SlideShare ist ein Scribd-Unternehmen logo
1 von 25
Downloaden Sie, um offline zu lesen
European Cyber
Security Organization
POLNOG’20, Warszawa, 19-20.03.2018
Janusz Pieczerak (Orange Labs)
Lessons learned
Orange Labs2
Orange Labs3
Orange Labs4
Co robić ???
 POLITYKA
 OPERACJE
 BADANIA i ROZWÓJ
 STANDARYZACJA
 CERTYFIKACJA
 ZNAKOWANIE
Jak żyć ???
Orange Labs5
Polityka
Orange Labs6
Orange Labs7
EU Cybersecurity certification framework
Orange Labs8
Certyfikacja …
Orange Labs9
Badania i rozwój (R&I)
 Programy ramowe (FP), HORIZON 2020
 Cele (KPI)
 Partnerstwo publiczno prywatne (PPP)
 Styczeń 2016: Komisja Europejska (EC) uruchamia Cybersecurity
cPPP
 Czerwiec 2016: Europejska Organizacja Cyberbezpieczeństwa (ECSO
– Association)
https://www.ecs-org.eu/
 450 mEUR z budżetu H2020, oczekiwany poziom inwestycji sektora
prywatnego 1300 mEUR
 Strategiczny Plan Badań i Rozwoju (SRIA)
Orange Labs10
ECS - cPPP Partnership Board
(monitoring of the ECS cPPP - R&I priorities)
EUROPEAN
COMMISSION
ECSO –Board of Directors
(Management of the ECSO Association: policy/market actions)
R&I
ECSO General Assembly
INDUSTRIAL POLICY
Coordination / Strategy Committee
WG 1
Standardisation /
certification /
labelling / supply
chain management
WG 2
Market deployment
/ investments /
international
collaboration
WG 3
Sectoral Demand
(Industry 4.0; Energy;
Transport; Finance;
eGov; Health; Smart
Cities; Telecom/media )
WG 4
Support to SMEs
and REGIONS
(in particular
East EU)
WG 5
Education,
training, cyber
ranges, awareness
WG 6
Strategic Research &
Innovation Agenda
Technologies,
Products & Services
SME solutions /
services providers;
local / regional SME
clusters and
associations Startups,
Incubators /
Accelerators
Large companies
Solutions / Services
Providers; National
or European
Organisation /
Associations
Regional / Local
administrations
(with economic
interests); Regional
/ Local Clusters of
Solution / Services
providers or users
Public or
private users /
operators:
large
companies
and SMEs
National Public
Authority
Representatives
Committee
R&I Group /
Policy Advisory
Group (GAG)
Others
(financing
bodies,
insurance,
etc.)
Research Centers
(large and
medium / small),
Academies /
Universities and
their Associations
Governance
WORKING GROUPS & TASK FORCES
WG 1
Standardisation
Certification /
Labelling / Supply Chain
Management
WG 2
Market deployment /
investments /
international collaboration
WG 3
Sectoral demand
(vertical market applications:
Industry 4.0; Energy;
Transport; Finance; eGov;
Health; Smart Cities;
Telecom/media )
WG 4
Support SME, REGIONS and
coordination with local
bodies (in particular East EU)
WG 5
Education, training,
awareness,
cyber ranges
WG 6
Strategic Research &
Innovation Agenda (SRIA)
Technologies, Products &
Services
Orange Labs13
Europejski certyfikat bezpieczeństwa
 Obowiązkowy czy dobrowolny
 Koszty
 Czas ważności
 Przyznawanie
 Odnawianie
 Monitorowanie
 Co ?
 Jak ?
 Kto ?
 Gdzie ?
 Kiedy ?
 Dlaczego ?
Ogólna koncepcja klasyfikacji certyfikatu
cyberbezpieczeństwa (wg ECSO)
14
15
Cybersecurity Act: levels proposed
Assurance
Level
Definition proposed
Basic Provides a limited degree of confidence in the claimed or asserted
cybersecurity qualities of an ICT product or service, and is characterized with
reference to technical specifications, standards and procedures related
thereto, including technical controls, the purpose of which is to decrease the
risk of cybersecurity incidents.
Substantial Provides a substantial degree of confidence in the claimed or asserted
cybersecurity qualities of an ICT product or service, and is characterized with
reference to technical specifications, standards and procedures related
thereto, including technical controls, the purpose of which is to decrease
substantially the risk of cybersecurity incidents.
High Provides a higher degree of confidence in the claimed or asserted
cybersecurity qualities of an ICT product or service than certificates with the
assurance level substantial, and is characterized with reference to technical
specifications, standards and procedures related thereto, including technical
controls, the purpose of which is to prevent cybersecurity incidents.
16
Risk assessment: impact levels and relevant
factors mapping
Level of
impact
Attributes Weighting factors
Privacy Confidenti
ality
Integrity Availa
bility
Authenti
city
Safety Reputatio
