SlideShare une entreprise Scribd logo
1  sur  15
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Enterprise Security Management
Protection Profiles:
An Implementation Plan
September 2009
Eric Winterton, Booz | Allen| Hamilton
Joshua Brickman, CA Inc.
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
2
Agenda
- Review
- Enterprise Security Management—what are
these products?
-Categories
-Methodology
- Schedule
- Communication Plan
- Risks/Beta/Roll-out
- How can you get involved (Participants)
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
3
How did we got here?
-2008 Proposal (Winterton/Brickman)
-Approach
-Consensus
-All Participating Countries
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Enterprise Security Management
4
Standardized
logging
Compliance
&
configuration
Identity
Management
Monitoring
&
response
Policy/Access
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
What Products Make Up ESM?
CA Identity
Manager
CA GRC Manager CA Siteminder CA Auditor for z/OS CA Enterprise Log
Manager
SC Operations
Manager, SC
Configuration
Manager & SC VMM
SC Operations
Manager, SC
Configuration
Manager, SC
Essentials
SC Operations
Manager &
SC Essentials
SC Operations
Manager*
Symantec Alteris Symantec CCS/FTK Symantec Alteris Symantec SSIM Symantec Alteris
EMC RSA Access
Manager
EMC RSA Envision EMC RSA Envision
Oracle Identity
Manager
Oracle Enterprise
Manager
Oracle Access
Manager
Oracle Audit Vault Oracle Audit Vault
IBM Tivoli Identity
Manager
IBM Tivoli
Compliance Insight
Manager (TCIM) ,
Security
Information Event
Manager (TSIEM)
IBM Tivoli Unified
Single Sign-On ,
Tivoli Security
Policy Manager
IBM Common Audit
and Reporting
(CARS) & TCIM
5
Identity
Management Compliance
and
configuration
Policy/Access
Monitoring
and
response
Standardized
logging
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
6
Approach
ID CC
Gaps for
ESM
Start
Establish
Industry
Team and
Select Lab
Created
ESM Product
Categories
Collected
Products
and Data
Define next
level of Use
Cases
Develop
Global
Threat
Analysis
Select
Protection
Profile
Establish
High-level
Spec for PP
Develop PP
Verify (QA)
on PP
Publish PP
Draft for
Public
Comment
Declare PP
Status
(Global
Conference)
Publish PP
PPs
Complete?
Stop
No
Yes
Publish PP
Draft for
Public
Comment
Completed as of Sept 09
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
7
Cause and Effect/Fishbone
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
8
Timeline so far
- Sept 2008 Proposal
- Received well at 9th ICCC--interest by multiple
vendors, NIAP, consultants and other schemes
- May 2009: NIAP pledges support for creation of
the ESM PP’s.
- May-Aug 2009: Concurrence of ESM product
categories among Microsoft, IBM, EMC, Oracle
Symantec, Ricoh, and CA Inc solidified
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Implementation Plan
9
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Communication Plan
- Comment Periods
-Posted on official sites
-Allow for anyone to provide feedback
- CCVF
- ICCC and RSA
10
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Participation to Date
- You can be a part of this team
- The more participants the better the quality
11
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Joshua Brickman, PMP
CA, Inc.
Program Manager, Federal Certifications
(508) 628-8917
Joshua.Brickman@ca.com
Q & A
12
Eric Winterton, CISSP
Booz | Allen | Hamilton
CCTL Director
(410) 684-6691
winterton_eric@bah.com
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
13
Backup Slides
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
Impact to Effort Matrix
14
Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services
marks and logos referenced herein belong to their respective companies.
All Products in ESM
15

Contenu connexe

Dernier

Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 

Dernier (20)

Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 

En vedette

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 

En vedette (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

Enterprise security management protection profiles an implementatiion plan final

  • 1. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Enterprise Security Management Protection Profiles: An Implementation Plan September 2009 Eric Winterton, Booz | Allen| Hamilton Joshua Brickman, CA Inc.
  • 2. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 2 Agenda - Review - Enterprise Security Management—what are these products? -Categories -Methodology - Schedule - Communication Plan - Risks/Beta/Roll-out - How can you get involved (Participants)
  • 3. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 3 How did we got here? -2008 Proposal (Winterton/Brickman) -Approach -Consensus -All Participating Countries
  • 4. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Enterprise Security Management 4 Standardized logging Compliance & configuration Identity Management Monitoring & response Policy/Access
  • 5. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. What Products Make Up ESM? CA Identity Manager CA GRC Manager CA Siteminder CA Auditor for z/OS CA Enterprise Log Manager SC Operations Manager, SC Configuration Manager & SC VMM SC Operations Manager, SC Configuration Manager, SC Essentials SC Operations Manager & SC Essentials SC Operations Manager* Symantec Alteris Symantec CCS/FTK Symantec Alteris Symantec SSIM Symantec Alteris EMC RSA Access Manager EMC RSA Envision EMC RSA Envision Oracle Identity Manager Oracle Enterprise Manager Oracle Access Manager Oracle Audit Vault Oracle Audit Vault IBM Tivoli Identity Manager IBM Tivoli Compliance Insight Manager (TCIM) , Security Information Event Manager (TSIEM) IBM Tivoli Unified Single Sign-On , Tivoli Security Policy Manager IBM Common Audit and Reporting (CARS) & TCIM 5 Identity Management Compliance and configuration Policy/Access Monitoring and response Standardized logging
  • 6. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 6 Approach ID CC Gaps for ESM Start Establish Industry Team and Select Lab Created ESM Product Categories Collected Products and Data Define next level of Use Cases Develop Global Threat Analysis Select Protection Profile Establish High-level Spec for PP Develop PP Verify (QA) on PP Publish PP Draft for Public Comment Declare PP Status (Global Conference) Publish PP PPs Complete? Stop No Yes Publish PP Draft for Public Comment Completed as of Sept 09
  • 7. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 7 Cause and Effect/Fishbone
  • 8. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 8 Timeline so far - Sept 2008 Proposal - Received well at 9th ICCC--interest by multiple vendors, NIAP, consultants and other schemes - May 2009: NIAP pledges support for creation of the ESM PP’s. - May-Aug 2009: Concurrence of ESM product categories among Microsoft, IBM, EMC, Oracle Symantec, Ricoh, and CA Inc solidified
  • 9. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Implementation Plan 9
  • 10. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Communication Plan - Comment Periods -Posted on official sites -Allow for anyone to provide feedback - CCVF - ICCC and RSA 10
  • 11. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Participation to Date - You can be a part of this team - The more participants the better the quality 11
  • 12. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Joshua Brickman, PMP CA, Inc. Program Manager, Federal Certifications (508) 628-8917 Joshua.Brickman@ca.com Q & A 12 Eric Winterton, CISSP Booz | Allen | Hamilton CCTL Director (410) 684-6691 winterton_eric@bah.com
  • 13. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. 13 Backup Slides
  • 14. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. Impact to Effort Matrix 14
  • 15. Copyright ©2009 CA & Booz Allen Hamilton. All rights reserved. All trademarks, trade names, services marks and logos referenced herein belong to their respective companies. All Products in ESM 15