B2B eCommunity Ops Continuity

Concerns 2002

http://misrc.umn.edu/calendar.asp

Date: January 18, 2002

Speaker: Bob Burkhart

Topic: "Dealing with Digital Disruptions and Software Sabotage"

Abstract:

Shortly after the Sept 11 terrorism attacks in New York and Washington, another virus attack was initiated over the Internet. Both the frequency and destructive potential of virus and hacking attacks are increasing to the point where giving this the label of cyber terrorism is not an exaggeration. This presentation is directed towards mid level IS professionals and business managers seeking solutions to the growing need to protect their organization's information and client data. This is not just for the internal comp sci experts, but is very important in the analysis, design, construction and operation of business processes and information systems.

Some topics to be covered:

Understanding risk factors and safeguards

Clarification of terms and provide context for the terms

How not to be a victim

New legislation on security and privacy

Computer forensics and digital evidence

Review the FBI InfraGard program (public and private collaboration)

Sample policies and procedures

The presentation will include mini-case studies of attacks, prevention, detection and response.

 

Biography:

Bob Burkhart is a principal in ACCTTS, LLC, (www.acctts.com) which designs, develops and delivers training products supporting the InfraGard Outreach Program. The InfraGard Outreach program operates under the FBI's National Infrastructure Protection Center (www.nipc.gov) to help safeguard e-Business ventures and E-Commerce information protection (ECip) initiatives. ACCTTS Programs build on prior "lessons learned" by professional association supporters, concerned multi-national firms, communities of interest and regional program co-sponsors.

Bob (RJ) Burkhart works with Information Resource and Information Security Management (IRM & ISM) emphasizing business system productivity, quality, and protection. His focus is on business disruption AVOIDance and scenario-based team training. Bob received his M.S. in Information Science from the University of Hawaii – Manoa and a B.S. in Business degree from the University of Kansas.

He completed a Mini-MSDD with Graduate Programs in Software at the University of St. Thomas in 1992.

Bob is a long-term member of www.MnIPS.org and currently serves as Secretary of this organization and served as an on-line guest lecturer for Capella University's Cyber Threats to Enterprise Security Workshop.

This course, designed for IT managers, executives, network and system administrators, plus other IT professionals helps learners develop a practical working knowledge and vocabulary to assess their organization's digital disruption risks.

Registration for this seminar

http://misrc.umn.edu/register.asp

Click here for information regarding Audio Conferencing

http://misrc.umn.edu/year_end_meeting.htm

Click here for Presenter Seminar Presentation Slides- Posted before

each seminar with permission from the presenter

http://misrc.umn.edu/PresenterSlides.htm

B2BeCommunity_OpsContinuity-Concerns-2002.htm

 

Tivoli® Security Management Solution [IBM]

Tivoli security provides three critical solutions for secure e-business:

Access management

Identity management

Risk management

The Tivoli Security Solution enables e-businesses to increase revenues by providing secure access for customers, prospects and partners, optimize operational expenses through centralized single-action management, and effectively manage security threats, attacks and exposures across the entire organization.

Tivoli Security removes the security barriers to fully exploiting e-business.

http://www.tivoli.com/products/solutions/security/news.html

 

M_O_M

Relationship

Profile

Motive

Opportunity

(Means)

Methods

© 2001 by ACCTTS, LLC. All Rights Reserved Worldwide.

http://www.acctts.com/MISACATTS/ACCTTS-SIRT-CATTS_Proposal.htm

Operational

Risk Factors

© 2001 by ACCTTS, LLC. All Rights Reserved Worldwide.

http://www.acctts.com/dimens-1.html#MenuD1

Gartner Group: Information Systems Security Dimensions

http://mdev.temple.edu/gartner/research/ras/98600/98601/98601.html

DISA ISO 7498-2

http://www.google.com/search?site=swr&hl=en&q=DISA+ISO+7498-2&as_q=Security

Evolving Operational Continuity

Security Incident Response Teams (OCSIRT)

Capella University "Cyber Threats to Enterprise Security"
TS5070: On-Line Workshop

http://www.acctts.com/trust-factors/Capella%20University%20%20Online%20CyberThreats%20Workshop.htm

 

Denial of Service Attack Scenario

http://www.tivoli.com/products/index/secureway_risk_mgr/images/intrusion_detection.jpg

When companies experience a denial of service attack, like the ones that wiped out high-profile Web sites this year, security administrators can often become confused by the plethora of event information sent by firewalls and intrusion detection systems.

