Securing Critical Internet Infrastructure

Size: px
Start display at page:

Download "Securing Critical Internet Infrastructure"

Transcription

1 Securing Critical Internet Infrastructure Albert Daniels ICANN Manager for Stakeholder Engagement - Caribbean

2 Agenda Recent trends in Cybersecurity in the Caribbean o Mechanics of Breaches o Latin America and Caribbean Targets o Best Practice Recommendations DNSSEC and Securing Critical Internet Infrastructure

3 Latin American and Caribbean Cyber Security Trends (Published June 2014) OAS Symantec AMERIPOL APWG ICANN LACNIC Microsoft

4 2013 was the year of the Mega Breach Proliferation of financially motivated cyber breaches Many breaches in Latin America and the Caribbean to gain access to sensitive data A 62% rise from 2012 Eight of these exposed more than 10 million identities each Imposing significant expenditure of time and financial resources for response, recovery and added protection

5

6

7

8 Best Practice Guidelines for Enterprise (1) Employ defense-in-depth strategies Monitor for network incursion attempts, vulnerabilities, and brand abuse Antivirus on endpoints is not enough Secure your websites against Man in The Middle attacks and malware infection Protect your private keys Use encryption to protect sensitive data

9 Best Practice Guidelines for Enterprise (2) Ensure all devices allowed on company networks have adequate security protections Implement removable media policy Be aggressive in your updating and patching Enforce an effective password policy Ensure regular backups are available Restrict attachments Ensure that you have infection and incident response procedures in place Educate users on basic security protocols

10 Country Specific Reports - Caribbean Details on National Situation Antigua & Barbuda Barbados Belize Dominica Dominican Republic Grenada Guyana Haiti Jamaica St. Kitts & Nevis St. Vincent & the Grenadines Suriname Trinidad and Tobago

11 Why DNSSEC?

12 DNS Basics DNS converts names ( to numbers ( )..to identify services such as www and ..that identify and link customers to business and visa versa

13 om VoIP DNS is a part of all IT ecosystems US-NSTIC effort OECS ID effort Smart Electrical Grid mydomainname.

14 Where DNSSEC fits in..but CPU and bandwidth advances make legacy DNS vulnerable to MITM attacks DNS Security Extensions (DNSSEC) introduces digital signatures into DNS to cryptographically protect contents With DNSSEC fully deployed a business can be sure a customer gets un-modified data (and visa versa)

15 The Bad: DNSChanger - Biggest Cybercriminal Takedown in History 4M machines, 100 countries, $14M Nov

16 The Internet s Phone Book - Domain Name System (DNS) Get page Login page Username / Password Account Data DNS Resolver ISP = DNS Server webserver Majorbank (Registrant) DNS Hierarchy root se com majorbank.se

17 Caching Responses for Efficiency Get page Login page Username / Password Account Data DNS Resolver = DNS Server webserver

18 The Problem: DNS Cache Poisoning Attack Get page Login page Username / Password Error DNS Resolver = DNS Server Attacker = Attacker webserver Password database

19 Argghh! Now all ISP customers get sent to attacker DNS Resolver = DNS Server Get page Login page Username / Password Error Attacker webserver Password database

20 Securing The Phone Book - DNS Security Extensions (DNSSEC) Get page Login page Username / Password Account Data DNS Resolver with DNSSEC Attacker s record does not validate drop it = DNS Server with Attacker DNSSEC = webserver

21 The Business Case for DNSSEC Cyber security is becoming a greater concern to enterprises, government, and end users. DNSSEC is a key tool and differentiator. DNSSEC is the biggest security upgrade to Internet infrastructure in over 20 years. It is a platform for new security applications (for those that see the opportunity). DNSSEC infrastructure deployment has been brisk but requires expertise. Getting ahead of the curve is a competitive advantage.

22 DNSSEC - Where we are Deployed on 462/654 TLDs (29 July %.com.hr.es.in.af.ee.lb.bg.tm.cz.nl.uk.de.jp.cn.ru.рф.my مليسيا.asia.tw 台灣,.kr 한국.net,.org,.post, +gtlds) Root signed** and audited > 86% of domain names could have DNSSEC Required in new gtlds. Basic support by ICANN registrars Growing ISP support*. 3 rd party signing solutions*** Growing S/W H/W support: NLNetLabs, ISC, Microsoft, PowerDNS, Secure64? openssl, postfix, XMPP, mozilla: early DANE support IETF standard on DNSSEC SSL certificates (RFC6698) Growing support from major players (Apple iphone/ipad, Google , ) * COMCAST /w 20M and others; most ISPs in SE,CZ. AND ~12% of resolvers validate using DNSSEC **Int l bottom-up trust model /w 21 TCRs from: TT, BF, RU, CN, US, SE, NL, UG, BR, Benin, PT, NP, Mauritius, CZ, CA, JP, UK, NZ *** Partial list of registrars:

23 DNSSEC: So what s the problem? Not enough IT departments know about it or are too busy putting out other security fires. When they do look into it they hear old stories of FUD and lack of turnkey solutions. Registrars*/DNS providers see no demand leading to chicken-and-egg problems. *but required by new ICANN registrar agreement

24 What you can do For Organizations / Companies: o Sign your corporate domain names o Just turn on validation on corporate DNS resolvers For Users: o Ask ISP to turn on validation on their DNS resolvers For All: o Take advantage of ICANN, ISOC and other organizations offering DNSSEC education and training

25 Game changing Internet Core Infrastructure Upgrade More has happened here today than meets the eye. An infrastructure has been created for a hierarchical security system, which can be purposed and re purposed in a number of different ways... Vint Cerf (June 2010)

