critical infrastructure protection (cip)...mohamed ahmed abd el haleem email: [email protected]...

18
Regional Forum on Cybersecurity in the Era of Emerging Technologies & the Second Meeting of the “Successful Administrative Practices”-2017 Cairo, Egypt 28-29 November 2017 Critical Infrastructure Protection (CIP) by Mohamed Abd El Haleem CCISO, CEH, CHFI, ECSA ISO27001LA, ISO PENTEST, ISO/IEC 38500 Lead Corporate Governance Manager, CERTIFIED Lead SCADA Security Professional

Upload: others

Post on 14-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Regional Forum on Cybersecurity in the Era of Emerging Technologies &

the Second Meeting of the “Successful Administrative Practices”-2017 Cairo, Egypt 28-29 November 2017

Critical Infrastructure Protection(CIP)

by

Mohamed Abd El Haleem

CCISO, CEH, CHFI, ECSA

ISO27001LA, ISO PENTEST, ISO/IEC 38500 Lead Corporate Governance Manager, CERTIFIED Lead

SCADA Security Professional

Page 2: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Critical Infrastructure Protection(CIP)

Page 3: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Critical infrastructure is an asset or system which is essential for themaintenance of vital societal functions. The damage to a criticalinfrastructure, its destruction or disruption by natural disasters, terrorism,criminal activity or malicious behaviour, may have a significant negativeimpact for the security of the EU and the well-being of its citizens.

Critical Infrastructure Protection(CIP)

Page 4: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Defining Industrial

Control Systems

Page 5: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Defining OT and

IT

Page 6: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

NIST CyberSecurity

Framework

Page 7: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS
Page 8: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Top Practices To Secure

The Industrial Control

System (ICS)

Page 9: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

1. Threat Modeling

Page 10: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

4. Honeypots

Page 11: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

5. Vulnerability Management

Page 12: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

6. Penetration Testing

Page 13: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

8. Configuration Hardening

Page 14: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

7. Source Code Review

Page 15: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

10.Strong Authentication

Page 16: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

9. Encryption

Page 17: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS
Page 18: Critical Infrastructure Protection (CIP)...Mohamed Ahmed Abd El Haleem Email: mohamedhaleem2@msn.com Mob.: 0100 440 2408 Linkedin: Mohamed Abd ElHaleem 1992 2017 CELEBRATING 25 YEARS

Mohamed Ahmed Abd El Haleem

Email: [email protected]

Mob.: 0100 440 2408

Linkedin: Mohamed Abd ElHaleem