n and
financial
loss
High
Disclosure
of
biometric
data
Disclosure of
classified IP
System
behaves
different
than
expected
Compl
ete
DoS
Impersona
tion
Death or
permanent
environment
al damage
Break of
business
Substan-
tial
Disclosure
of any
other
personal
data
Disclosure of
any other
information
Some
functionali-
ties features
impacted
Partial
DoS
Impossible
to verify
authentici
ty
Injury or
remediable
environment
al damage
Long term
impact
Basic No
disclosure
of data
No disclo-
sure of
information
No feature is
impacted
No
impact
No impact No harm No impact
17
Possible mapping of levels
Levels of
assurance in the
Cybersecurity
Act
Levels of
assurance from
the ECSO’s
meta-scheme
Levels of
assurance from
the ECSO’s meta-
scheme (alt.)
Body performing
the evaluation
High
A Ag National
(governmental)
body
B A
3rd party
evaluation facility
(lab)
Substantial C B
Basic
D Ce
E Ci Self-evaluation
Orange Labs18
ECSO WG1 - 135 members
Standardization, certification, labelling and supply chain
 Structure
– SWG 1.1 Products & components manufacturers
– SWG 1.2 ICT infrastructure operators (chaired byOrange)
– SWG 1.3 Users, Integrators and other service providers
– SWG 1.4 Basic Layer
 Deliverables:
 Challenges of the Industry (COTI)
- Collection of member’s views
 State-of-the-Art Syllabus (SOTA)
- Standards and certification schemes
 Certification Meta Scheme Approach
- Certification framework proposal
Orange Labs19
ECSO WG2 - 41 members
Market deployment
 Structure
– SWG 2.1 Market development, products and stakeholders
– SWG 2.2 Investments, innovative business models
– SWG 2.3 International cooperation, global competetiveness and support to
export
– SWG 2.4 Dissemination and awareness, events
Orange Labs20
ECSO WG3 - 123 members
Sectoral demand
 Structure
– SWG 3.1 Digitalisation of the European Industry (including Industry 4.0) and ICS;
– SWG 3.2 Energy (oil, gas, electricity), and Smart Grids;
– SWG 3.2 Transportation (road, rail, air, sea, space);
– SWG 3.4 Banks and Financial Services, ePayments and Insurance;
– SWG 3.5 Public Services, eGovernment, Digital Citizenship;
– SWG 3.6 Healthcare;
– SWG 3.7 Smart Cities and Smart Buildings (convergence of digital services for Citizens) and
other Utilities;
– SGW 3.8 Telecom, Media and Content
 Deliverables (landscape, user engagement, sector specifics, market study):
 2018_SWG3.1Industry4.0andICS_sectorreport_final_v0.1
 2018_SWG3.4FinancialServicesInsurance_sectorreport_final_v0.1
 2018_SWG3.6Healthcare_sectorreport_final_v0.1
 2018_SWG3.7Smartcities_sectorreport_final_v0.1
Orange Labs21
ECSO WG4 - 23 members
Support to SME and regions
 Structure
– SWG 4.1 SMEs, start-ups and high growth companies
– SWG 4.2 Coordination with activities in EU countries and regions
– SWG 4.3 Support to East EU Members
 WG4_Deliverable_Positionpaper_Consolidated_VF
 Support to SME’s, coordination with countries (in particular East EU) and
regions
Orange Labs22
ECSO WG5 - 98 members
Education, training, awareness, exercises
 Structure
– TF 5.0.1 EHR4CYBER Task Force
– SWG 5.1 Cyber Range environments and technical exercises
– SWG 5.2 Education and professional training
– SWG 5.3 Awareness
 Deliverables
 “Report on market overview of European cyber range landscape“
 “Report on overview of European cyber education and professional training,
including gap analysis“
 “Report on awareness activities already in place and actors involved”
 Cyber range questionnaires
 Questionnaire #1: Understanding/mapping existing cyber range platforms
and activities (technology focused)
 Questionnaire #2: Understanding of attitude and experience towards cyber
trainings and exercises (usage, acceptance, etc.)
Orange Labs23
ECSO WG6 – 66 members
Strategic Research and Innovation Agenda
 Structure
– SWG 6.1 Ecosystem
– SWG 6.2 Application domains
– SWG 6.3 Transversal infrastructures
– SWG 6.4 Basic technologies
 Deliverable: 2017_WG6_ECSO_SRIA
 H2020-WP2018-20-LEIT-ICT
 SU-ICT-03-2018: Establishing and operating a pilot for a Cybersecurity
Competence Network to develop and implement a common Cybersecurity
Research & Innovation Roadmap
 Network of Competence Centres
 Questionnaire on competences
 European Cyber Security Centres of Expertise Map
 WG6 cyber security vision 2020 and beyond: R&I future priorities for the
European cyber security strategy - towards FP9
Orange Labs24
Dziękuję !

