IT-Security at Karlsruhe Institute of Technology Introduction Andreas Lorenz STEINBUCH CENTRE FOR COMPUTING - SCC KIT University of the State of Baden-Württemberg and National Laboratory of the Helmholtz Association www.kit.edu
Agenda KIT Mission Organization Scientific Topics IT-Security in the Organization IT-Security Policy Cooperation IT-Security, Data Protection and IT- Compliance KIT-CERT 2 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: One Institution, Two Missions Mission of a state university with research and teaching Mission of a research institution of the Helmholtz Association with program oriented provident research Employees 8.500 19.700 Students 364 Professors Annual Budget in Million Euros 482 Trainees 3 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: Common Objective Positioning as an institution of excellent research and teaching in natural and engineering sciences on an international scale, with scientific excellence and worldwide top level in Research Teaching Innovation IT-Security and Service Management Prerequisite: Excellent infrastructure and service units. 4 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: Fields, Centers and Focusses 30 Fields of Competence Bundled in 6 Areas of Competence Matter and Materials Earth and Environment Applied Life Siences Systems ans Processes Information, Communication und Organization Technology, Culture and Society KIT Centers: Energy Nano & Micro Science and Technology Elementary Particle and Astroparticle Physics Climate and Environment KIT Focuses: COMMputation Mobility Systems Optics and Photonics Humans and Technology Secure IT-based Solutions! 5 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
SCC: IT-Security in the Organization 6 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
SCC: IT-Security Tasks of ISM Operation and Development IT-Security Management IT-Security Officer Organizational Aspects ASDUR Organizational Aspects Definition of Policies Organizational Aspects Patchmanagement Awareness Operation and Development IT-Security Services KIT-CERT Organizational Aspects KIT-CA Encryption Concept / Operation&Development Platform Intrusion Detection Systems /Intrusion Prevention Systems Security Assesments Desktop Security 7 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology Organisationseinheit, Autor 23.09.2010 7
KIT: IT-Security Policy Details low Changes rare IT-Security Guideline (CIO) Common Security Conception (IT-Security Officer) IT-Security Concept IT-Security Policies high Technical Advisories (IT-Security Team) often 8 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: IT-Security Guideline November 2009 Assets to Protect Organization Presidium / CIO IT-Committees IT-Security Officer Cooperation IT- Security, Data Protection and IT- Compliance SCC and IT-Security Team (KIT-CERT) Users IT-Security Process 9 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: IT-Security Officer Coordination Definition of IT-Security Concept and Backout Concepts Security-Relevant Projects; Informationflow between persons in charge Initiating and Controlling Actionplan to implement IT-Security Measures IT-Security Awarenesscappaigns- and Trainings Initiating and Coordination Definition of IT-Security Policies Coordination and Controlling IT-Security Process Inspecting Security Incidents Supporting CIO by Definition of IT-Security Guideline Reporting CIO and IT-Security Team 10 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: ASDUR Arbeitsstab IT-Sicherheit, Datenschutz und IT-Rechtskonformität Cooperation between IT-Security, Data Protection and IT-Compliance at an early stage of a project Lead by CIO Interdisciplinary Key Issues IT-Security Data Protection IT-Compliance Development of Advices Strategic Policies Strategic Regulations Members CIO IT-Security Officer Data Protection Officer Jurisconsult Users Administration Scientists Staff Council 11 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT: IT-Security Process Preparation Strategic Decissions User Interests KIT-Presidium Data Protection ASDUR IV-A (IT-Comitee) IT-Security SCC IT- Compliance Preparation Technical Decission 12 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology, Adrian Wiedemann 23.09.2010 12
ASDUR: Task Usergroups Netzzugriff auf das Internet (ab Campus KIT) Netzzugriff auf das Intranet (Netzwerk, kein Inhalt) Inhalte (Web, File,...) VPN / Remote Access Email KIT Email (nicht kit.edu) Portalbereich (geschützt) Nutzung Software Lizenzen Rechenleistung Datenhaltung Nutzung von Terminaldiensten (ssh etc.) / Zugriff auf lokale Rechner Business Class Mitarbeiter A1 A6 Mitarbeiter - entbunden A4 A4 A1 A4 A4 A4 A4 A4, A6 A4 A4 A4 Studierende r A1 A6 Gasthörer/S chüler A3 A3 A1 A3 A3 A3 A3, A6 A3 A3 A3 Lehrender A1 A6 Förderer A6 Gast - mitarbeitend A2 A2 A2 A2 A2 A2, A6 A2 A2 A2 Gast A6 Extrener - mitarbeitend A1 A6 Externer A5 Markierung: verboten (rechtlich) mit Auflagen erlaubt erlaubt verboten (KIT- Regelwerk) Rechtliche Unsicherheit 13 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT-CERT Computer Emergency Response Team central authority for issues concerning IT security and coordination in the field of computer abuse in KIT Reactive Services Coordination of security or abuse-related investigations Incident response on imminent security breaches Computer-forensic investigations Proactive Servcies Operating network security systems on various layers Monitoring network traffic for malicious activity Consulting Services Counseling on topics concerning information-security Publishing reports on specific topics for KIT Collaboration regarding the creation and publication of security policies 14 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
KIT-CERT 15 10.09.2010 Andreas Lorenz IT-Security at Karlsruhe Institute of Technology
Thank you for your attention andreas.lorenz@kit.edu STEINBUCH CENTRE FOR COMPUTING - SCC KIT University of the State of Baden-Württemberg and National Laboratory of the Helmholtz Association www.kit.edu