SlideShare ist ein Scribd-Unternehmen logo
1 von 15
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Enterprise Security Management
Protection Profiles:
An Implementation Plan
September 2009
Eric Winterton, Booz | Allen| Hamilton
Joshua Brickman, CA Inc.
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
2
Agenda
- Review
- Enterprise Security Management—what are
these products?
-Categories
-Methodology
- Schedule
- Communication Plan
- Risks/Beta/Roll-out
- How can you get involved (Participants)
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
3
How did we got here?
-2008 Proposal (Winterton/Brickman)
-Approach
-Consensus
-All Participating Countries
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Enterprise Security Management
4
Standardized
logging
Compliance
&
configuration
Identity
Management
Monitoring
&
response
Policy/Access
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
What Products Make Up ESM?
CA Identity
Manager
CA GRC Manager CA Siteminder CA Auditor for z/OS CA Enterprise Log
Manager
SC Operations
Manager, SC
Configuration
Manager & SC VMM
SC Operations
Manager, SC
Configuration
Manager, SC
Essentials
SC Operations
Manager &
SC Essentials
SC Operations
Manager*
Symantec Alteris Symantec CCS/FTK Symantec Alteris Symantec SSIM Symantec Alteris
EMC RSA Access
Manager
EMC RSA Envision EMC RSA Envision
Oracle Identity
Manager
Oracle Enterprise
Manager
Oracle Access
Manager
Oracle Audit Vault Oracle Audit Vault
IBM Tivoli Identity
Manager
IBM Tivoli
Compliance Insight
Manager (TCIM) ,
Security
Information Event
Manager (TSIEM)
IBM Tivoli Unified
Single Sign-On ,
Tivoli Security
Policy Manager
IBM Common Audit
and Reporting
(CARS) & TCIM
5
Identity
Management Compliance
and
configuration
Policy/Access
Monitoring
and
response
Standardized
logging
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
6
Approach
ID CC
Gaps for
ESM
Start
Establish
Industry
Team and
Select Lab
Created
ESM Product
Categories
Collected
Products
and Data
Define next
level of Use
Cases
Develop
Global
Threat
Analysis
Select
Protection
Profile
Establish
High-level
Spec for PP
Develop PP
Verify (QA)
on PP
Publish PP
Draft for
Public
Comment
Declare PP
Status
(Global
Conference)
Publish PP
PPs
Complete?
Stop
No
Yes
Publish PP
Draft for
Public
Comment
Completed as of Sept 09
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
7
Cause and Effect/Fishbone
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
8
Timeline so far
- Sept 2008 Proposal
- Received well at 9th ICCC--interest by multiple
vendors, NIAP, consultants and other schemes
- May 2009: NIAP pledges support for creation of
the ESM PP’s.
- May-Aug 2009: Concurrence of ESM product
categories among Microsoft, IBM, EMC, Oracle
Symantec, Ricoh, and CA Inc solidified
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Implementation Plan
9
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Communication Plan
- Comment Periods
-Posted on official sites
-Allow for anyone to provide feedback
- CCVF
- ICCC and RSA
10
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Participation to Date
- You can be a part of this team
- The more participants the better the quality
11
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Joshua Brickman, PMP
CA, Inc.
Program Manager, Federal Certifications
(508) 628-8917
Joshua.Brickman@ca.com
Q & A
12
Eric Winterton, CISSP
Booz | Allen | Hamilton
CCTL Director
(410) 684-6691
winterton_eric@bah.com
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
13
Backup Slides
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Impact to Effort Matrix
14
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
All Products in ESM
15

Weitere ähnliche Inhalte

Kürzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Kürzlich hochgeladen (20)

Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 

Empfohlen

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Empfohlen (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

Enterprise security management protection profiles an implementatiion plan final

  • 1. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Enterprise Security Management Protection Profiles: An Implementation Plan September 2009 Eric Winterton, Booz | Allen| Hamilton Joshua Brickman, CA Inc.
  • 2. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 2 Agenda - Review - Enterprise Security Management—what are these products? -Categories -Methodology - Schedule - Communication Plan - Risks/Beta/Roll-out - How can you get involved (Participants)
  • 3. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 3 How did we got here? -2008 Proposal (Winterton/Brickman) -Approach -Consensus -All Participating Countries
  • 4. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Enterprise Security Management 4 Standardized logging Compliance & configuration Identity Management Monitoring & response Policy/Access
  • 5. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. What Products Make Up ESM? CA Identity Manager CA GRC Manager CA Siteminder CA Auditor for z/OS CA Enterprise Log Manager SC Operations Manager, SC Configuration Manager & SC VMM SC Operations Manager, SC Configuration Manager, SC Essentials SC Operations Manager & SC Essentials SC Operations Manager* Symantec Alteris Symantec CCS/FTK Symantec Alteris Symantec SSIM Symantec Alteris EMC RSA Access Manager EMC RSA Envision EMC RSA Envision Oracle Identity Manager Oracle Enterprise Manager Oracle Access Manager Oracle Audit Vault Oracle Audit Vault IBM Tivoli Identity Manager IBM Tivoli Compliance Insight Manager (TCIM) , Security Information Event Manager (TSIEM) IBM Tivoli Unified Single Sign-On , Tivoli Security Policy Manager IBM Common Audit and Reporting (CARS) & TCIM 5 Identity Management Compliance and configuration Policy/Access Monitoring and response Standardized logging
  • 6. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 6 Approach ID CC Gaps for ESM Start Establish Industry Team and Select Lab Created ESM Product Categories Collected Products and Data Define next level of Use Cases Develop Global Threat Analysis Select Protection Profile Establish High-level Spec for PP Develop PP Verify (QA) on PP Publish PP Draft for Public Comment Declare PP Status (Global Conference) Publish PP PPs Complete? Stop No Yes Publish PP Draft for Public Comment Completed as of Sept 09
  • 7. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 7 Cause and Effect/Fishbone
  • 8. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 8 Timeline so far - Sept 2008 Proposal - Received well at 9th ICCC--interest by multiple vendors, NIAP, consultants and other schemes - May 2009: NIAP pledges support for creation of the ESM PP’s. - May-Aug 2009: Concurrence of ESM product categories among Microsoft, IBM, EMC, Oracle Symantec, Ricoh, and CA Inc solidified
  • 9. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Implementation Plan 9
  • 10. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Communication Plan - Comment Periods -Posted on official sites -Allow for anyone to provide feedback - CCVF - ICCC and RSA 10
  • 11. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Participation to Date - You can be a part of this team - The more participants the better the quality 11
  • 12. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Joshua Brickman, PMP CA, Inc. Program Manager, Federal Certifications (508) 628-8917 Joshua.Brickman@ca.com Q & A 12 Eric Winterton, CISSP Booz | Allen | Hamilton CCTL Director (410) 684-6691 winterton_eric@bah.com
  • 13. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 13 Backup Slides
  • 14. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Impact to Effort Matrix 14
  • 15. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. All Products in ESM 15