SlideShare a Scribd company logo
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Enterprise Security Management
Protection Profiles:
An Implementation Plan
September 2009
Eric Winterton, Booz | Allen| Hamilton
Joshua Brickman, CA Inc.
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
2
Agenda
- Review
- Enterprise Security Management—what are
these products?
-Categories
-Methodology
- Schedule
- Communication Plan
- Risks/Beta/Roll-out
- How can you get involved (Participants)
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
3
How did we got here?
-2008 Proposal (Winterton/Brickman)
-Approach
-Consensus
-All Participating Countries
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Enterprise Security Management
4
Standardized
logging
Compliance
&
configuration
Identity
Management
Monitoring
&
response
Policy/Access
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
What Products Make Up ESM?
CA Identity
Manager
CA GRC Manager CA Siteminder CA Auditor for z/OS CA Enterprise Log
Manager
SC Operations
Manager, SC
Configuration
Manager & SC VMM
SC Operations
Manager, SC
Configuration
Manager, SC
Essentials
SC Operations
Manager &
SC Essentials
SC Operations
Manager*
Symantec Alteris Symantec CCS/FTK Symantec Alteris Symantec SSIM Symantec Alteris
EMC RSA Access
Manager
EMC RSA Envision EMC RSA Envision
Oracle Identity
Manager
Oracle Enterprise
Manager
Oracle Access
Manager
Oracle Audit Vault Oracle Audit Vault
IBM Tivoli Identity
Manager
IBM Tivoli
Compliance Insight
Manager (TCIM) ,
Security
Information Event
Manager (TSIEM)
IBM Tivoli Unified
Single Sign-On ,
Tivoli Security
Policy Manager
IBM Common Audit
and Reporting
(CARS) & TCIM
5
Identity
Management Compliance
and
configuration
Policy/Access
Monitoring
and
response
Standardized
logging
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
6
Approach
ID CC
Gaps for
ESM
Start
Establish
Industry
Team and
Select Lab
Created
ESM Product
Categories
Collected
Products
and Data
Define next
level of Use
Cases
Develop
Global
Threat
Analysis
Select
Protection
Profile
Establish
High-level
Spec for PP
Develop PP
Verify (QA)
on PP
Publish PP
Draft for
Public
Comment
Declare PP
Status
(Global
Conference)
Publish PP
PPs
Complete?
Stop
No
Yes
Publish PP
Draft for
Public
Comment
Completed as of Sept 09
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
7
Cause and Effect/Fishbone
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
8
Timeline so far
- Sept 2008 Proposal
- Received well at 9th ICCC--interest by multiple
vendors, NIAP, consultants and other schemes
- May 2009: NIAP pledges support for creation of
the ESM PP’s.
- May-Aug 2009: Concurrence of ESM product
categories among Microsoft, IBM, EMC, Oracle
Symantec, Ricoh, and CA Inc solidified
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Implementation Plan
9
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Communication Plan
- Comment Periods
-Posted on official sites
-Allow for anyone to provide feedback
- CCVF
- ICCC and RSA
10
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Participation to Date
- You can be a part of this team
- The more participants the better the quality
11
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Joshua Brickman, PMP
CA, Inc.
Program Manager, Federal Certifications
(508) 628-8917
Joshua.Brickman@ca.com
Q & A
12
Eric Winterton, CISSP
Booz | Allen | Hamilton
CCTL Director
(410) 684-6691
winterton_eric@bah.com
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
13
Backup Slides
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Impact to Effort Matrix
14
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
All Products in ESM
15

More Related Content

Recently uploaded

Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
saastr
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
Tatiana Kojar
 
AppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSFAppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSF
Ajin Abraham
 
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing InstancesEnergy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Alpen-Adria-Universität
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
Neo4j
 
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
saastr
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
DianaGray10
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
Alex Pruden
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
AstuteBusiness
 
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their MainframeDigital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Precisely
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
Antonios Katsarakis
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Tosin Akinosho
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Pitangent Analytics & Technology Solutions Pvt. Ltd
 
Principle of conventional tomography-Bibash Shahi ppt..pptx
Principle of conventional tomography-Bibash Shahi ppt..pptxPrinciple of conventional tomography-Bibash Shahi ppt..pptx
Principle of conventional tomography-Bibash Shahi ppt..pptx
BibashShahi
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
Chart Kalyan
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
Brandon Minnick, MBA
 