26 Too many CAs. Which one can we trust? DNSSEC to the rescue. CA Certificate roots ~1482 DNSSEC root - 1 Content security Commercial SSL Certificates for Web and DANE and other yet to be discovered security innovations, enhancements, and synergies Content security Free SSL certificates for Web and and trust agility Network security IPSECKEY RFC4025 Securing VoIP Domain Names Crossorganizational and trans-national identity and authentication security DKIM RFC4871 Login security SSHFP RFC

27 ICANN DNSSEC Multi-stakeholder, bottom-up trust model* /w 21 crypto officers from around the world Broadcast Key Ceremonies and public docs SysTrust audited FIPS level 4 HSMs Root DPS DNSSEC Practice Statement *Managed by technical community+icann

28 98/ Photos: Kim Davies

29 Photos: Kim Davies

30 DNSSEC: Internet infrastructure upgrade to help address today s needs and create tomorrow s opportunity.

31 Securing Critical Internet Infrastructure Albert Daniels ICANN Manager for Stakeholder Engagement - Caribbean

DNSSEC and Business Case Study

DNSSEC and Business Case Study The Business Case for DNSSEC DNS Basics DNS converts names (www.bot.tz) to numbers (208.112.30.18)..to iden=fy services such as www and e- mail..that iden=fy and link customers to business and visa versa

More information

DNSSEC Deployment: Where We Are (and where we need to be) MENOG 10, Dubai 30 April 2012 richard.lamb@icann.org

DNSSEC Deployment: Where We Are (and where we need to be) MENOG 10, Dubai 30 April 2012 richard.lamb@icann.org DNSSEC Deployment: Where We Are (and where we need to be) MENOG 10, Dubai 30 April 2012 richard.lamb@icann.org DNSSEC: We have passed the point of no return Fast pace of deployment at the TLD level Stable

More information

Strengthening our Ecosystem through Stakeholder Collaboration. Jia-Rong Low, Sr Director, Asia 20 August 2015

Strengthening our Ecosystem through Stakeholder Collaboration. Jia-Rong Low, Sr Director, Asia 20 August 2015 Strengthening our Ecosystem through Stakeholder Collaboration Jia-Rong Low, Sr Director, Asia 20 August 2015 Agenda 1 2 3 About ICANN and the Domain Name System (DNS) DNS attacks and their impact DNS Security

More information

Before the. Committee on Energy and Commerce Subcommittee on Communications and Technology United States House of Representatives

Before the. Committee on Energy and Commerce Subcommittee on Communications and Technology United States House of Representatives Testimony of Fiona M. Alexander Associate Administrator, Office of International Affairs National Telecommunications and Information Administration United States Department of Commerce Before the Committee

More information

Fig 1.1: GDP at Constant 2006 Prices: 2011

Fig 1.1: GDP at Constant 2006 Prices: 2011 1 2 Fig 1.1: GDP at Constant 2006 Prices: 2011 Trinidad and Tobago 36.7% Suriname 6.4% Jamaica 19.9% Guyana 3.2% Barbados 7.2% Belize 2.7% Antigua & Barbuda Other 8.5% The Bahamas 15.3% 2.0% Grenada 1.4%

More information

CDM Loan Scheme DNA Help Desk CDM Help Desk

CDM Loan Scheme DNA Help Desk CDM Help Desk CDM Loan Scheme DNA Help Desk CDM Help Desk Regional DNA Training for Latin America and the Caribbean Best Western Belize Biltmore Plaza Hotel Belize City, Belize 23 October 2012 Fatima-Zahra Taibi, Programme

More information

DNSSEC: Where We Are (and how we get to where we want to be) APNIC 34, Phnom Penh, Cambodia 21-31 August 2012 richard.lamb@icann.

DNSSEC: Where We Are (and how we get to where we want to be) APNIC 34, Phnom Penh, Cambodia 21-31 August 2012 richard.lamb@icann. DNSSEC: Where We Are (and how we get to where we want to be) APNIC 34, Phnom Penh, Cambodia 21-31 August 2012 richard.lamb@icann.org DNSSEC: We have passed the point of no return Fast pace of deployment

More information

DNSSEC - Why Network Operators Should Care And How To Accelerate Deployment

DNSSEC - Why Network Operators Should Care And How To Accelerate Deployment DNSSEC - Why Network Operators Should Care And How To Accelerate Deployment Dan York, CISSP Senior Content Strategist, Internet Society Eurasia Network Operators' Group (ENOG) 4 Moscow, Russia October

More information

DNS Security FAQ for Registrants

DNS Security FAQ for Registrants DNS Security FAQ for Registrants DNSSEC has been developed to provide authentication and integrity to the Domain Name System (DNS). The introduction of DNSSEC to.nz will improve the security posture of

More information

SAC075: SSAC Comments to ITU-D on Establishing New Certification Authorities

SAC075: SSAC Comments to ITU-D on Establishing New Certification Authorities 03 December 2015 Subject: SAC075: SSAC Comments to ITU-D on Establishing New Certification Authorities The Internet Corporation for Assigned Names and Numbers (ICANN) Security and Stability Advisory Committee

More information

REGISTRATION POLICY Version 1.1 5/2/2016. Summary

REGISTRATION POLICY Version 1.1 5/2/2016. Summary REGISTRATION POLICY Version 1.1 5/2/2016 Summary This Registration Policy, to be read together with the Registration Agreement and the.hoteles Registry Policies, sets forth the criteria which all Applicants,

More information

Thierry Tressel Lead Economist, Research Group, World Bank 2015 High Level Caribbean Forum, Sept. 3-4 2015, St. Kitts

