ITS Datamatix Gitex Conference 2009 New ICT Security V2

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Notes on slide 1

    Computer Associates International, Inc. ca.com January 29, 2001

    Computer Associates International, Inc. ca.com January 29, 2001

    Computer Associates International, Inc. ca.com January 29, 2001

    Computer Associates International, Inc. ca.com January 29, 2001

    Computer Associates International, Inc. ca.com January 29, 2001

    Computer Associates International, Inc. ca.com January 29, 2001

    Computer Associates International, Inc. ca.com January 29, 2001

    1 Favorite

    ITS Datamatix Gitex Conference 2009 New ICT Security V2 - Presentation Transcript

    1. Implementing New Approaches of Global ICT Security Management +973-36040991 [email_address]
      • 79% - don’t believe Security Software of Digital Signature provides Sufficient Protection
      • 50% - Organization not protected against Malware based on attack trends
      • 62% - not enough time resources to address vulnerabilities
      • 66% - out of work during recession will lead to more people joining cyber-criminal underground
      ICT Security 2009 - Risks
      • 41% - increase in sophistication of attacks
      • 45% - increase in phishing attacks on employees
      • 49% - (financial services) increase in technical sophistication of attacks
      • 63% - infected web site biggest cause of compromise of online security
      ICT Security 2009 – Arms Race
    2. eCrime 2009 – UAE Costly
    3. Complexity is a big issue FIREWALLS EMAIL HYGIENE COMPLIANCE POLICY IM / VolP SECURITY 1990 2000 2005 2010 TIME VolP & Unified Messaging Content Control Spam +AV Control Perimeter Security
    4. ICT Risks are changing
    5. More sophisticated Attacks
    6. Criminals Hacking is now a business
    7. Hacker don’t follow rules?
    8. There is much more?
    9. Importance of Critical Infrastructures
    10. People is the biggest problem?
    11. Technology Process People Technology is not enough
    12. Scope of Security Management & Value
    13. Security focus on Business
    14. Integrated Security Mgmt Business Security Management Physical Security Management ICT Security Management
    15. Infrastructure Best Practices
    16. Risk Classification
    17. Managing Risk Threats Vulnerabilities Controls Risks Assets Security Requirements Business Impact exploit expose increase increase increase have protect against met by indicate reduce
    18. Business View Service and Continuity Customer Focus Managing Risks Operation Risk Controls Auditing Governance & Compliance IT Infrastructure Disaster Recovery High Availability Views of Security and Risk Management
      • Not all risk can be eliminated via controls
      Elimination Reduction/Controls Transfer/Outsource Insurance Residual Risk Management
    19. Technology People
      • SLA
      • 24x7x365
      • Industry Best Practices
      • ITIL based processes
      • Data Center Best Practices
      • Latest Monitoring tools
      • State of the Art knowledge base
      • Secure technology
      • Certified and Trained Staff
      • Technical Experts
      • Cross Training
      • Onsite and Offsite
      Holistic Implementation Process
    20. How to achieve organization goals and objectives Organization Goals and Objectives How to perform the activities that are needed Artifacts used to perform activities References to use for efficient performance Best Practices Structure
    21. Managed Security Framework Desktop Network Servers Databases Storage Applications Monitoring, Automation Tools ITIL Compliant Best Practices Aggregated Reporting / Portal / I2MP, Service Desk Redundancy / High Availability / Disaster Recovery Onsite Offsite Vendor A Vendor B Call Center Center of Excellence
    22. Implementation Continuous Detection Response
      • 24x7x365
      • Security monitoring
      • Managed Services
      • Automatic Alerting
      • Incidence Response
      • Vulnerability Assessment
      • Patch Management
      • Forensic Analysis
      • Integration
      Incident Response Analyse Contain Eliminate Restore Lessons Policy Refine Policy Continuous Monitoring T-1 T 0 T 1 T 1 T 3 T 4 T N Communicate
    23. CIO Security Metrics
    24. Not enough security – system is at risk Too much security – system is unusable Practical Security Mix
    25. Protection Detection Response SECURITY P>D+R Security = Time Anti-virus VPN Firewall Access Control Intrusion Prevention Managed Services Patch Mgmt CIRT Vulnerability Testing Intrusion Detection Log Correlation CCTV
    26. Security in Depth
    27. Security in Depth Revised People Technology Process Prevent Respond/ Recover Detect
    28. Knowledge fills gaps SETA = Security +Training + Awareness + Education
    29. Transformation Optimization Due Diligence Transition Plan Implementation Process
    30. Chose right balance Controls & Trade-Offs Secure Fast/Easy Cheap
    31. ICT Security Skilled Resources Logical Physical Integration Best Practices Continuous Model Security with 20/20 Vision
    32. Questions

    + Jorge SebastiaoJorge Sebastiao, 3 weeks ago

    custom

    114 views, 1 favs, 0 embeds more stats

    This provides an update on the new ICT challenges f more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 114
      • 114 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 0
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories