2004 12 03 Larry Clinton Philadelphia Presentation About ISA and Coherent Program of Cyber Security Through Incentives
2004 12 03 Larry Clinton Philadelphia Presentation About ISA and Coherent Program of Cyber Security Through Incentives
2004 12 03 Larry Clinton Philadelphia Presentation About ISA and Coherent Program of Cyber Security Through Incentives
Presentation Outline
The Growing Problem of Cyber Security Traditional Solutions and Why They Wont Work A New Paradigm (tools and incentives) Bringing it all Together
The Past
The Present
Source: http://cm.bell-labs.com/who/ches/map/gallery/index.html
Methods of Attack Brute force Denial of Service Viruses & worms Back door taps & misappropriation, Information Warfare (IW) techniques
911 Unavailable
100000 80000
55,100
60000 40000
21,756
20000
6 132 252 406 773 1,334 2,340 2,412 2,573 2,134 3,734 9,859
0 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002
4,129
2,437
Tools
High
Intruder Knowledge
Attack Sophistication
Low
1980
password guessing
1985
1990
150
billion
120 90 60 30 0
Putnam Legislation
Risk Assessment Risk Mitigation Incident Response Program Tested Continuity plan Updated Patch management program Putnam has said it wont work.
Participants in information sharing have the ability to better prepare for attacks and respond to them.
ISAlliance/CERT Training
Concepts and Trends In Information Security Information Security for Technical Staff OCTAVE Method Training Workshop Overview of Managing Computer Security Incident Response Teams Fundamentals of Incident Handling Advanced Incident Handling for Technical Staff Information Survivability an Executive Perspective
A coherent program
7. Develop the business case (ROI) for improved cyber security 8. Develop market incentives and tools for consistent maintenance of cyber security 9. Integrate sound theory and practice and evaluation into public policy 10. Constantly expand the perimeter of cyber security by adding new members
Sponsors
Larry Clinton Operations Officer Internet Security Alliance [email protected] 703-907-7028 202-236-0001