Tivoli Risk Manager features an advanced correlation engine, based on technology created in IBM's Zurich Research laboratory, that pulls information from various security checkpoints and determines the difference between real attacks and false-positives.

http://www.tivoli.com/products/index/secureway_risk_mgr/

 

Networking

& IT Systems

Complexity

New products are continually being introduced into the IT marketplace that offer new services or business opportunities.

As businesses try to keep up with innovative technologies and opportunities, integration and manageability issues occur more frequently.

http://www.tivoli.com/bpprogram/programs/tivoliready/

Tivoli leverages its Business Partner Program

Partner organization to ensure other security technologies are integrated with Tivoli Risk Manager.

You can find more information on the value of integrating with Tivoli Risk Manager at

http://www.tivoli.com/products/documents/whitepapers/sway_risk_mgr_wp.pdf

 

Figure 1.Tivoli

SecureWay Risk

Manager integrates

information from

multiple sources.

Tivoli SecureWay

Risk Manager

Desktops

Web Farm

Tivoli

Firewall

Tivoli

Database

Manager

Tivoli

Public Key

Infrastructure

Server

Router

IDS

Appliance

Directory

Mainframe

Relationship

Profile


Motive

Opportunity

(Means)


Methods

Frequency
[H-M-L]

Impacts
[H-M-L]

Effective

Safeguards

Proven
Practices

Mandated
Controls

                   

Insiders:

(In-laws?)

Clueless
User

None

Access &
Authorization

Error &
Omissions

High

Low-Med

     
                   

 

Contractor

Varies

Weak
Controls

Exploits Lax
Controls

Unknown

Med-High

     
                   

 

Disgruntled
Stakeholder

Get Even

Insider
Insights

Exploits Lax
Controls

Low-Med

High

     
                   

 

Gamers
(MUDD)

Have Fun

After Hours
Diversions

Compromises
Controls

Low

Med-High

     
                   

 

Outsiders:

(Outlaws?)

Script
Kiddie

Intellectual
Curiosity

Spare Time
Lax Parents

Freeware

High

Low-Med

     
                   

 

Hacktivist

Political
Causes

See
Below

Various

Unknown

Med-High

     
                   

 

Coder / Pro
(Core Wars)

Peer
Recognition

Lax Software
Quality

Discovers
Loopholes

Low

High

(Day Zero)

     
                   

 

Comp Intel & Economic

Espionage

Economic
Gain

   

Medium

High

     
                   

 

State-Sponsored
Netspionage

Economic
& Political
Gains

   

Unknown


(
See Survey)

High

     
                   

© 2001 by ACCTTS, LLC. All Rights Reserved Worldwide.

IE Only Ref: http://my.octopus.com/view.oce?v=6B3937A27CD749E39C510BCF93ED8934 [ACCTTS-SIRT Selection Support PKM]
MISD 692Text: http://www.metasecuritygroup.com/services/design.html - sirt

& http://www.metasecuritygroup.com/research/glossary.html [Glossary of Terns]

 

 

Operational

Risk

Factors:

Type Digital
Disruption

Outage
Impacts?
[H-M-L]

Outage
Scope?

Time- Critical
Window?

Outage
Duration?

Protection

Policy

Pre-Reqs

Defined

SIRT

Roles

Key
Resp. &
Resources

Desired
Results

Metrics?

                   

 

Anti-Social
Engineering

               
                   

 

Deletion

(Accidental)

               
                   

 

Denial of Service

               
                   
 

Destruction
(Intentional)

               
                   
 

Errors &
Omissions

               
                   
 

Unauthorized Access

               
                   
 

Unauthorized Disclosure

               
                   
 

Unauthorized
Duplication

               
                   
 

Unauthorized
Modification

               
                   
 

Network Abuse
or Misuse

               
                   

© 2001 by ACCTTS, LLC. All Rights Reserved Worldwide.