Thierry Tressel Lead Economist, Research Group, World Bank 2015 High Level Caribbean Forum, Sept. 3-4 2015, St. Kitts Thierry Tressel Lead Economist, Research Group, World Bank 215 High Level Caribbean Forum, Sept. 3-4 215, St. Kitts Policy issue Focus on SMEs: they are the biggest contributors to employment across countries,

More information

DNSSEC Explained. Marrakech, Morocco June 28, 2006

DNSSEC Explained. Marrakech, Morocco June 28, 2006 DNSSEC Explained Marrakech, Morocco June 28, 2006 Ram Mohan rmohan@afilias.info Agenda Getting Started Finding out what DNS does for you What Can Go Wrong A Survival Guide to DNSSEC Why Techies Created

More information

WHITE PAPER. Best Practices DNSSEC Zone Management on the Infoblox Grid

WHITE PAPER. Best Practices DNSSEC Zone Management on the Infoblox Grid WHITE PAPER Best Practices DNSSEC Zone Management on the Infoblox Grid What Is DNSSEC, and What Problem Does It Solve? DNSSEC is a suite of Request for Comments (RFC) compliant specifications developed

More information

DNS Cache Poisoning Vulnerability Explanation and Remedies Viareggio, Italy October 2008

DNS Cache Poisoning Vulnerability Explanation and Remedies Viareggio, Italy October 2008 DNS Cache Poisoning Vulnerability Explanation and Remedies Viareggio, Italy October 2008 Kim Davies Internet Assigned Numbers Authority Internet Corporation for Assigned Names & Numbers Agenda How do you

More information

FAQ (Frequently Asked Questions)

FAQ (Frequently Asked Questions) FAQ (Frequently Asked Questions) Specific Questions about Afilias Managed DNS What is the Afilias DNS network? How long has Afilias been working within the DNS market? What are the names of the Afilias

More information

Check Point and Security Best Practices. December 2013 Presented by David Rawle

Check Point and Security Best Practices. December 2013 Presented by David Rawle Check Point and Security Best Practices December 2013 Presented by David Rawle Housekeeping o Mobiles on Silent o No File Alarms planned o Fire exits are in front and behind and down the stairs o Downstairs

More information

Consultation on Root Zone KSK Rollover

Consultation on Root Zone KSK Rollover Consultation on Root Zone KSK Rollover 2012-12-14 Consultation Objective The Internet Assigned Numbers Authority (IANA) Functions contract (SA1301---12---CN---0035) between ICANN and the United States

More information

DNS Basics. DNS Basics

DNS Basics. DNS Basics DNS Basics 1 A quick introduction to the Domain Name System (DNS). Shows the basic purpose of DNS, hierarchy of domain names, and an example of how the DNS protocol is used. There are many details of DNS

More information

Introduction to the DANE Protocol

Introduction to the DANE Protocol Introduction to the DANE Protocol ICANN 47 July 17, 2013 Internet Society Deploy360 Programme Providing real-world deployment info for IPv6, DNSSEC, routing and other Internet technologies: Case Studies

More information

Brand Development and Packaging Workshop/Webinar

Brand Development and Packaging Workshop/Webinar Appendix 1: TERMS OF REFERENCE Brand Development and Packaging Workshop/Webinar 1. BACKGROUND INFORMATION 1.1. Beneficiary/Eligible countries CARIFORUM Region: Antigua and Barbuda, The Bahamas, Barbados,

More information

Next Steps In Accelerating DNSSEC Deployment

Next Steps In Accelerating DNSSEC Deployment Next Steps In Accelerating DNSSEC Deployment Dan York, CISSP Senior Content Strategist, Internet Society DNSSEC Deployment Workshop, ICANN 45 Toronto, Canada October 17, 2012 Internet Society Deploy360

More information

A Study of What Really Breaks SSL HITB Amsterdam 2011

A Study of What Really Breaks SSL HITB Amsterdam 2011 A Study of What Really Breaks SSL HITB Amsterdam 2011 v1.0 Ivan Ristic Michael Small 20 May 2011 Agenda 1. State of SSL 2. Quick intro to SSL Labs 3. SSL Configuration Surveys 4. Survey of Actual SSL Usage

More information

Cyber-Security Risk in the Global Organization:

Cyber-Security Risk in the Global Organization: Cyber-Security Risk in the Global Organization: Trends, Challenges and Strategies for Effective Management David Childers, CCEP, CIPP CEO, Compli Todd Carroll Assistant Special Agent in Charge, FBI Three

More information

Security in the Network Infrastructure - DNS, DDoS,, etc.

Security in the Network Infrastructure - DNS, DDoS,, etc. Security in the Network Infrastructure - DNS, DDoS,, etc. GTER, São Paulo December 8, 2006 Steve Crocker, steve@shinkuro.com Russ Mundy, mundy@sparta.com Proactive Security Build security into the infrastructure

More information

TRAINING AND CERTIFICATION PROGRAM FOR DRUG AND VIOLENCE PREVENTION, TREATMENT AND REHABILIATION AND REHABILIATION

TRAINING AND CERTIFICATION PROGRAM FOR DRUG AND VIOLENCE PREVENTION, TREATMENT AND REHABILIATION AND REHABILIATION INTER-AMERICAN DRUG ABUSE CONTROL COMMISSION C I C A D Secretariat for Multidimensional Security FIFTIETH REGULAR SESSION November 2-4, 2011 Buenos Aires, Argentina OEA/Ser.L/XIV.2.50 CICAD/doc.1909/11

More information

Securing DNS Infrastructure Using DNSSEC

Securing DNS Infrastructure Using DNSSEC Securing DNS Infrastructure Using DNSSEC Ram Mohan Executive Vice President, Afilias rmohan@afilias.info February 28, 2009 Agenda Getting Started Finding out what DNS does for you What Can Go Wrong A Survival

More information

Knowledge of language and life in the UK and Islands for settlement and naturalisation Changes to the requirement from October 2013

Knowledge of language and life in the UK and Islands for settlement and naturalisation Changes to the requirement from October 2013 Isle of Man Immigration Office Knowledge of language and life in the UK and Islands for settlement and naturalisation Changes to the requirement from October 2013 Introduction Individuals wishing to apply

More information

Deploying DNSSEC: From End-Customer To Content

Deploying DNSSEC: From End-Customer To Content Deploying DNSSEC: From End-Customer To Content March 28, 2013 www.internetsociety.org Our Panel Moderator: Dan York, Senior Content Strategist, Internet Society Panelists: Sanjeev Gupta, Principal Technical

More information

Supporting Small Island Developing States: Scholarship Program to strengthen capacity in the water sector. Prof. Maria D.

