430 likes | 840 Views
Information Security. The CIA Triad. Confidentiality. The state of being secret. Security. Integrity. Availability. Present and ready for use. The state or quality of being entire or complete. The Job. http://technet.microsoft.com/en-us/library/cc723507.aspx. Agenda. Some Threats
E N D
The CIA Triad Confidentiality The state of being secret Security Integrity Availability Present and ready for use The state or quality of being entire or complete
The Job http://technet.microsoft.com/en-us/library/cc723507.aspx
Agenda • Some Threats • Some Controls
San Francisco – Terry Childs http://articles.sfgate.com/2008-12-27/bay-area/17133065_1_computer-network-mr-childs-passwords
UBS – Roger Duronio http://www.cbsnews.com/stories/2002/12/18/tech/main533450.shtml
Australia – Vitek Boden This file is licensed under the Creative Commons Attribution-Share Alike 2.5 Generic license “…marine life died, the creek water turned black and the stench was unbearable for residents…” - Australian EPA
Waheed Mahmood http://news.bbc.co.uk/
Where is Security? • IT Security? • Information Security? • Physical Security? • Business Security? Business Assurance?
Some Problems • IT Vendors • People – IT, employees, others … • Complexity • Technology • Control Systems • Anyone who thinks that I am responsible for Information Security
Agenda • Some Problems • Some Solutions
Security Golden Rules • Accept Challenges • Display Your Badge • Assess Risks • Protect Your Identity • Thirty Minute Rule - 22 -
Security Program • Risk Management • Policy … Standards • Business Engagement • Culture / Behaviour Change • Security Architecture • Metrics and Measurements • Management System • Money / Staff • Controls
Further Reading • Bruce Schneier • SANS Internet Storm Centre / Newsbites • SecurityFocus • Titan Rain • Advanced Persistent Threat • Jericho Forum
Reading List • Ross Anderson: Security Engineering • Bruce Schneier: Secrets & Lies