janusz.pieczerak@orange.com

Weitere ähnliche Inhalte

Ähnlich wie PLNOG20 - Janusz Pieczerak - European Cyber Security Organisation – lesson learned

UL Consumer Technology
UL Consumer TechnologyUL Consumer Technology
UL Consumer TechnologyKeith Gilbert
 
ScadaLab Project
ScadaLab Project ScadaLab Project
ScadaLab Project JMBALBOA
 
A Major Revision of the CISRCP Program
A Major Revision of the CISRCP ProgramA Major Revision of the CISRCP Program
A Major Revision of the CISRCP ProgramGoogleNewsSubmit
 
Towards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluationTowards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluationAxel Rennoch
 
CPGR - Service provision, innovation eco-system creation, translational resea...
CPGR - Service provision, innovation eco-system creation, translational resea...CPGR - Service provision, innovation eco-system creation, translational resea...
CPGR - Service provision, innovation eco-system creation, translational resea...Reinhard Hiller
 
SABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 contextSABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 contextDavid Sweigert
 
ISCF Future Flight Networking Event - Regulation
ISCF Future Flight Networking Event - RegulationISCF Future Flight Networking Event - Regulation
ISCF Future Flight Networking Event - RegulationKTN
 
H2020 project WITDOM overview
H2020 project WITDOM overviewH2020 project WITDOM overview
H2020 project WITDOM overviewElsa Prieto
 
Smartcard Helsinki Public ID conference
Smartcard Helsinki Public ID conferenceSmartcard Helsinki Public ID conference
Smartcard Helsinki Public ID conferenceFilipe Mello
 
160405 Catálogos Industriais
160405  Catálogos Industriais160405  Catálogos Industriais
160405 Catálogos IndustriaisZoltan Patkai
 
Information Society Programme - Trust & Security
Information Society Programme - Trust & SecurityInformation Society Programme - Trust & Security
Information Society Programme - Trust & SecurityFilipe Mello
 
The presence and the future: from EUCIP Core to e-CF plus
The presence and the future: from EUCIP Core to e-CF plusThe presence and the future: from EUCIP Core to e-CF plus
The presence and the future: from EUCIP Core to e-CF plusITStudy Ltd.
 
