B2B eCommunity Ops Continuity
Concerns 2002
http://misrc.umn.edu/calendar.asp
Date: January 18, 2002
Speaker: Bob Burkhart
Topic: "Dealing with Digital Disruptions and Software Sabotage"
Abstract:
Shortly after the Sept 11 terrorism attacks in New York and Washington, another virus attack was initiated over the Internet. Both the frequency and destructive potential of virus and hacking attacks are increasing to the point where giving this the label of cyber terrorism is not an exaggeration. This presentation is directed towards mid level IS professionals and business managers seeking solutions to the growing need to protect their organization's information and client data. This is not just for the internal comp sci experts, but is very important in the analysis, design, construction and operation of business processes and information systems.
Some topics to be covered:
Understanding risk factors and safeguards
Clarification of terms and provide context for the terms
How not to be a victim
New legislation on security and privacy
Computer forensics and digital evidence
Review the FBI InfraGard program (public and private collaboration)
Sample policies and procedures
The presentation will include mini-case studies of attacks, prevention, detection and response.
Biography:
Bob Burkhart is a principal in ACCTTS, LLC, (www.acctts.com) which designs, develops and delivers training products supporting the InfraGard Outreach Program. The InfraGard Outreach program operates under the FBI's National Infrastructure Protection Center (www.nipc.gov) to help safeguard e-Business ventures and E-Commerce information protection (ECip) initiatives. ACCTTS Programs build on prior "lessons learned" by professional association supporters, concerned multi-national firms, communities of interest and regional program co-sponsors.
Bob (RJ) Burkhart works with Information Resource and Information Security Management (IRM & ISM) emphasizing business system productivity, quality, and protection. His focus is on business disruption AVOIDance and scenario-based team training. Bob received his M.S. in Information Science from the University of Hawaii – Manoa and a B.S. in Business degree from the University of Kansas.
He completed a Mini-MSDD with Graduate Programs in Software at the University of St. Thomas in 1992.
Bob is a long-term member of www.MnIPS.org and currently serves as Secretary of this organization and served as an on-line guest lecturer for Capella University's Cyber Threats to Enterprise Security Workshop.
This course, designed for IT managers, executives, network and system administrators, plus other IT professionals helps learners develop a practical working knowledge and vocabulary to assess their organization's digital disruption risks.
Registration for this seminar
http://misrc.umn.edu/register.asp
Click here for information regarding Audio Conferencing
http://misrc.umn.edu/year_end_meeting.htm
Click here for Presenter Seminar Presentation Slides- Posted before
each seminar with permission from the presenter
http://misrc.umn.edu/PresenterSlides.htm
B2BeCommunity_OpsContinuity-Concerns-2002.htm
Tivoli® Security Management Solution [IBM]
Tivoli security provides three critical solutions for secure e-business:
Access management
Identity management
Risk management
The Tivoli Security Solution enables e-businesses to increase revenues by providing secure access for customers, prospects and partners, optimize operational expenses through centralized single-action management, and effectively manage security threats, attacks and exposures across the entire organization.
Tivoli Security removes the security barriers to fully exploiting e-business.
http://www.tivoli.com/products/solutions/security/news.html
Profile
Motive
Opportunity
(Means)
Methods
© 2001 by ACCTTS, LLC. All Rights Reserved Worldwide.
http://www.acctts.com/MISACATTS/ACCTTS-SIRT-CATTS_Proposal.htm
© 2001 by ACCTTS, LLC. All Rights Reserved Worldwide.
http://www.acctts.com/dimens-1.html#MenuD1
Gartner Group: Information Systems Security Dimensions
http://mdev.temple.edu/gartner/research/ras/98600/98601/98601.html
DISA ISO 7498-2
http://www.google.com/search?site=swr&hl=en&q=DISA+ISO+7498-2&as_q=Security
Evolving Operational Continuity
Security Incident Response Teams (OCSIRT)
Capella University "Cyber Threats to Enterprise Security"
TS5070: On-Line Workshop
http://www.acctts.com/trust-factors/Capella%20University%20%20Online%20CyberThreats%20Workshop.htm
Denial of Service Attack Scenario
http://www.tivoli.com/products/index/secureway_risk_mgr/images/intrusion_detection.jpg
When companies experience a denial of service attack, like the ones that wiped out high-profile Web sites this year, security administrators can often become confused by the plethora of event information sent by firewalls and intrusion detection systems.
Tivoli Risk Manager features an advanced correlation engine, based on technology created in IBM's Zurich Research laboratory, that pulls information from various security checkpoints and determines the difference between real attacks and false-positives.
http://www.tivoli.com/products/index/secureway_risk_mgr/
Networking
& IT Systems
Complexity
New products are continually being introduced into the IT marketplace that offer new services or business opportunities.
As businesses try to keep up with innovative technologies and opportunities, integration and manageability issues occur more frequently.
http://www.tivoli.com/bpprogram/programs/tivoliready/
Tivoli leverages its Business Partner Program
Partner organization to ensure other security technologies are integrated with Tivoli Risk Manager.
You can find more information on the value of integrating with Tivoli Risk Manager at
http://www.tivoli.com/products/documents/whitepapers/sway_risk_mgr_wp.pdf
Figure 1.Tivoli
SecureWay Risk
Manager integrates
information from
multiple sources.
Tivoli SecureWay
Risk Manager
Desktops
Web Farm
Tivoli
Firewall
Tivoli
Database
Manager
Tivoli
Public Key
Infrastructure
Server
Router
IDS
Appliance
Directory
Mainframe
|
Profile |
|
Opportunity (Means) |
|
Frequency |
Impacts |
Effective Safeguards |
Proven |
Mandated |
|
|
Insiders :(In-laws?) |
Clueless |
None |
Access & |
Error & |
High |
Low-Med |
|||
|
|
Contractor |
Varies |
Weak |
Exploits Lax |
Unknown |
Med-High |
|||
|
|
Disgruntled |
Get Even |
Insider |
Exploits Lax |
Low-Med |
High |
|||
|
|
Gamers |
Have Fun |
After Hours |
Compromises |
Low |
Med-High |
|||
|
Outsiders :(Outlaws?) |
Script |
Intellectual |
Spare Time |
Freeware |
High |
Low-Med |
|||
|
|
Hacktivist |
Political |
See |
Various |
Unknown |
Med-High |
|||
|
|
Coder / Pro |
Peer |
Lax Software |
Discovers |
Low |
High (Day Zero) |
|||
|
|
Comp Intel & Economic Espionage |
Economic |
Medium |
High |
|||||
|
|
State-Sponsored |
Economic |
Unknown |
High |
|||||
©
2001 by ACCTTS, LLC. All Rights Reserved Worldwide.IE Only Ref:
http://my.octopus.com/view.oce?v=6B3937A27CD749E39C510BCF93ED8934 [ACCTTS-SIRT Selection Support PKM]& http://www.metasecuritygroup.com/research/glossary.html [Glossary of Terns]
|
Risk Factors: |
Type Digital |
Outage |
Outage |
Time- Critical |
Outage |
Protection Policy Pre-Reqs |
Defined SIRT Roles |
Key |
Desired Metrics? |
|
|
Anti-Social |
||||||||
|
|
Deletion (Accidental) |
||||||||
|
|
Denial of Service |
||||||||
|
Destruction |
|||||||||
|
Errors & |
|||||||||
|
Unauthorized Access |
|||||||||
|
Unauthorized Disclosure |
|||||||||
|
Unauthorized |
|||||||||
|
Unauthorized |
|||||||||
|
Network Abuse |
|||||||||
©
2001 by ACCTTS, LLC. All Rights Reserved Worldwide.