Supporting Small Island Developing States: Scholarship Program to strengthen capacity in the water sector. Prof. Maria D. Supporting Small Island Developing States: Scholarship Program to strengthen capacity in the water sector Prof. Maria D. Kennedy, PhD Launch of SIDS project In August 2015, the Ministry of Foreign Affairs

More information

Internet Security and Resiliency: A Collaborative Effort

Internet Security and Resiliency: A Collaborative Effort Internet Security and Resiliency: A Collaborative Effort Baher Esmat Manager, Regional Relations Middle East MENOG 4 Manama, 9 April 2009 1 WHAT IS THIS PRESENTATION ABOUT? ICANN s effort in enhancing

More information

CARIBBEAN DISASTER EMERGENCY MANAGEMENT AGENCY (CDEMA)

CARIBBEAN DISASTER EMERGENCY MANAGEMENT AGENCY (CDEMA) CARIBBEAN DISASTER EMERGENCY MANAGEMENT AGENCY (CDEMA) The Caribbean Disaster Emergency Management Agency (CDEMA) is a regional inter-governmental agency for disaster management in the Caribbean Community

More information

What is South-South Cooperation?

What is South-South Cooperation? SOUTH-SOUTH COOPERATION South-South Cooperation (SSC) is an effective and efficient means to achieving a world without hunger. Countries of the global south exchanging development solutions will strongly

More information

Some Perspectives On Cybersecurity. Shernon Osepa Manager Regional Affairs Latin America & Caribbean www.internetsociety.org

Some Perspectives On Cybersecurity. Shernon Osepa Manager Regional Affairs Latin America & Caribbean www.internetsociety.org Some Perspectives On Cybersecurity Shernon Osepa Manager Regional Affairs Latin America & Caribbean www.internetsociety.org Agenda What is the Internet Society (ISOC) On the IETF Cyber Security Themes

More information

REQUEST FOR PROPOSAL FOR CAROSAI WEBSITE DEVELOPMENT

REQUEST FOR PROPOSAL FOR CAROSAI WEBSITE DEVELOPMENT REQUEST FOR PROPOSAL FOR CAROSAI WEBSITE DEVELOPMENT PART I BACKGROUND CAROSAI (the Caribbean Organization of Supreme Audit Institutions) is one of nine regional working groups under INTOSAI (the International

More information

Payment Card Industry (PCI) Data Security Standards (DSS) The Prevailing Standard for Digital Transactions

Payment Card Industry (PCI) Data Security Standards (DSS) The Prevailing Standard for Digital Transactions Spring 2010. Payment Card Industry (PCI) Data Security Standards (DSS) The Prevailing Standard for Digital Transactions Gideon Samid Lectures Cryptology and Data Protection INFA640 About A Published and

More information

THE MULTILATERAL INVESTMENT FUND (MIF) CLEAN & EFFICIENT ENERGY: BUSINESS CASES

THE MULTILATERAL INVESTMENT FUND (MIF) CLEAN & EFFICIENT ENERGY: BUSINESS CASES THE MULTILATERAL INVESTMENT FUND (MIF) CLEAN & EFFICIENT ENERGY: BUSINESS CASES JENNIFER BALDWIN Georgetown, Guyana April 18, 2012 1. WHAT IS THE MIF? 2. LESSONS FROM CHILE 3. OPORTUNITIES 4. MIF PROJECTS

More information

DNSSEC Applying cryptography to the Domain Name System

DNSSEC Applying cryptography to the Domain Name System DNSSEC Applying cryptography to the Domain Name System Gijs van den Broek Graduate Intern at SURFnet Overview First half: Introduction to DNS Attacks on DNS Second half: DNSSEC Questions: please ask! DNSSEC

More information

2008 DNS Cache Poisoning Vulnerability Cairo, Egypt November 2008

2008 DNS Cache Poisoning Vulnerability Cairo, Egypt November 2008 2008 DNS Cache Poisoning Vulnerability Cairo, Egypt November 2008 Kim Davies Manager, Root Zone Services Internet Corporation for Assigned Names & Numbers How does the DNS work? A typical DNS query The

More information

CKLN Regional Collaboration & Capacity Building A Summary

CKLN Regional Collaboration & Capacity Building A Summary CKLN Regional Collaboration & Capacity Building A Summary CKLN funded a Regional Collaboration Workshop where stakeholder representatives from the Tertiary Education Community reviewed current initiatives

More information

XN--P1AI (РФ) DNSSEC Policy and Practice Statement

XN--P1AI (РФ) DNSSEC Policy and Practice Statement XN--P1AI (РФ) DNSSEC Policy and Practice Statement XN--P1AI (РФ) DNSSEC Policy and Practice Statement... 1 INTRODUCTION... 2 Overview... 2 Document name and identification... 2 Community and Applicability...

