EISAS Pilot Collaborative Awareness Information Dissemination to EU Citizens & SMEs 1
o Romain Bourgue o Network Information Security Expert at ENISA o Project Manager for EISAS 2012 – Large scale pilot o ENISA: European Network and Information Security Agency o EU Cyber Security Agency o Securing Europe's Information Society 2
o The EISAS Project? o EISAS in 2012 – Large scale pilot o EISAS in 2013 Agenda 3
o The EISAS Project? o C l o s i n g the gaps! o Collaborative approach for awareness raising o EISAS Background, target and actors o EISAS in 2012 – Large scale pilot o EISAS in 2013 Agenda 4
Citizens and SMEs are not equally empowered with information to protect themselves against cyber threats Most of awareness raising campaigns are limited to a country or to a company Global cyber threats calls for global awareness We need pan-European and collaborative Awareness Raising actions! In 2006, European Commission introduced the idea of European Information Sharing and Alert System The EISAS project Closing the gaps! 5
o EISAS is actively motivated by European Commission o ENISA is working since 2006 on EISAS o 2007: Feasibility study for EISAS o 2010: Roadmap for EISAS o 2011: First Pilot in one Member State 2012: Large scale Pilot in several Member States o 2013: EISAS deployed in EU The EISAS project Background, goals and actors 6
The initial goals of EISAS are to: empower all EU citizens and SMEs with the knowledge and skills necessary to protect their IT systems and information assets build on national capabilities of EU Member States and, enhance cooperation between national/governmental CERTs* in the EU Member States o CERT: Computer Emergency Response Team * or other entities involved in Awareness raising The EISAS project Background, goals and actors 7
The EISAS project A collaborative approach for AR 8 Information Gathering Information Processing Information Dissemination
o The EISAS Project? o EISAS in 2012 – Large scale pilot o Step1: Gathering o Step2: Processing o Step3: Disseminating o Pilot early Outcomes o EISAS in 2013 Agenda 9
EISAS in 2012 – Large scale pilot Step 1: Gathering 10 o 3 key topics addressed: o Social engineering o Identity theft o Home protection against botnets o 3 materials gathered Information Gathering
EISAS in 2012 – Large scale pilot Step 1: Gathering 11 o Botnet web guide for home users o Used in the previous pilot of EISAS Information Gathering
EISAS in Large scale pilot Step 1: Gathering 12 o ID Theft Quiz o Self assessment quiz and guide on ID Theft o NorSIS – Material and source code released under Creative Common licence Information Gathering
EISAS in Large scale pilot Step 1: Gathering 13 o “Bluff” Interactive movie on social engineering o Courtesy of Deutsche Telekom Information Gathering
EISAS in Large scale pilot Step 2: Information processing 14 o Partnership with dissemination actors o CesiCat, CertHU, CertPL, NorSIS, La Caixa o Information brokering between actors o Tailoring the information to the target and the channels (translation, adaptation to channels) o Long and costly process Information Processing
o Publishing, advertising on social media and mailing list (employees) 15 EISAS in Large scale pilot Step 3: Information dissemination Information Dissemination
o Advertising more, gathering statistics and feedbacks 16 EISAS in Large scale pilot Step 3: Information dissemination Information Dissemination
o The goal of the pilot is reached: 6 different entities in 4 MS are collaborating in a joint awareness raising campaign o Coordination and Information brokering between pilot actors is crucial for success o Good materials are hard to find but helps partnership o Not all the actors have the same motivation o More to come… EISAS in Large scale pilot Early outcomes 17
o The EISAS Project? o EISAS in 2012 – Large scale pilot o EISAS in 2013 Agenda 18
o EISAS is to be run by CERTs and other communities o EISAS actors have to be motivated and endorse the coordination role o NISHA will provide an efficient platform for collaboration and dissemination o ENISA will keep working closely with NISHA and the communities involved in EISAS EISAS in
o Stay tuned! o Contact: Any questions? 20
21