04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx
04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx
04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docxPetruVrlan
 
DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...
DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...
DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...SpagoWorld
 
ECIL: EU Cybersecurity Package and EU Certification Framework
ECIL: EU Cybersecurity Package and EU Certification FrameworkECIL: EU Cybersecurity Package and EU Certification Framework
ECIL: EU Cybersecurity Package and EU Certification FrameworkDeutsche Telekom AG
 

Ähnlich wie PLNOG20 - Janusz Pieczerak - European Cyber Security Organisation – lesson learned (20)

UL Consumer Technology
UL Consumer TechnologyUL Consumer Technology
UL Consumer Technology
 
ScadaLab Project
ScadaLab Project ScadaLab Project
ScadaLab Project
 
CRISP WP3 stakeholder workshop
CRISP WP3 stakeholder workshopCRISP WP3 stakeholder workshop
CRISP WP3 stakeholder workshop
 
Ecsa LPT V8 brochure
Ecsa LPT V8 brochureEcsa LPT V8 brochure
Ecsa LPT V8 brochure
 
A Major Revision of the CISRCP Program
A Major Revision of the CISRCP ProgramA Major Revision of the CISRCP Program
A Major Revision of the CISRCP Program
 
Towards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluationTowards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluation
 
CPGR - Service provision, innovation eco-system creation, translational resea...
CPGR - Service provision, innovation eco-system creation, translational resea...CPGR - Service provision, innovation eco-system creation, translational resea...
CPGR - Service provision, innovation eco-system creation, translational resea...
 
SABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 contextSABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 context
 
ISCF Future Flight Networking Event - Regulation
ISCF Future Flight Networking Event - RegulationISCF Future Flight Networking Event - Regulation
ISCF Future Flight Networking Event - Regulation
 
H2020 project WITDOM overview
H2020 project WITDOM overviewH2020 project WITDOM overview
H2020 project WITDOM overview
 
Smartcard Helsinki Public ID conference
Smartcard Helsinki Public ID conferenceSmartcard Helsinki Public ID conference
Smartcard Helsinki Public ID conference
 
160405 Catálogos Industriais
160405  Catálogos Industriais160405  Catálogos Industriais
160405 Catálogos Industriais
 
Information Society Programme - Trust & Security
Information Society Programme - Trust & SecurityInformation Society Programme - Trust & Security
Information Society Programme - Trust & Security
 
The presence and the future: from EUCIP Core to e-CF plus
The presence and the future: from EUCIP Core to e-CF plusThe presence and the future: from EUCIP Core to e-CF plus
The presence and the future: from EUCIP Core to e-CF plus
 
04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx
04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx
04_a_CEPEJ(2021)5 EN - CEPEJ roadmap certification AI (1).docx
 
DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...
DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...
DrupalDay 2014 - Ecology of value and DRUPAL@Engineering: the experience of a...
 
Tien3
Tien3Tien3
Tien3
 
Profile tulasi digital_health
Profile tulasi digital_healthProfile tulasi digital_health
Profile tulasi digital_health
 
ECIL: EU Cybersecurity Package and EU Certification Framework
ECIL: EU Cybersecurity Package and EU Certification FrameworkECIL: EU Cybersecurity Package and EU Certification Framework
ECIL: EU Cybersecurity Package and EU Certification Framework
 
Profile tulasi v1.1
Profile tulasi v1.1Profile tulasi v1.1
Profile tulasi v1.1
 

Kürzlich hochgeladen

08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 

Kürzlich hochgeladen (20)

08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 

PLNOG20 - Janusz Pieczerak - European Cyber Security Organisation – lesson learned