More information

REPORT ON THE MEETINGS CONVENED. Biennium 2006-2007. [Covering the period 1 January 2006 to 31 December 2007]

REPORT ON THE MEETINGS CONVENED. Biennium 2006-2007. [Covering the period 1 January 2006 to 31 December 2007] 1 Distr. LIMITED CDCC 22-3/Add.1 LC/CAR/L.162/Add.1 14 April 2008 ORIGINAL: ENGLISH REPORT ON THE MEETINGS CONVENED In Biennium - [Covering the period 1 January to 31 December ] Economic Commission for

More information

CSME OVERVIEW. Free Movement of Skills is classified under two categories:

CSME OVERVIEW. Free Movement of Skills is classified under two categories: CSME OVERVIEW BACKGROUND TO THE CSME In the Revised Treaty of Chaguaramas which created the Caribbean Community (CARICOM) including the CARICOM Single Market and Economy (CSME) there are specific provisions

More information

Recognition of Judgments 2016

Recognition of Judgments 2016 The United Nations High Commissioner for Refugees, Sin Fronteras, the Inter-American Commission on Human Rights, and the Asociación Mexicana de Impartidores de Justicia A.C. CALL FOR PROPOSALS Recognition

More information

OAS CYBER SECURITY INITIATIVE. Global Forum on Cyber Expertise (GFCE)

OAS CYBER SECURITY INITIATIVE. Global Forum on Cyber Expertise (GFCE) OAS CYBER SECURITY INITIATIVE Global Forum on Cyber Expertise (GFCE) CONTENTS 2 3 9 12 OAS Regional Cyber Security Framework What we offer to our Member States How we do our work ANNEX -A- OAS CYBER SECURITY

More information

DNS and BIND. David White

DNS and BIND. David White DNS and BIND David White DNS: Backbone of the Internet Translates Domains into unique IP Addresses i.e. developcents.com = 66.228.59.103 Distributed Database of Host Information Works seamlessly behind

More information

Current Counter-measures and Responses by the Domain Name System Community

Current Counter-measures and Responses by the Domain Name System Community Current Counter-measures and Responses by the Domain Name System Community Paul Twomey President and CEO 22 April 2007 APEC-OECD Malware Workshop Manila, The Philippines 1 What we want you to do today

More information

Frequently Asked Questions. Frequently Asked Questions: Securing the Future of Trust on the Internet

Frequently Asked Questions. Frequently Asked Questions: Securing the Future of Trust on the Internet FREQUENTLY ASKED QUESTIONS: SECURING THE FUTURE OF TRUST ON THE INTERNET Frequently Asked Questions Frequently Asked Questions: Securing the Future of Trust on the Internet Securing the Future of Trust

More information

Overview of CAAM-HP and its Achievements

Overview of CAAM-HP and its Achievements Overview of CAAM-HP and its Achievements Presented at the 10 th Anniversary Conference of the CAAM-HP July 28-30, 2014 Montego Bay, JAMAICA Lorna Parkins Executive Director The Caribbean GULF OF MEXICO

More information

Request for Proposal Title: Website Development and Maintenance for the Caribbean Leadership Project Country: International

Request for Proposal Title: Website Development and Maintenance for the Caribbean Leadership Project Country: International Request for Proposal Title: Website Development and Maintenance for the Caribbean Leadership Project Country: International Information to Consultants 1. Introduction 1.1 Consultants are invited to submit

More information

Climate finance as an instrument to enhance renewable energy technologies

Climate finance as an instrument to enhance renewable energy technologies Climate finance as an instrument to enhance renewable energy technologies Dr. Karla Solís-García Team Lead Regional Collaboration Centre St. George s 18 September 2013 CARILEC Renewable Energy Forum September,

More information

ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster

ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster Security Standards Symantec shall maintain administrative, technical, and physical safeguards for the Symantec Network designed to (i) protect the security and integrity of the Symantec Network, and (ii)

More information

Evolution of EU exports and imports of goods with CELAC, 2004-2014 (in billion)

Evolution of EU exports and imports of goods with CELAC, 2004-2014 (in billion) 100/2015-9 June 2015 EU Community of Latin American and Caribbean States (CELAC) summit CELAC represents the fifth most important trading partner of the EU More than 200 bn total trade The 28 Member States

More information

DNS POISONING, AKA PHARMING, MAKES THE HEADLINES IN NOVEMBER S NEWS

DNS POISONING, AKA PHARMING, MAKES THE HEADLINES IN NOVEMBER S NEWS DNS POISONING, AKA PHARMING, MAKES THE HEADLINES IN NOVEMBER S NEWS December 2011 November saw DNS Poisoning, aka Pharming, making the headlines on more than one occasion: To name a few, the online threat

More information

TAX CARIBBEAN REGIONAL CAPACITY BUILDING WORKSHOP ON FACTORING / RECEIVABLES DISCOUNTING TAX IMPLICATIONS ON FACTORING RECEIVABLES By H.

TAX CARIBBEAN REGIONAL CAPACITY BUILDING WORKSHOP ON FACTORING / RECEIVABLES DISCOUNTING TAX IMPLICATIONS ON FACTORING RECEIVABLES By H. TAX CARIBBEAN REGIONAL CAPACITY BUILDING WORKSHOP ON FACTORING / RECEIVABLES DISCOUNTING TAX IMPLICATIONS ON FACTORING RECEIVABLES By H. Wayne Lovell, Director, Tax, KPMG November 5 th 2009 Tax Implications

More information

The Security Framework 4.1 Programming and Design

The Security Framework 4.1 Programming and Design Tel: (301) 587-3000 Fax: (301) 587-7877 E-mail: info@setecs.com Web: www.setecs.com Security Architecture for Development and Run Time Support of Secure Network Applications Sead Muftic, President/CEO

