Official register ● Archive management ● Web headers
Copyright © 2005 janusNET Pty Ltd UNCLASSIFIED Gateway flow control ● Major area of Government activity ● DSD / ACSI33 & AGIMO ● Sending ● Receiving ● Agency adoption