National Incident Response Team Implementation. Mohamad Sazly B Musa IMPACT 29 th April 2013

Similar documents
Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

MANITOBA SECURITIES COMMISSION STRATEGIC PLAN

Copernicus & Big Data: A Perspective from the European EO Services Industry. Geoff Sawyer: EARSC Secretary General

9 ITS Standards Specification Catalog and Testing Framework

TERM OF REFERENCE. for the English Based Curriculum Development (Primary) for Westline Education Group

Research Report. Abstract: The Emerging Intersection Between Big Data and Security Analytics. November 2012

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014

Avaya Business Continuity Plan Overview

Organisational self-migration guide an overview V1-5 April 2014

BT Applications Assured Infrastructure (AAI) Application Optimisation Service (AOS) Optimising business performance

Policy on Free and Open-source Software. Government Policy of Iceland

Build the cloud OpenStack Installation & Configuration Integration with existing tools and processes Cloud Migration

PROTIVITI FLASH REPORT

High Level Meeting on National Drought Policy (HMNDP) CICG, Geneva March 2013

Inter-University Council for East Africa Institution of the East African Community

ISO Management Systems. Guidance on understanding the benefits of an ISO Management System

Job Profile Data & Reporting Analyst (Grant Fund)

D11.6 Project Web Site Report

COUNTY OF SONOMA AGENDA ITEM SUMMARY REPORT

Introduction to Mindjet MindManager Server

Help Desk Level Competencies

Service Level Agreement in IBM T Clud - ITAP

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT

State of Wisconsin. File Server Service Service Offering Definition

Datasheet. PV4E Management Software Features

Systems Support - Extended

State of Wisconsin Division of Enterprise Technology (DET) Distributed Database Hosting Service Offering Definition (SOD)

Customizing Microsoft Dynamics CRM for Complex Field Service and Sales Organizations

SOFTWARE DEVELOPER POSITION BY RIOMED LTD. SAFE. EFFICIENT. QUALITY WORLD CLASS HEALTHCARE SOLUTION

SUPPORTING SMEs IN A TIME OF CRISIS: HOW TO CHOOSE THE RIGHT ACTIONS

Organizational Capacity. Audit Tool

Microsoft Certified Database Administrator (MCDBA)

How To Run An Independent Cmpany

Zimbra Professional Services Portfolio, Purchasing Guide & Price List

VACANCY. SENIOR MANAGER: SPECIAL PROJECTS AND STAKEHOLDER MANAGEMENT x1 3 YEAR CONTRACT (WITH A POSSIBILITY OF BEING EXTENDED TO 5 YEARS) JOB LEVEL: 5

How Does Cloud Computing Work?

Cloud Services Frequently Asked Questions FAQ

IT Help Desk Service Level Expectations Revised: 01/09/2012

Organizational Capacity Audit Tool. Prepared by. Esther Wachira Global e-schools and Communities Initiative September 2009

JACK CROWLEY, PMP 3856 Mill Mount Drive Powhatan, Virginia

G-CLOUD FRAMEWORK SERVICE DEFINITION. Oracle Technology Service for Agile Cloud Projects. Copyright: point6 Ltd

Statewide Strategic Plan for Global Learning in Minnesota. Global Learning Advisory Board Five Year Plan

Understand Business Continuity

MANAGED VULNERABILITY SCANNING

TESTING TIMES: HOLISTIC ENVIRONMENT MANAGEMENT IN AN AGILE WORLD

G-CLOUD FRAMEWORK SERVICE DEFINITION. Solution Architecture for Cloud Service. Copyright: point6 Ltd

The Importance Advanced Data Collection System Maintenance. Berry Drijsen Global Service Business Manager. knowledge to shape your future

Partnership for better solutions DATALAB DEVELOPER PROGRAM

How To Manage An Infrmatin Security Gvernance Prgram

How To Write Insurance Quotation Software For Gthaer Vericherungen Insurance Prducts