More information

DNS Risks, DNSSEC. Olaf M. Kolkman and Allison Mankin. olaf@nlnetlabs.nl and mankin@psg.com. http://www.nlnetlabs.nl/ 8 Feb 2006 Stichting NLnet Labs

DNS Risks, DNSSEC. Olaf M. Kolkman and Allison Mankin. olaf@nlnetlabs.nl and mankin@psg.com. http://www.nlnetlabs.nl/ 8 Feb 2006 Stichting NLnet Labs DNS Risks, DNSSEC Olaf M. Kolkman and Allison Mankin olaf@nlnetlabs.nl and mankin@psg.com 8 Feb 2006 Stichting NLnet Labs DNSSEC evangineers of the day Allison: Independent consultant Member of the Internet2

More information

Website Security: It s Not all About the Hacker Anymore

Website Security: It s Not all About the Hacker Anymore Website Security: It s Not all About the Hacker Anymore Mike Smart Sr. Manager, Products and Solutions Trust Services & Website Security Website Security 1 Website Security Challenges Evolving Web Use

More information

Parent/Guardian details to be completed only where the applicant is 16 or 17 years old. If applicant is 18 or over, skip to Part 3.

Parent/Guardian details to be completed only where the applicant is 16 or 17 years old. If applicant is 18 or over, skip to Part 3. POINTS BASED SYSTEM APPENDIX 8 (APR 2016) TIER 4 (GENERAL) STUDENT SELF-ASSESSMENT This form is for use outside the UK only This form is provided free of charge For official use only READ THIS FIRST This

More information

DEADLINE: 01 April 2015, 4:30PM (AST) CARIBBEAN EXPORT DEVELOPMENT AGENCY REQUEST FOR PROPOSALS NOTICE

DEADLINE: 01 April 2015, 4:30PM (AST) CARIBBEAN EXPORT DEVELOPMENT AGENCY REQUEST FOR PROPOSALS NOTICE DEADLINE: 01 April 2015, 4:30PM (AST) CARIBBEAN EXPORT DEVELOPMENT AGENCY REQUEST FOR PROPOSALS NOTICE TITLE: Lead generation, pre-qualification and short-listing of foreign companies identified as potential

More information

Cybersecurity and internal audit. August 15, 2014

Cybersecurity and internal audit. August 15, 2014 Cybersecurity and internal audit August 15, 2014 arket insights: what we are seeing so far? 60% of organizations see increased risk from using social networking, cloud computing and personal mobile devices

More information

Microsoft s cybersecurity commitment

Microsoft s cybersecurity commitment Microsoft s cybersecurity commitment Published January 2015 At Microsoft, we take the security and privacy of our customers data seriously. This focus has been core to our culture for more than a decade

More information

Guidance Regarding Skype and Other P2P VoIP Solutions

Guidance Regarding Skype and Other P2P VoIP Solutions Guidance Regarding Skype and Other P2P VoIP Solutions Ver. 1.1 June 2012 Guidance Regarding Skype and Other P2P VoIP Solutions Scope This paper relates to the use of peer-to-peer (P2P) VoIP protocols,

More information

Number of relevant issues

Number of relevant issues Electronic signature Lecture 8 Number of relevant issues cryptography itself algorithms for signing documents key management generating keys, distribution, key revocation security policy certificates may

More information

Current Counter-measures and Responses by the Domain Name System Community

Current Counter-measures and Responses by the Domain Name System Community Current Counter-measures and Responses by the Domain Name System Community Paul Twomey President and CEO 22 April 2007 APEC-OECD Malware Workshop Manila, The Philippines 1 What I want to do today in 15

More information

States of Guernsey Home Department. Immigration Act 1971 as extended to the Bailiwick

States of Guernsey Home Department. Immigration Act 1971 as extended to the Bailiwick WORK PERMIT APPLICATION FORM WORK PERMIT APPLICATION FORM States of Guernsey Home Department Immigration Act 1971 as extended to the Bailiwick Work permits will be issued or refused on behalf of the Home

More information

DNSSEC. Introduction. Domain Name System Security Extensions. AFNIC s Issue Papers. 1 - Organisation and operation of the DNS

DNSSEC. Introduction. Domain Name System Security Extensions. AFNIC s Issue Papers. 1 - Organisation and operation of the DNS AFNIC s Issue Papers DNSSEC Domain Name System Security Extensions 1 - Organisation and operation of the DNS 2 - Cache poisoning attacks 3 - What DNSSEC can do 4 - What DNSSEC cannot do 5 - Using keys

More information

On and off premises technologies Which is best for you?

On and off premises technologies Which is best for you? On and off premises technologies Which is best for you? We don t mind what you buy, as long as it is YELLOW! Warren Sealey and Paul-Christian Garpe On Premises or in the cloud? 1 Agenda Why Symantec? Email

More information

The Global Framework for Climate Services

The Global Framework for Climate Services The Global Framework for Climate Services L. S. Rathore DGM & Co-Vice-Chair Intergovernmental Board on Climate Services http://gfcs.wmo.int 1 History of the GFCS Third World Climate Conference (2009):

More information

Harmonising Cyber Security Across the Caribbean: CTU Initiatives & Activities

Harmonising Cyber Security Across the Caribbean: CTU Initiatives & Activities Harmonising Cyber Security Across the Caribbean: CTU Initiatives & Activities Caribbean Telecommunications Union Presented by Nigel Cassimire Telecommunications Specialist ICT in the Caribbean 1. Caribbean

More information

Installing New Software Using the Online Installer (Backup and Restore Required)

Installing New Software Using the Online Installer (Backup and Restore Required) Installing New Software Using the Online Installer (Backup and Restore Required) Last Updated: September 7, 2010 This chapter provides procedures for installing a new version of the Cisco Video Management

