national cirt - montenegro · national cirt - montenegro ... readiness assessment report, national...

25
National CIRT - Montenegro “Regional Cybersecurity Forum” Sofia, November 2016 Ministry for Information Society and Telecommunications

Upload: others

Post on 03-Jan-2020

39 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

National CIRT - Montenegro

“Regional Cybersecurity Forum”Sofia, November 2016

Ministry for Information Society and Telecommunications

Page 2: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

CIRT ESTABLISHMENT

• Key Organizations in establishing Montenegro CIRT:• Government of Montenegro – Ministry for Information Society and

Telecommunications• ITU – International Telecommunication Union • IMPACT – International Multilateral Partnership Against Cyber Threats

• Signing of the Administrative Agreement between Government of Montenegro and ITU, July 2011

Page 3: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

CIRT-ME Services

•Incident Handling, Response and Coordination•Security Advisories•Awareness, Training & Education

CIRT-ME Constituency •State authorities•Government authorities•Local authorities• .me domain•Montenegro IP address range

Page 4: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Roles and Responsibilities

National CIRTs can Drive &

Promote

National Cybersecurity Strategies /

PoliciesCyber

Forensics Services

National Public Key

Infrastructure (PKI) / Digital

Signature

Governance / Legislations

Critical Information

Infrastructure Protection

Cybersecurity Awareness Training & Education

Cybersecurity Research

International Cooperation

Security Assurance

Page 5: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed
Page 6: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Legal Framework

• Law on Information Security (currently working on amendments)

• Administrative Agreement between Government of Montenegro and ITU,

Readiness Assessment Report, National CIRT Project Documentation , User

Requirement Specification

• CIRT Policies

• Detailed study on Government Agencies roles against cyber crime

• Cyber Security Strategy 2013-2017

•Methodology for Critical Information Infrastructure

Page 7: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Initial Training & Education

ITU supported trainings:

• Online training held by IMPACT

• Onsite training in Malaysia: “Developing and Implementing a CIRT Team”, held

by IMPACT experts in 2012

• Onsite training in Montenegro - Incident Response training in Montenegro for

representatives from different Government Agencies of Montenegro, held by

IMPACT

• EC-Council (CEH) vouchers,

Page 8: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Implementation

- Implementation stage started in February 2012 - Publishing of www.cirt.me website and RTIR ticketing system, April 2012

Page 9: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

National CIRT Positioning

Page 10: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Cooperation with Government Agencies

National CIRT started the process of establishing local CIRT teams in Montenegro.

• Ministry of Defense, • Ministry of Internal Affairs,• Ministry of Justice, • National Security Agency• Directorate for the Protection of Classified Information • etc.

Page 11: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Cooperation with Private Sector

Key Institutions:

• ISP,• Mobile Operators,• Banking Sector,• Electric Power Industry,• Montenegro Post office• other institutions

Page 12: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

• ITU• IMPACT• ENISA• TRUSTED Introducer• FIRST• CERT/CIRT Network

Page 13: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

CONFERENCE:

ITU, NATO, George C. Marshall European Center for Security Studies

Cyber security - global chalenge of 21st century, Podgorica 2011

Page 14: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

TRAININGS:

ITU, IMPACT,

Cyber drill in Bulgaria „ITU Regional Forum on Cybersecurity for Europe and CIS”, October 2012

Page 15: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

CONFERENCE:

GCSP, CCDCOE (NATO)

Developement of National Cyber Security Framework Manual, Geneve October 2012

Page 16: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

WORKSHOP:

OSCE

„Computer crime”, Bar and Kolasin, June 2013

Page 17: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

WORKSHOP:

NATO, METU

„Cyber crime and terrorism”, Ankara, September 2013

Page 18: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

ACDC, september 2013

Page 19: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

TRAININGS:

ITU

Cyber Drill , Budva, Montenegro, september 2015

Page 20: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

TRAININGS:

Government of Romania, US embassy, ITU, ANCOM

• Broadband for Sustainable Development, Bucharest, april 2015 • Regional cyber security summit, Bucharest, may 2015

Page 21: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

International Cooperation

WORKSHOP:

CISCO systems, US embassy in MN

Cyber threat defence – Podgorica, november 2015

Page 22: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Redesigned CIRT-ME Website

- Published in December 2014

Page 23: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Child Online Protection

Page 24: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Child Online Protection Awareness raising campaign: “Conquer Internet, Surf Wisely”

Page 25: National CIRT - Montenegro · National CIRT - Montenegro ... Readiness Assessment Report, National CIRT Project Documentation , User Requirement Specification •CIRT Policies •Detailed

Thank you for your attention!