HP ExpertOne. HP2-T21: Administering HP Server Solutions. Table of Contents

Leoni s implementation of a travel and expense solution

IT CHANGE MANAGEMENT POLICY

POSITION DESCRIPTION. Classification Higher Education Worker, Level 7. Responsible to. I.T Manager. The Position

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S

The Whole of Government Approach: Models and Tools for EGOV Strategy & Alignment

ALM in the Cloud an Overview of Oracle Developer Cloud Service. Introduction. By Dana Singleterry

PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK

Lumesse TalentLink pricing guide for G-Cloud 5

Proposal: Tourism and Hospitality Certificate Program

Installation Guide Marshal Reporting Console

Professional Leaders/Specialists

Personal Data Security Breach Management Policy

CSC 421 COURSE COMPACT

Oakland County Department of Information Technology Project Scope and Approach

CTF-ENDORSED NF CLINICS: PRINCIPLES OF OPERATION

Presentation: The Demise of SAS 70 - What s Next?

Transcription:

Natinal Incident Respnse Team Implementatin Mhamad Sazly B Musa IMPACT 29 th April 2013

ITU-IMPACT Cllabratin The Internatinal Multilateral Partnership Against Cyber Threats (IMPACT) is the cybersecurity executing arm f the United Natins (UN) specialised agency - the Internatinal Telecmmunicatin Unin (ITU) bringing tgether gvernments, academia and industry experts t enhance the glbal cmmunity s capabilities in dealing with cyber threats. ITU & IMPACT signs a Memrandum f Understanding in 2008. IMPACT becmes the physical hme f ITU s Glbal Cybersecurity Agenda t peratinalise cybersecurity services acrss 193 cuntries. ITU & IMPACT signs a Cperatin Agreement in May 2011. IMPACT becmes the cybersecurity executing arm f the United Natins specialised agency, ITU. IMPACT nw will expand its services t the UN System. 2

ITU-IMPACT A Glbal Calitin Industry Partners Academia Internatinal Bdies Think Tanks Cybersecurity Services 193 Partner Cuntries UN System 3

Cybersecurity Services Deplyed 145 Cuntries have jined the ITU-IMPACT Calitin 4

Cmputer Incident Respnse Team CIRT Assessments and Deplyments Over 40 Assessments Perfrmed Glbally Afghanistan Albania Armenia Bangladesh Barbads Bhutan Bsnia & Herzegvina Btswana Burkina Fas Cambdia Camern Chad Cng Dminican Republic Ecuadr Gabn Gambia Ghana Grenada Hnduras Ivry Cast Kenya Las Lebann Lesth Macednia Maldives Mali Mntenegr Myanmar Nepal Niger Nigeria Senegal Serbia St. Kitts & Nevis St. Vincent & the Grenadines Sudan Tanzania Tg Trinidad & Tbag Uganda Vietnam Zambia Fur Cmpleted Deplyments: Mntenegr, Zambia, Kenya & Burkina Fas Seven Planned fr 2013: Uganda, Tanzania, Ivry Cast, Tg, Barbads, Trinidad & Tbag, Burundi 5

CIRT Deplyment 2012 Natinal CIRT Implementatin Mntenegr Zambia http://www.cirt.me http://www.cirt.zm Kenya Burkina Fas https://cirt.cck.g.ke http://www.cirt.bf 6

CIRT Deplyment 2012 Mntenegr CIRT Our first implementatin f the CIRT in Mntenegr has been frmally inducted as a member f FIRST and becme a trusted intrducer 7

Cmputer Incident Respnse Team Definitin CIRT stands fr Cmputer Incidents and Respnse Team It is an rganisatin r team that prvides services and supprt fr bth preventing and respnding t cmputer security incidents A fcal pint t crdinate incident handling activities 8