  • 1. European Cyber Security Organization POLNOG’20, Warszawa, 19-20.03.2018 Janusz Pieczerak (Orange Labs) Lessons learned
  • 4. Orange Labs4 Co robić ???  POLITYKA  OPERACJE  BADANIA i ROZWÓJ  STANDARYZACJA  CERTYFIKACJA  ZNAKOWANIE Jak żyć ???
  • 7. Orange Labs7 EU Cybersecurity certification framework
  • 9. Orange Labs9 Badania i rozwój (R&I)  Programy ramowe (FP), HORIZON 2020  Cele (KPI)  Partnerstwo publiczno prywatne (PPP)  Styczeń 2016: Komisja Europejska (EC) uruchamia Cybersecurity cPPP  Czerwiec 2016: Europejska Organizacja Cyberbezpieczeństwa (ECSO – Association) https://www.ecs-org.eu/  450 mEUR z budżetu H2020, oczekiwany poziom inwestycji sektora prywatnego 1300 mEUR  Strategiczny Plan Badań i Rozwoju (SRIA)
  • 11. ECS - cPPP Partnership Board (monitoring of the ECS cPPP - R&I priorities) EUROPEAN COMMISSION ECSO –Board of Directors (Management of the ECSO Association: policy/market actions) R&I ECSO General Assembly INDUSTRIAL POLICY Coordination / Strategy Committee WG 1 Standardisation / certification / labelling / supply chain management WG 2 Market deployment / investments / international collaboration WG 3 Sectoral Demand (Industry 4.0; Energy; Transport; Finance; eGov; Health; Smart Cities; Telecom/media ) WG 4 Support to SMEs and REGIONS (in particular East EU) WG 5 Education, training, cyber ranges, awareness WG 6 Strategic Research & Innovation Agenda Technologies, Products & Services SME solutions / services providers; local / regional SME clusters and associations Startups, Incubators / Accelerators Large companies Solutions / Services Providers; National or European Organisation / Associations Regional / Local administrations (with economic interests); Regional / Local Clusters of Solution / Services providers or users Public or private users / operators: large companies and SMEs National Public Authority Representatives Committee R&I Group / Policy Advisory Group (GAG) Others (financing bodies, insurance, etc.) Research Centers (large and medium / small), Academies / Universities and their Associations Governance
  • 12. WORKING GROUPS & TASK FORCES WG 1 Standardisation Certification / Labelling / Supply Chain Management WG 2 Market deployment / investments / international collaboration WG 3 Sectoral demand (vertical market applications: Industry 4.0; Energy; Transport; Finance; eGov; Health; Smart Cities; Telecom/media ) WG 4 Support SME, REGIONS and coordination with local bodies (in particular East EU) WG 5 Education, training, awareness, cyber ranges WG 6 Strategic Research & Innovation Agenda (SRIA) Technologies, Products & Services
  • 13. Orange Labs13 Europejski certyfikat bezpieczeństwa  Obowiązkowy czy dobrowolny  Koszty  Czas ważności  Przyznawanie  Odnawianie  Monitorowanie  Co ?  Jak ?  Kto ?  Gdzie ?  Kiedy ?  Dlaczego ?
  • 14. Ogólna koncepcja klasyfikacji certyfikatu cyberbezpieczeństwa (wg ECSO) 14
  • 15. 15 Cybersecurity Act: levels proposed Assurance Level Definition proposed Basic Provides a limited degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterized with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of cybersecurity incidents. Substantial Provides a substantial degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterized with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of cybersecurity incidents. High Provides a higher degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service than certificates with the assurance level substantial, and is characterized with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent cybersecurity incidents.
  • 16. 16 Risk assessment: impact levels and relevant factors mapping Level of impact Attributes Weighting factors Privacy Confidenti ality Integrity Availa bility Authenti city Safety Reputatio n and financial loss High Disclosure of biometric data Disclosure of classified IP System behaves different than expected Compl ete DoS Impersona tion Death or permanent environment al damage Break of business Substan- tial Disclosure of any other personal data Disclosure of any other information Some functionali- ties features impacted Partial DoS Impossible to verify authentici ty Injury or remediable environment al damage Long term impact Basic No disclosure of data No disclo- sure of information No feature is impacted No impact No impact No harm No impact