More information

University of California, Riverside Computing and Communications. IS3 Local Campus Overview Departmental Planning Template

University of California, Riverside Computing and Communications. IS3 Local Campus Overview Departmental Planning Template University of California, Riverside Computing and Communications IS3 Local Campus Overview Departmental Planning Template Last Updated April 21 st, 2011 Table of Contents: Introduction Security Plan Administrative

More information

How To Manage Icann

How To Manage Icann FY13 ICANN Security, Stability & Resiliency Framework 1 June 2012 Part B Security, Stability & Resiliency Part B - FY 13 Module 2 Components of FY13 Framework PART A Foundational Section (Ecosystem & ICANN

More information

STATEMENT BY MS. SHORNA-KAY RICHARDS DEPUTY PERMANENT REPRESENTATIVE OF JAMAICA TO THE UNITED NATIONS ON BEHALF OF THE CARIBBEAN COMMUNITY (CARICOM)

STATEMENT BY MS. SHORNA-KAY RICHARDS DEPUTY PERMANENT REPRESENTATIVE OF JAMAICA TO THE UNITED NATIONS ON BEHALF OF THE CARIBBEAN COMMUNITY (CARICOM) STATEMENT BY MS. SHORNA-KAY RICHARDS DEPUTY PERMANENT REPRESENTATIVE OF JAMAICA TO THE UNITED NATIONS ON BEHALF OF THE CARIBBEAN COMMUNITY (CARICOM) DURING THE TWENTY-SEVENTH SESSION OF THE COMMITTEE OF

More information

CARICOM ICT STATISTICS AND INDICATORS

CARICOM ICT STATISTICS AND INDICATORS CARICOM ICT STATISTICS AND INDICATORS 2000 2012 STATISTICS SUB-PROGRAMME CARIBBEAN COMMUNITY (CARICOM) SECRETARIAT April 2014 i CARICOM ICT STATISTICS AND INDICATORS Copyright 2014, Caribbean Community

More information

Topics of Interest Iraklion, Greece June 2008

Topics of Interest Iraklion, Greece June 2008 Topics of Interest Iraklion, Greece June 2008 Kim Davies Internet Assigned Numbers Authority Internet Corporation for Assigned Names & Numbers Agenda ICANN Budget for 2009 Interim Trust Anchor Repository

More information

Maritime Law Enforcement

Maritime Law Enforcement Maritime Law Enforcement A Critical Component of National Security and Economic Vitality Maritime Security Challenges Multinational- Multiflags Terrorism Safe Ports & Waterways Smuggling g (Drugs & Aliens)

More information

Cybercrime & Cybersecurity

Cybercrime & Cybersecurity Cybercrime & Cybersecurity Professor Ian Walden Institute for Computer and Communications Law Centre for Commercial Law Studies, Queen Mary, University of London Introductory Remarks Inherently transnational

More information

Server Certificates based on DNSSEC

Server Certificates based on DNSSEC Server Certificates based on DNSSEC Audun Jøsang and Kashif Sana Dar University of Oslo josang@mn.uio.no and kashifd@ifi.uio.no Abstract. Globally unique domain names and IP addresses that are provided

More information

Closing the Antivirus Protection Gap

Closing the Antivirus Protection Gap A comparative study on effective endpoint protection strategies May 2012 WP-EN-05-07-12 Introduction Corporate economic concerns have put increased pressure on already limited IT resources in recent years

More information

Estimation of PPPs for non-benchmark economies for the 2005 ICP round

Estimation of PPPs for non-benchmark economies for the 2005 ICP round Estimation of PPPs for non-benchmark economies for the 25 ICP round This note provides a brief explanation on the imputation method used to estimate PPP rates at the GDP and private consumption level for

More information

Attitudes and Preferences in Relation to Internet Banking in The

Attitudes and Preferences in Relation to Internet Banking in The Attitudes and Preferences in Relation to Internet Banking in The Caribbean Prepared By: Dr. Justin Robinson Dr. Winston Moore Background to Study The financial services industry is important to overall

More information

Before The United States House of Representatives Committee On The Judiciary. Subcommittee on Intellectual Property, Competition and the Internet

Before The United States House of Representatives Committee On The Judiciary. Subcommittee on Intellectual Property, Competition and the Internet Before The United States House of Representatives Committee On The Judiciary Subcommittee on Intellectual Property, Competition and the Internet Hearing on Promoting Investment and Protecting Commerce

More information

Specific recommendations

Specific recommendations Background OpenSSL is an open source project which provides a Secure Socket Layer (SSL) V2/V3 and Transport Layer Security (TLS) V1 implementation along with a general purpose cryptographic library. It

More information

That Point of Sale is a PoS

That Point of Sale is a PoS SESSION ID: HTA-W02 That Point of Sale is a PoS Charles Henderson Vice President Managed Security Testing Trustwave @angus_tx David Byrne Senior Security Associate Bishop Fox Agenda POS Architecture Breach

More information

Internet-Praktikum I Lab 3: DNS

Internet-Praktikum I Lab 3: DNS Kommunikationsnetze Internet-Praktikum I Lab 3: DNS Mark Schmidt, Andreas Stockmayer Sommersemester 2015 kn.inf.uni-tuebingen.de Motivation for the DNS Problem IP addresses hard to remember for humans

More information

BitSight Insights Global View. Revealing Security Performance Metrics Across Major World Economies

BitSight Insights Global View. Revealing Security Performance Metrics Across Major World Economies BitSight Insights Global View Revealing Security Performance Metrics Across Major World Economies Introduction There is no denying the global nature of 21st century business. The export and import of goods

