ictwg-ecprd seminar 2006 information security issues at the chamber of deputies carlo simonelli head...

9
ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department – Chamber of Deputies Vilnius, 6th October 2006 1

Upload: charlene-lawrence

Post on 26-Dec-2015

213 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

ICTWG-ECPRD SEMINAR 2006

INFORMATION SECURITY ISSUES AT THE

CHAMBER OF DEPUTIES

Carlo SimonelliHead of Unit – ICT Systems and User Support

ICT Department – Chamber of Deputies

Vilnius, 6th October 2006 1

Page 2: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

OVERVIEW

Information System Security “Documento programmatico sulla

sicurezza dei dati” (Programmatic Data Security Document)

Risk analysis carried out for the Programmatic Data Security Document

Other contents of the Document Internet redundant links Projects for improving information

system security2

Page 3: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

INFORMATION SYSTEM SECURITY

Information System Security at the Chamber of Deputies during the past years

Security procedures difficult to be implemented

3

Page 4: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

PERSONAL DATA PROTECTION CODE

Internet, Electronic mail and always-on era required more effort in information security

Implementing “Personal Data Protection Code” (Decreto Legislativo n. 196, 2003)

4

Page 5: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

PROGRAMMATIC DATA SECURITY DOCUMENT

First edition of “Documento programmatico sulla sicurezza dati” (Programmatic Data Security Document)

The “Register of IT systems” is a prerequisite

The two parts of the Document1. Analytic review of all data treatments

2. Rules for managing personal and sensitive data and general instruction to protect the information systems 5

Page 6: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

RISK ANALYSIS AND ASSESSMENT

ISO/IEC 17799 (now ISO/IEC 27799:2005) and other information security standards

Risk exposure level established for 51 data bases with sensitive data and for 77 data bases with personal data

Activities this year on sensible data6

Page 7: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

BENEFITS OF THE DOCUMENT

Joint activities improving information security

Important managing procedures Procedures for managers and employees

Duration of data stored online and offline

Who is in charge of deleting data

Managing backups and logs

Data ciphering

Password characteristics and expiration

Training of managers and employees7

Page 8: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

IMPROVING INTERNET LINK SPEED AND AVAILABILITY

8

Page 9: ICTWG-ECPRD SEMINAR 2006 INFORMATION SECURITY ISSUES AT THE CHAMBER OF DEPUTIES Carlo Simonelli Head of Unit – ICT Systems and User Support ICT Department

IMPROVING INFORMATION SYSTEM SECURITY

PKI system for digital signatures Smart cards for strong

authentication of employees New projects

MPs VPN SSL authentication and profiling; use of tokens

Protocol 802.1x for administrative user workstation connection

9