  • 17. 17 Possible mapping of levels Levels of assurance in the Cybersecurity Act Levels of assurance from the ECSO’s meta-scheme Levels of assurance from the ECSO’s meta- scheme (alt.) Body performing the evaluation High A Ag National (governmental) body B A 3rd party evaluation facility (lab) Substantial C B Basic D Ce E Ci Self-evaluation
  • 18. Orange Labs18 ECSO WG1 - 135 members Standardization, certification, labelling and supply chain  Structure – SWG 1.1 Products & components manufacturers – SWG 1.2 ICT infrastructure operators (chaired byOrange) – SWG 1.3 Users, Integrators and other service providers – SWG 1.4 Basic Layer  Deliverables:  Challenges of the Industry (COTI) - Collection of member’s views  State-of-the-Art Syllabus (SOTA) - Standards and certification schemes  Certification Meta Scheme Approach - Certification framework proposal
  • 19. Orange Labs19 ECSO WG2 - 41 members Market deployment  Structure – SWG 2.1 Market development, products and stakeholders – SWG 2.2 Investments, innovative business models – SWG 2.3 International cooperation, global competetiveness and support to export – SWG 2.4 Dissemination and awareness, events
  • 20. Orange Labs20 ECSO WG3 - 123 members Sectoral demand  Structure – SWG 3.1 Digitalisation of the European Industry (including Industry 4.0) and ICS; – SWG 3.2 Energy (oil, gas, electricity), and Smart Grids; – SWG 3.2 Transportation (road, rail, air, sea, space); – SWG 3.4 Banks and Financial Services, ePayments and Insurance; – SWG 3.5 Public Services, eGovernment, Digital Citizenship; – SWG 3.6 Healthcare; – SWG 3.7 Smart Cities and Smart Buildings (convergence of digital services for Citizens) and other Utilities; – SGW 3.8 Telecom, Media and Content  Deliverables (landscape, user engagement, sector specifics, market study):  2018_SWG3.1Industry4.0andICS_sectorreport_final_v0.1  2018_SWG3.4FinancialServicesInsurance_sectorreport_final_v0.1  2018_SWG3.6Healthcare_sectorreport_final_v0.1  2018_SWG3.7Smartcities_sectorreport_final_v0.1
  • 21. Orange Labs21 ECSO WG4 - 23 members Support to SME and regions  Structure – SWG 4.1 SMEs, start-ups and high growth companies – SWG 4.2 Coordination with activities in EU countries and regions – SWG 4.3 Support to East EU Members  WG4_Deliverable_Positionpaper_Consolidated_VF  Support to SME’s, coordination with countries (in particular East EU) and regions
  • 22. Orange Labs22 ECSO WG5 - 98 members Education, training, awareness, exercises  Structure – TF 5.0.1 EHR4CYBER Task Force – SWG 5.1 Cyber Range environments and technical exercises – SWG 5.2 Education and professional training – SWG 5.3 Awareness  Deliverables  “Report on market overview of European cyber range landscape“  “Report on overview of European cyber education and professional training, including gap analysis“  “Report on awareness activities already in place and actors involved”  Cyber range questionnaires  Questionnaire #1: Understanding/mapping existing cyber range platforms and activities (technology focused)  Questionnaire #2: Understanding of attitude and experience towards cyber trainings and exercises (usage, acceptance, etc.)
  • 23. Orange Labs23 ECSO WG6 – 66 members Strategic Research and Innovation Agenda  Structure – SWG 6.1 Ecosystem – SWG 6.2 Application domains – SWG 6.3 Transversal infrastructures – SWG 6.4 Basic technologies  Deliverable: 2017_WG6_ECSO_SRIA  H2020-WP2018-20-LEIT-ICT  SU-ICT-03-2018: Establishing and operating a pilot for a Cybersecurity Competence Network to develop and implement a common Cybersecurity Research & Innovation Roadmap  Network of Competence Centres  Questionnaire on competences  European Cyber Security Centres of Expertise Map  WG6 cyber security vision 2020 and beyond: R&I future priorities for the European cyber security strategy - towards FP9