1 / 14

John Kanalis, CCO BECCA Europe Administrator Authorized BECCA Instructor www.BECCA-online.org jkanalis@otenet.

Conscience is a mother-in-law whose visit never ends. H.L . Mencken . Presentation for the Workshop on Developing National Critical Infrastructure Protection in Serbia Role of Private Security Companies BELGRADE -SERBIA. John Kanalis, CCO BECCA Europe Administrator

bayard
Download Presentation

John Kanalis, CCO BECCA Europe Administrator Authorized BECCA Instructor www.BECCA-online.org jkanalis@otenet.

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Conscience is a mother-in-law whose visit never ends. H.L. Mencken Presentation for the Workshop on Developing National Critical Infrastructure Protection in Serbia Role of Private Security Companies BELGRADE -SERBIA John Kanalis, CCO BECCA Europe Administrator Authorized BECCA Instructor www.BECCA-online.org jkanalis@otenet.gr becca eu@otenet.gr We focus on Human Factor

  2. Critical Infrastructure Protection (CIP) & How to Safeguard Sensitive Business Information QUESTIONS & ANSWERS "If your only tool is a hammer, you tend to see every problem as a nail." • Abraham Maslow

  3. What means Sensitive Business Information (SBI) in CIP? • Sensitive critical infrastructure protection related information, means facts about a critical infrastructure, which if disclosed could be used to plan and act with a view to causing disruption or destruction of critical infrastructure installations, Council Directive 2008/114/EC, Article 2d • butin simple words sensitive business information are • (i) Technical Information. (ii) Business and Commercial Information. (iii) Miscellaneous Information and Documentation.

  4. So,what covers basic concepts and principles that address thesecurity-related issue of safeguarding SBI? The collection of approaches that address issues covering physical, electronic, administrational, and procedural aspects of critical/sensitive business information protection and which insure that no breaches of this critical/sensitive business information will occur. "Fortuna audaces juvat (Luck helps the brave)"Publius Vergilius Maro

  5. What means Confidentiality? Confidentiality refers to limits on who can get what kind of information. Confidentiality is an ethical or professional duty not to disclose information to a third party. Confidentiality may apply because of the legal or ethical requirements of certain professionals(Private Security Companies),board members, staff and visitors that are legally required to keep certain sensitive/critical business information confidential. This legal obligation exists even though any contracts or other documents related to confidentiality may not have signed. "I didn’t forget your advice, but Nature forces me to have my opinion" Aeschylus

  6. Is Confidentiality a toolbox?"In theory there is no difference between theory and practice. In practice there is". Lawrence Peter "Yogi" Berra-- Yogi Berra Confidentiality applied as a stand- alone process can help identify whether complete pathways exist that link to a potential "window of opportunity". The need for confidentiality exists when information is designated as “confidential” (e.g. stamped or announced). It also applies where the need for it is obvious or evident (nature of the material or context of the situation), or required by applicable law, even though the information is not specifically designated as confidential. Confidentiality as an applied countermeasure to safeguard sensitive information (single most valuable asset) is a reflection of a wide variety of protection techniques due to the number of espionage techniques that exist.

  7. Why implement Confidentiality? "History is Philosophy learned from examples" Thucydides  To create and sustain a mature risk management environment  To enable and develop a results-oriented approach to security risk management To avoid unnecessary costs (Losses) and make quick responses as crisis arise. To establish a good internal management control system To protect critical information assets throughout an enterprise because security is a journey rather than a one-time event “Management refers to the process of getting things done, effectively and efficiently through other people” • David A. DeCenzo,PhD, Stephen P. Robbins,PhD, • Human Resource Management, 7th Edition

  8. What the Toolbox contains?(Indicative)  The Four Faces of Business Espionage The Confidentiality Survey  The Laws of Confidentiality The Business Confidentiality Management Process & sub processes The Five Steps of Direct Approach Process  The Business Confidentiality Gap  Awareness  etc • "We spend all our time searching for security, and then we hate it when we get it ". John Ernst Steinbeck

  9. Andwhy absence of guarding measures for SBI leads to Espionage? Because as it has been proved byBECCA, the basic trigger for someone to exercise espionage is that; "if you have a product or service to sell, you have something worth stealing" BECCA:Business Espionage Controls & Countermeasures Association www.BECCA-online.org • "There is always more spirit in attack than in defense." • Titus Livius Patavinus

  10. What is Business (Industrial /Economic) Espionage? “The term Industrial Espionage refers to the practice of obtaining business or technological information through surreptitious means” (Grolier Multimedia Encyclopedia). Most definitions and discussions concerning business espionage will likely be under the heading of “economic espionage” or “industrial espionage”. "There's no sense in being precise when you don't even know what you're talking about". John von Neumann

  11. But, why people spy?"If everybody is thinking alike, then nobody is thinking". George S. Patton BECCA members answering the question found four driving forces at work today in private and public sectors, in the following order of importance; MONEY  ADVENTURE  IDEALISM •  ALIENATION "To see what is in front of one's nose needs a constant struggle". • George Orwell

  12. Finally, security is about what?"The best way to have a good idea is to have lots of ideas."Linus Pauling Fundamentally, security is about people. It’s not really computers that are breaking into different systems, its people. It’s your adversaries. It’s often actually your insiders, people that work for you. So understanding the motivation of those people and, I believe, training your people -people you trust, people that works for you, yourself, your employees, your contractors- to be proactive about security is one of the very best paths you can take to maintaining a good security stance.

  13. And because CONFIDENTIALITYis an old but often forgotten preventative strategy lets remember what Nicholas Machiavelli said about initiating changes;"… there is nothing more difficult to arrange, more doubtful of success, more dangerous to carry through than initiating changes...The innovator makes enemies of all those who prosper under the old order, and only lukewarm support is forthcoming from those who would prosper under the new. Men are generally incredulous, never really trusting new things unless they have tested them by experience.“

  14. Similia Similibus ServienturSimilar will be served by SimilarThank you all for your kind attention

More Related