Transcript
Page 1: Janet, Security & ESISS

Janet, Security & ESISS

September 2013

Page 2: Janet, Security & ESISS

Janet, Security & ESISS

• Janet and Security• An introduction to ESISS• New services• What won’t be changing• Q&A

Page 3: Janet, Security & ESISS

Janet and Security

• Operates CSIRT• Works with UK Gov’t Cabinet Office and Cyber security Information Sharing

Partnership (CISP), collaborating as required.• Presence on UK e-Infrastructure Leadership Council and Security stream• Range of products including server certificates• Increasingly investing in security projects (recent funding on threat

information service)• Reviewing ISO27001

• And… Janet ESISS

Page 4: Janet, Security & ESISS

Janet ESISS

• From August 1st, Janet will be taking on the operations of ESISS..

• Now some history...

Page 5: Janet, Security & ESISS

A Shared Issue

•The same challenges

•Different resources

•Desire to collaborate

Page 6: Janet, Security & ESISS

One Shared Service

Page 7: Janet, Security & ESISS

Incorporating into Janet

Service Manager: Wally Jackson

Janet

Operations

ESISSCSIRT

• Share Service Manager• Share skills between teams• Roadmap not shared• Targets not shared• New Business Processes!

Based in Loughborough

University

Based in Janet Offices, Harwell

Product Managem

ent

Strategic Technolog

ies

Page 8: Janet, Security & ESISS

The Initial Services

• Automated Penetration Testing• Manual Penetration Testing• Consultancy• 6 month review for other services

Page 9: Janet, Security & ESISS

Automated Penetration Testing

• On demand testing for potential vulnerabilities on external systems and websites

• Testing is specifically designed to check for the most common vulnerabilities

• Continuously updated vulnerability database• Easy to use web interface for management of scanning and reporting• Provides remediation advice on securing vulnerabilities

Page 10: Janet, Security & ESISS

SECTION HEADING

Page 11: Janet, Security & ESISS

Manual Penetration Testing

• Manual testing by experienced and certified testers, carried out to industry standards

• Team members have wide experience of common educational applications• A complete service from scoping, project management, through to testing

and reporting• Report provides executive overview, graphical summary and detailed

analysis

Page 12: Janet, Security & ESISS

Consultancy

• Janet has had the skills internally, however has lacked the route• Supporting the outcomes from penetration testing• ... also providing support for security issues arising from the work of CSIRT• ... and other security work, best practises, security management incident

response training

Page 13: Janet, Security & ESISS

Key Points

• Service as normal for existing ESISS customers, including price• Same certified testing team• For the sector, by the sector• Several new contracts since taking ESISS into Janet

Page 14: Janet, Security & ESISS

WHY?

• How does penetration testing help your organisation?

• Part of an audit: security, IT, financial

• Compliance: PCI-DSS, data protection

• To improve your security

Page 15: Janet, Security & ESISS

PENETRATION TESTING AS A CONTROL

• Penetration testing won’t make a system 100% secure (nothing will)

• Reduces the likelihood that the system can be compromised, and so reduces the risk

• Demonstrates a certain standard of care towards your information

Page 16: Janet, Security & ESISS

HOW SHOULD IT BE USED

• Perhaps around your most sensitive assets and applications• When new applications are first deployed• As part of the QA and release processes for software development.

• When needed - on demand• Scheduled - check for unexpected changes, new vulnerabilities

• A mix of the above depending on the risks

Page 17: Janet, Security & ESISS

Any Questions

Page 18: Janet, Security & ESISS

THANK YOUJanet, Lumen House

Library Avenue, Harwell Oxford

Didcot, Oxfordshire

t: +44 (0) 1235 822200

f: +44 (0) 1235 822399

e: [email protected]


Top Related