Recently uploaded (20)

Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
 
AppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSFAppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSF
 
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing InstancesEnergy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
 
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
 
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their MainframeDigital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
 
Principle of conventional tomography-Bibash Shahi ppt..pptx
Principle of conventional tomography-Bibash Shahi ppt..pptxPrinciple of conventional tomography-Bibash Shahi ppt..pptx
Principle of conventional tomography-Bibash Shahi ppt..pptx
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
 

Featured

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
Expeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
Pixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
marketingartwork
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
Skeleton Technologies
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
SpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Lily Ray
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
Rajiv Jayarajah, MAppComm, ACC
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
Christy Abraham Joy
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
Vit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
MindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Applitools
 

Featured (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

Enterprise security management protection profiles an implementatiion plan final

  • 1. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Enterprise Security Management Protection Profiles: An Implementation Plan September 2009 Eric Winterton, Booz | Allen| Hamilton Joshua Brickman, CA Inc.
  • 2. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 2 Agenda - Review - Enterprise Security Management—what are these products? -Categories -Methodology - Schedule - Communication Plan - Risks/Beta/Roll-out - How can you get involved (Participants)
  • 3. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 3 How did we got here? -2008 Proposal (Winterton/Brickman) -Approach -Consensus -All Participating Countries
  • 4. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Enterprise Security Management 4 Standardized logging Compliance & configuration Identity Management Monitoring & response Policy/Access
  • 5. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. What Products Make Up ESM? CA Identity Manager CA GRC Manager CA Siteminder CA Auditor for z/OS CA Enterprise Log Manager SC Operations Manager, SC Configuration Manager & SC VMM SC Operations Manager, SC Configuration Manager, SC Essentials SC Operations Manager & SC Essentials SC Operations Manager* Symantec Alteris Symantec CCS/FTK Symantec Alteris Symantec SSIM Symantec Alteris EMC RSA Access Manager EMC RSA Envision EMC RSA Envision Oracle Identity Manager Oracle Enterprise Manager Oracle Access Manager Oracle Audit Vault Oracle Audit Vault IBM Tivoli Identity Manager IBM Tivoli Compliance Insight Manager (TCIM) , Security Information Event Manager (TSIEM) IBM Tivoli Unified Single Sign-On , Tivoli Security Policy Manager IBM Common Audit and Reporting (CARS) & TCIM 5 Identity Management Compliance and configuration Policy/Access Monitoring and response Standardized logging
  • 6. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 6 Approach ID CC Gaps for ESM Start Establish Industry Team and Select Lab Created ESM Product Categories Collected Products and Data Define next level of Use Cases Develop Global Threat Analysis Select Protection Profile Establish High-level Spec for PP Develop PP Verify (QA) on PP Publish PP Draft for Public Comment Declare PP Status (Global Conference) Publish PP PPs Complete? Stop No Yes Publish PP Draft for Public Comment Completed as of Sept 09
  • 7. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 7 Cause and Effect/Fishbone
  • 8. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 8 Timeline so far - Sept 2008 Proposal - Received well at 9th ICCC--interest by multiple vendors, NIAP, consultants and other schemes - May 2009: NIAP pledges support for creation of the ESM PP’s. - May-Aug 2009: Concurrence of ESM product categories among Microsoft, IBM, EMC, Oracle Symantec, Ricoh, and CA Inc solidified
  • 9. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Implementation Plan 9
  • 10. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Communication Plan - Comment Periods -Posted on official sites -Allow for anyone to provide feedback - CCVF - ICCC and RSA 10
  • 11. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Participation to Date - You can be a part of this team - The more participants the better the quality 11
  • 12. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Joshua Brickman, PMP CA, Inc. Program Manager, Federal Certifications (508) 628-8917 Joshua.Brickman@ca.com Q & A 12 Eric Winterton, CISSP Booz | Allen | Hamilton CCTL Director (410) 684-6691 winterton_eric@bah.com
  • 13. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 13 Backup Slides
  • 14. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Impact to Effort Matrix 14
  • 15. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. All Products in ESM 15