More information

RESOLVING SOVEREIGN DEBT DISTRESS IN THE CARIBBEAN TOWARDS A HEAVILY INDEBTED MIDDLE INCOME COUNTRY (HIMIC) INITIATIVE

RESOLVING SOVEREIGN DEBT DISTRESS IN THE CARIBBEAN TOWARDS A HEAVILY INDEBTED MIDDLE INCOME COUNTRY (HIMIC) INITIATIVE RESOLVING SOVEREIGN DEBT DISTRESS IN THE CARIBBEAN TOWARDS A HEAVILY INDEBTED MIDDLE INCOME COUNTRY (HIMIC) INITIATIVE SIR ARTHUR LEWIS INSTITUTE OF SOCIAL AND ECONOMIC STUDIES (SALISES) 15 th ANNUAL CONFERENCE

More information

ARGE Styrian Voip Business Park 4 8200 Gleisdorf Tel: 03112 38900 email: office@styrian-voip.at

ARGE Styrian Voip Business Park 4 8200 Gleisdorf Tel: 03112 38900 email: office@styrian-voip.at USA _001201 0,06 USA _001313 0,06 USA _001202 0,06 USA _001314 0,06 USA _001203 0,06 USA _001315 0,06 Canada _001204 0,06 USA _001316 0,06 USA _001205 0,06 USA _001317 0,06 USA _001206 0,06 USA _001318

More information

SSL and Browsers: The Pillars of Broken Security

SSL and Browsers: The Pillars of Broken Security SSL and Browsers: The Pillars of Broken Security Ivan Ristic Wolfgang Kandek Qualys, Inc. Session ID: TECH-403 Session Classification: Intermediate SSL, TLS, And PKI SSL (or TLS, if you prefer) is the

More information

DNS & IPv6. Agenda 4/14/2009. MENOG4, 8-9 April 2009. Raed Al-Fayez SaudiNIC CITC rfayez@citc.gov.sa, www.nic.net.sa. DNS & IPv6.

DNS & IPv6. Agenda 4/14/2009. MENOG4, 8-9 April 2009. Raed Al-Fayez SaudiNIC CITC rfayez@citc.gov.sa, www.nic.net.sa. DNS & IPv6. DNS & IPv6 MENOG4, 8-9 April 2009 Raed Al-Fayez SaudiNIC CITC rfayez@citc.gov.sa, www.nic.net.sa Agenda DNS & IPv6 Introduction What s next? SaudiNIC & IPv6 About SaudiNIC How a cctld Registry supports

More information

Data Protection: From PKI to Virtualization & Cloud

Data Protection: From PKI to Virtualization & Cloud Data Protection: From PKI to Virtualization & Cloud Raymond Yeung CISSP, CISA Senior Regional Director, HK/TW, ASEAN & A/NZ SafeNet Inc. Agenda What is PKI? And Value? Traditional PKI Usage Cloud Security

More information

Call for Expressions of Interest (EOI):

Call for Expressions of Interest (EOI): 10 th EDF Sanitary and Phytosanitary Measures (SPS) Project Support to the Caribbean Forum of ACP States in the Implementation of Commitments Undertaken Under the Economic Partnership Agreement (EPA):

More information

Preparing Tomorrow's Teachers with Web 2.0 Tools and 21st Century Skills 1

Preparing Tomorrow's Teachers with Web 2.0 Tools and 21st Century Skills 1 Professional Development Scholarship Program Preparing Tomorrow's Teachers with Web 2.0 Tools and 21st Century Skills 1 OAS/DHDEC/CIR.031/2012 1) Study venue: The course will be delivered entirely online

More information

ftld Registry Services Security Requirements December 2014

ftld Registry Services Security Requirements December 2014 ftld Registry Services Security Requirements December 2014 1. define Ensure domains are compliant with and implement a name provide a description of its the name selection policy. selection policy (i.e.,

More information

What Does DNSChanger Do to My Computer? Am I Infected?

What Does DNSChanger Do to My Computer? Am I Infected? DNSChanger Malware DNS (Domain Name System) is an Internet service that converts user-friendly domain names into the numerical Internet protocol (IP) addresses that computers use to talk to each other.

More information

Certified Secure Computer User

Certified Secure Computer User Certified Secure Computer User Exam Info Exam Name CSCU (112-12) Exam Credit Towards Certification Certified Secure Computer User (CSCU). Students need to pass the online EC-Council exam to receive the

More information

Wireless Robust Security Networks: Keeping the Bad Guys Out with 802.11i (WPA2)

Wireless Robust Security Networks: Keeping the Bad Guys Out with 802.11i (WPA2) Wireless Robust Security Networks: Keeping the Bad Guys Out with 802.11i (WPA2) SUNY Technology Conference June 21, 2011 Bill Kramp FLCC Network Administrator Copyright 2011 William D. Kramp All Rights

More information

Your Global Solution For Medical Flights Caribbean, Americas and Transatlantic

Your Global Solution For Medical Flights Caribbean, Americas and Transatlantic Air Ambulance CARIBBEAN AIR MEDICAL ASSISTANCE Your Global Solution For Medical Flights Caribbean, Americas and Transatlantic ABOUT US JetBudget is an air operator based in St Maarten / St Martin specializing

More information

THE UNIVERSITY OF THE WEST INDIES OPEN CAMPUS ADVERTISEMENT

THE UNIVERSITY OF THE WEST INDIES OPEN CAMPUS ADVERTISEMENT THE UNIVERSITY OF THE WEST INDIES OPEN CAMPUS ADVERTISEMENT ENTERPRISE APPLICATIONS SUPPORT MANAGER COMPUTING AND TECHNOLOGY SERVICES DEPARTMENT (CATS) (TRINIDAD AND TOBAGO) Applications are invited for

More information