1 july 08, 2010 information security officer meeting

30
1 July 08, 2010 Information Security Officer Meeting

Post on 20-Dec-2015

219 views

Category:

Documents


4 download

TRANSCRIPT

Page 1: 1 July 08, 2010 Information Security Officer Meeting

1

July 08, 2010

Information Security Officer Meeting

Page 3: 1 July 08, 2010 Information Security Officer Meeting

Meeting Agenda

----- Topics -----

Opening10 minutes

Topics:

OIS Management Changes

Cyber Exercises – Cyber Storm III

Legislation

2010 Federal Grants

DNSSEC – A technical discussion

ISO Basic Training – It’s for everyone, not just the newbie

Enterprise Information Security Awareness Web Application

Public Scorecard

Policy

90 minutes

Q&A and Closing20 minutes

Page 4: 1 July 08, 2010 Information Security Officer Meeting

4

OIS Management Changes

Page 5: 1 July 08, 2010 Information Security Officer Meeting

5

Cyber Exercises

Page 6: 1 July 08, 2010 Information Security Officer Meeting

6

Cyber Exercises

California Cyber Exercise

August 12, 2010

Page 7: 1 July 08, 2010 Information Security Officer Meeting

7

Cyber Exercises

“The last major cybersecurity exercise conducted by DHS was held in 2008. Cyberstorm III is slated to include a number of international computer emergency readiness teams (CERTS), including representatives from Australia, New Zealand, Canada and the United Kingdom. Officials from Japan and nine European nations have also been invited to participate.

Previous Cyberstorm exercises focused on attacks attempting to take down the Internet or spread malicious software on high priority government systems. Cyberstorm III is expected to test the processes and roles in place while simulating a cyberattack against the underlying control systems of country's critical infrastructure – power grids, dams and systems that protect energy facilities.”

-- 15 Jun 2010 | SearchSecurity.com

CyberStorm III

Page 8: 1 July 08, 2010 Information Security Officer Meeting

8

Legislation

Page 9: 1 July 08, 2010 Information Security Officer Meeting

9

Pending Legislation

AB 1899

• Transparency.

• State agencies to post specific audit information.

• OCIO and DGS to post specific summary information regarding contracts awarded to the state.

• Governor's Office to post specific financial information.

Page 10: 1 July 08, 2010 Information Security Officer Meeting

10

Pending Legislation

AB 2091

• Public Records Act (PRA) exemption.

• Information Security records that would reveal vulnerabilities or would increase the potential for an attack on an information system.

• A very limited and targeted exemption.

Page 11: 1 July 08, 2010 Information Security Officer Meeting

11

Pending Legislation

AB 2408

• Governor’s Reorganization Plan clean-up bill

• Codifies Executive Order S-10-03

• Name change – OCIO to California Technology Agency

• Extends the OCIO’s sunset set date from 2013 to 2015

Page 12: 1 July 08, 2010 Information Security Officer Meeting

12

Pending Legislation

AB 1055

• State Chief Information Officer - fingerprints and criminal history checks.

• OCIO employees and contractors that have access to sensitive or confidential information.

• Conviction of crimes related to dishonesty, fraud, or deceit and is substantially related to the duties of the person.

• There is an appeals process.

Page 13: 1 July 08, 2010 Information Security Officer Meeting

13

2010 Federal Grants(Proposed)

OIS Grant Requests

• Threat Vulnerability Management Program

• Enterprise Vulnerability Assessment Service

• Statewide PCI Compliance

• CA Information Sharing and Analysis Center

• State and Local Government Training

• Content Learning Management System

Page 14: 1 July 08, 2010 Information Security Officer Meeting

14

2010 Federal Grants(Proposed)

• Online Incident Management System

• Enterprise Certificate Authority

• Enterprise Disaster Recovery

• Forensics Lab

• Enterprise Security Operations Center

Endorsement Letter for OIS Grant Request and Commitment for Joint Participation on Awarded Projects

Page 15: 1 July 08, 2010 Information Security Officer Meeting

15

SecureDNS - DNSSEC

Page 16: 1 July 08, 2010 Information Security Officer Meeting

16

SecureDNS - DNSSEC

Page 17: 1 July 08, 2010 Information Security Officer Meeting

17

SecureDNS - DNSSEC

Page 18: 1 July 08, 2010 Information Security Officer Meeting

18

SecureDNS - DNSSEC

Page 19: 1 July 08, 2010 Information Security Officer Meeting

19

… ca.gov

… state.ca.us

SecureDNS - DNSSEC

The DNSSEC project is an 18+ month, $1.353 million, federally funded project that will advance the integrity and availability for California’s Internet capabilities.

All entities that use one of the zones named above for either world wide web or email addressing will need to stay informed and involved.

Page 20: 1 July 08, 2010 Information Security Officer Meeting

20

SecureDNS - DNSSEC

End-State:

• A functional DNS governance program and oversight committee.

• California DNS infrastructure that is capable of signing DNS requests.

• The sub-domains with “ca.gov” and “state.ca.us” will all have been vetted for appropriateness and only

those approved and fully documented will remain active.

Page 21: 1 July 08, 2010 Information Security Officer Meeting

21

SecureDNS - DNSSEC

End-State (continued):

• All State of California entities that host internal DNS services will have the necessary technology to

support DNSSEC.

• A comprehensive DNS management process, complete with procedures and standards, will be operational.

Page 22: 1 July 08, 2010 Information Security Officer Meeting

22

SecureDNS - DNSSEC

What will the project need from departments?

• A point of contact at your department.

• Where necessary, hardware refresh.

• Software to manage DNS signing keys.

• Time to test and test, then test some more.

• Commitment.

Page 23: 1 July 08, 2010 Information Security Officer Meeting

23

SecureDNS - DNSSEC

• This is not only a technology project, it is also an enterprise governance project.

• This project will impact not only state entities, it will require commitment of time from counties and cities.

• Testing will be the most important phase of the SDLC.

• Service interruptions are unacceptable.

Page 24: 1 July 08, 2010 Information Security Officer Meeting

24

ISO Basic Training

• Six to seven hours of in-person training on OIS’ expectations for all ISOs and Agency ISOs.

• Required for all new ISOs.

• Required for all current ISOs in management or supervisor classifications.

• The first class will be held July 15th at 1325 J Street.

• This class will help establish future curriculum.

• There will be an annual refresher course (also required).

Page 25: 1 July 08, 2010 Information Security Officer Meeting

25

Enterprise Information Security Awareness Web Application

Page 26: 1 July 08, 2010 Information Security Officer Meeting

26

Public Scorecard

Page 27: 1 July 08, 2010 Information Security Officer Meeting

27

Public Scorecard

http://www.cio.ca.gov/OIS/Government/activities_schedule.asp

Page 28: 1 July 08, 2010 Information Security Officer Meeting

28

Public Scorecard

• There will be no surprises. You and your management will be fully aware of the scores before publication.

• First Scorecard will be published on our website in late July 2010.

Page 29: 1 July 08, 2010 Information Security Officer Meeting

29

Future Policies

• Security Reporting Scorecard Policy Letter

• Infrastructure Consolidation Scorecard

• Cloud Computing

• Privacy

Page 30: 1 July 08, 2010 Information Security Officer Meeting

30

Questions