Cmputer Incident Respnse Team CIRT Services Reactive Services Practive Services Security Quality Management Services Alerts, Warnings and Advisries Annuncements Risk Analysis Incident Handling Incident analysis Incident respnse n site Incident respnse supprt Incident respnse crdinatin Vulnerability Handling Vulnerability analysis Vulnerability respnse Vulnerability respnse crdinatin Artifact Handling Artifact analysis Artifact respnse Artifact respnse crdinatin Technlgy Watch Security-Related Infrmatin Disseminatin Security Audits r Assessments Cnfiguratin and Maintenance f Security Tls, Applicatins, and Infrastructures Develpment f Security Tls Intrusin Detectin Services Business Cntinuity and Disaster Recvery Planning Security Cnsulting Awareness Building Educatin/Training Prduct Evaluatin r Certificatin Surce: Handbk fr CSIRTs http://www.cert.rg/archive/pdf/csirt-handbk.pdf 9

Cmputer Incident Respnse Team Backgrund Emerging need fr natinal CIRTs t supprt incident acrss natinal s brders Identifies incidents that culd affect critical infrastructures CIRT can prvide a single pint f cntact fr dealing with cyber security incidents 10

Cmputer Incident Respnse Team Why Establish a Natinal CIRT? Increase in the number f reprted cmputer security incidents Grwth in the number f reprted vulnerabilities The realisatin that system and netwrk administratrs alne cannt prtect rganisatinal systems and assets The realisatin that a prepared plan and strategy is required T encurage citizens and cmpanies t reprt crimes mre ften 11

Radmap Natinal CIRT Implementatin Phase 1 6 mnths Phase 6-12 mnths 2 Phase 3 12

Methdlgy 13

Implementatin Apprach Activities Offsite Planning & design stage (URS) Remte installatin Onsite URS presentatin and signing Training n CIRT prcesses and applicatins Fine-tuning CIRT applicatins Operatin 6 mnths supprt fr CIRT peratins 14

Delivery Methd Onsite Implementatin Activities 10-day nsite training prgram fcusing n CIRT prcesses and systems Incident respnse framewrk CIRT prtal Incident management system (RTIR) Basic Linux administratin Lg analysis 15

Deliverables CIRT Implementatin Phase 1 The Natinal CIRT wuld be: Able t cnduct cybersecurity trainings and awareness activities within the cuntry Able t send alerts and warnings t varius stakehlders in the cuntry Able t handle and respnd t cybersecurity incidents 16

IMPACT Certlite Slutin Natinal CIRT Implementatin A cllectin f pen surce tls t enable the CIRT t prvide basic services t its cnstituents. CIRT Prtal Incident Management System Mailing List 17

IMPACT Certlite Slutin CIRT Prtal CIRT Prtal is a platfrm which publishes latest updates n threats and vulnerability. It's main functin is t facilitate the distributin f infrmatin t the targeted grup f audience 18

IMPACT Certlite Slutin Incident Management System The incident management system is based n Request Tracker fr Incident Respnse (RTIR). It is a custmised incident handling and ticketing system which has been built upn ne f the mst successful pen surce ticketing system the Request Tracker (RT). 19

IMPACT Certlite Slutin Mailing List A versatile mass mailing and cntact management tl. It is embedded in the CIRT prtal t allw users frm the cnstituent t subscribe t CIRT updates r alerts. 20

Incident Respnse Framewrk Natinal CIRT Implementatin Prvides an verview f the incident handling prcess, including CIRT services, intruder threats and the nature f incident respnse activities Standard Operating Prcedures (SOP) Plicy templates 21

Challenges Natinal CIRT Implementatin Acquiring the right peple fr CIRT Funding fr setting up the CIRT infrastructure Lengthy prcess fr prcurement f hardware Language barrier 22

Thank Yu IMPACT Jalan IMPACT63000 Cyberjaya Malaysia T +60 (3) 8313 2020 F +60 (3) 8319 2020 E cntactus@impact-alliance.rg impact-alliance.rg Cpyright 2012 IMPACT. All Rights Reserved.