information security

26
Information Security

Upload: jean

Post on 21-Mar-2016

54 views

Category:

Documents


0 download

DESCRIPTION

Information Security. The CIA Triad. Confidentiality. The state of being secret. Security. Integrity. Availability. Present and ready for use. The state or quality of being entire or complete. The Job. http://technet.microsoft.com/en-us/library/cc723507.aspx. Agenda. Some Threats - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Information Security

Information Security

Page 2: Information Security

The CIA TriadConfidentialitConfidentialit

yy

IntegritIntegrityy

AvailabiliAvailabilityty

The state of being secret

The state or quality of being

entire or complete

Present and ready for use

SecuritySecurity

Page 3: Information Security

The Job

http://technet.microsoft.com/en-us/library/cc723507.aspx

Page 4: Information Security

Agenda

Some ThreatsSome Controls

Page 5: Information Security

San Francisco – Terry Childs

http://articles.sfgate.com/2008-12-27/bay-area/17133065_1_computer-network-mr-childs-passwords

Page 6: Information Security

UBS – Roger Duronio

http://www.cbsnews.com/stories/2002/12/18/tech/main533450.shtml

Page 7: Information Security

Certegy Check Services

Page 8: Information Security

Lost Backup Tapes

Page 9: Information Security

Australia – Vitek Boden

“…marine life died, the creek water turned black and the stench was unbearable for residents…”

- Australian EPA

This file is licensed under the Creative Commons Attribution-Share Alike 2.5 Generic license

Page 10: Information Security

California – Mario Azar

Page 11: Information Security

Google and China

Page 12: Information Security

Waheed Mahmood

http://news.bbc.co.uk/

Page 13: Information Security

Lost Laptop

Page 14: Information Security

Scottish Council Loses Pay Details

Page 15: Information Security

Customer Information in Bins

Page 16: Information Security

The Biggie …

Page 17: Information Security
Page 18: Information Security

SMART

Page 19: Information Security

Where is Security?

IT Security?

Information Security?

Physical Security?

Business Security? Business Assurance?

Page 20: Information Security

Some Problems

IT VendorsPeople – IT, employees, others …ComplexityTechnologyControl SystemsAnyone who thinks that I am responsible for Information Security

Page 21: Information Security

Agenda

Some ProblemsSome Solutions

Page 22: Information Security

- 22 -

Security Golden Rules

Accept Challenges

Display Your Badge

Assess Risks

Protect Your Identity

Thirty Minute Rule

Page 23: Information Security

Security Program

Risk ManagementPolicy … StandardsBusiness EngagementCulture / Behaviour ChangeSecurity ArchitectureMetrics and MeasurementsManagement SystemMoney / StaffControls

Page 24: Information Security

Further Reading

Bruce SchneierSANS Internet Storm Centre / NewsbitesSecurityFocusTitan RainAdvanced Persistent ThreatJericho Forum

Page 25: Information Security

Questions

Page 26: Information Security

Reading List

Ross Anderson: Security EngineeringBruce Schneier: Secrets & Lies