Http://@iriss.ie Creating A CERT at WARP Speed.

41
http://www.iriss.ie [email protected] Creating A CERT at WARP Speed

Transcript of Http://@iriss.ie Creating A CERT at WARP Speed.

Page 1: Http://@iriss.ie Creating A CERT at WARP Speed.

http://www.iriss.ie [email protected]

Creating A CERT at WARP Speed

Page 2: Http://@iriss.ie Creating A CERT at WARP Speed.

2004 – The Journey Begins

Copyright © 2010 IRISS www.irissie 2

Page 3: Http://@iriss.ie Creating A CERT at WARP Speed.

What’s Missing?

3Copyright © 2010 IRISS www.irissie

Page 4: Http://@iriss.ie Creating A CERT at WARP Speed.

Situation

4

Knowledge Economy “Silicon Valley” Europe

Over 97% of Irish Businesses are SME<50 Employees and Annual Turnover <€10mEver Increasing Dependence on ICTNo Independent Source of InfoSec information

Economy At RiskNational Security and CNI at RiskLack of Data for Law EnforcementSoft Back Door to UK CNI

Copyright © 2010 IRISS www.irissie

Page 6: Http://@iriss.ie Creating A CERT at WARP Speed.

Stakeholders

6Copyright © 2010 IRISS www.irissie

Page 7: Http://@iriss.ie Creating A CERT at WARP Speed.

Does Ireland Need a CERT?

Do you think Ireland needs a CERT?

82.39%

17.61%

Yes

No

7Copyright © 2010 IRISS www.irissie

Page 8: Http://@iriss.ie Creating A CERT at WARP Speed.

8

Job Complete?

Copyright © 2010 IRISS www.irissie

Page 9: Http://@iriss.ie Creating A CERT at WARP Speed.

9

Estonia Effect

Copyright © 2010 IRISS www.irissie

Page 10: Http://@iriss.ie Creating A CERT at WARP Speed.

10

Job Complete?

Copyright © 2010 IRISS www.irissie

Page 11: Http://@iriss.ie Creating A CERT at WARP Speed.

11

IRISS Is Born

Copyright © 2010 IRISS www.irissie

Page 12: Http://@iriss.ie Creating A CERT at WARP Speed.

Who is IRISS-CERT?

12

Ireland’s First CSIRT(Computer Security Incident Response Team)

Provide Services On Information Security

Services Provided Free of Charge

Not For Profit Organisation

Copyright © 2010 IRISS www.irissie

Page 13: Http://@iriss.ie Creating A CERT at WARP Speed.

Services Offered

Irish Focused Alerts and WarningsVulnerability Awareness Incident AwarenessSanitised Attack NotificationsCoordination Service

Irish Focused ResearchTrends and MetricsGeneral Awareness

Knowledge Sharing Informal discussion Information Sharing & Dissemination

13Copyright © 2010 IRISS www.irissie

Page 14: Http://@iriss.ie Creating A CERT at WARP Speed.

We Serve

Government Bodies and Agencies

Private Sector Companies

SME Sector

Industry Bodies

Other CERTs

14Copyright © 2010 IRISS www.irissie

Page 16: Http://@iriss.ie Creating A CERT at WARP Speed.

16

Sponsors

Copyright © 2010 IRISS www.irissie

Page 17: Http://@iriss.ie Creating A CERT at WARP Speed.

Reaction

17Copyright © 2010 IRISS www.irissie

Page 18: Http://@iriss.ie Creating A CERT at WARP Speed.

The Future

18Copyright © 2010 IRISS www.irissie

Page 19: Http://@iriss.ie Creating A CERT at WARP Speed.

19

Planning Your CERT

Copyright © 2010 IRISS www.irissie

Page 20: Http://@iriss.ie Creating A CERT at WARP Speed.

20

Engage With Stakeholders

Copyright © 2010 IRISS www.irissie

Page 21: Http://@iriss.ie Creating A CERT at WARP Speed.

21

Identify Your Clients

Copyright © 2010 IRISS www.irissie

Page 22: Http://@iriss.ie Creating A CERT at WARP Speed.

22

Identify Services

Copyright © 2010 IRISS www.irissie

Page 23: Http://@iriss.ie Creating A CERT at WARP Speed.

23

Establish Your Requirements

Copyright © 2010 IRISS www.irissie

Page 24: Http://@iriss.ie Creating A CERT at WARP Speed.

24

Identify Tools

Copyright © 2010 IRISS www.irissie

Page 25: Http://@iriss.ie Creating A CERT at WARP Speed.

25

Get Funding & Support

Copyright © 2010 IRISS www.irissie

Page 26: Http://@iriss.ie Creating A CERT at WARP Speed.

26

Practise, Practise, Practise

Copyright © 2010 IRISS www.irissie

Page 27: Http://@iriss.ie Creating A CERT at WARP Speed.

27

Establish the IRT

Copyright © 2010 IRISS www.irissie

Page 28: Http://@iriss.ie Creating A CERT at WARP Speed.

28

Deliver Your Services

Copyright © 2010 IRISS www.irissie

Page 29: Http://@iriss.ie Creating A CERT at WARP Speed.

29

Be Prepared

Copyright © 2010 IRISS www.irissie

Page 30: Http://@iriss.ie Creating A CERT at WARP Speed.

30

Hurdles

Copyright © 2010 IRISS www.irissie

Page 31: Http://@iriss.ie Creating A CERT at WARP Speed.

31

IRISS Is A WARP

Copyright © 2010 IRISS www.irissie

Page 34: Http://@iriss.ie Creating A CERT at WARP Speed.

34

WARP MSP

Copyright © 2010 IRISS www.irissie

Page 35: Http://@iriss.ie Creating A CERT at WARP Speed.

35

WARP MSP

Copyright © 2010 IRISS www.irissie

Page 36: Http://@iriss.ie Creating A CERT at WARP Speed.

36

WARP MSP

Copyright © 2010 IRISS www.irissie

Page 38: Http://@iriss.ie Creating A CERT at WARP Speed.

38Copyright © 2010 IRISS www.irissie

Page 39: Http://@iriss.ie Creating A CERT at WARP Speed.

Why A WARP?

39Copyright © 2010 IRISS www.irissie

Page 40: Http://@iriss.ie Creating A CERT at WARP Speed.

40

More Resources

ENISA - A step-by-step approach on how to set up a CSIRT http://enisa.europa.eu/cert_guide/downloads/CSIRT_setting_up_guide_ENISA.pdf

CERT-in-a-boxhttp://www.govcert.nl/render.html?it=69

Handbook for CSIRTs (CERT/CC)http://www.cert.org/archive/pdf/csirt-handbook.pdf

Forming an Incident Response Teamhttp://www.auscert.org.au/render.html?it=2252

NIST Computer Security Incident Handling Guidehttp://www.securityunit.com/publications/sp800-61.pdf

CSIRT Starter Kit http://www.terena.org/activities/tf-csirt/starter-kit.htmlTrusted Introducer for CSIRTs in Europehttp://www.ti.terena.nl/

Warning Advice and Warning Point (WARP)http://www.warp.gov.uk/

Copyright © 2010 IRISS www.irissie

Page 41: Http://@iriss.ie Creating A CERT at WARP Speed.

Questions ?