SlideShare une entreprise Scribd logo
1  sur  18
Télécharger pour lire hors ligne
Information Sharing
    A requirement for Cyber Defense
                 Shuky Peleg, CISA, CISSP
           Head of Information Security, eGov




October 2012 | Ministry of Finance - eGovernment
What is eGov?

Providing citizens and businesses with better
access to government information.

eGov simplifies and shortens bureaucratic
processes, offers online services and implements
advanced government technologies in order to
benefit citizens and businesses.
Improving
                                                                              Improving
                 Raising                       government’s                     service
                                                  image        Saving
               government                                                         for
                                                               money
               production                                                     businesses
                               Better
  New                        service for
 online
                              citizens
services                                                      Increasing
                                                              efficiency
                  Reducing
                 bureaucracy
                                           Vision                             Raising
                                                                            productivity

                                            and
  Increasing
                                           Goals
transparency

                               Managing
                              platform for               24/7              Providing
     Technological
                            inter-ministries            service             better,
                               processes                                   efficient
    advancements
                                                                            online
                                                                            service
eGov
The Internet Frontier of the Israeli Government
   eGov Services for Citizens and Businesses
   Secure ISP/ASP/ESB/Connectivity providers for the
     Ministries
    IT & Cyber Security Service Providers for Ministries
    Knowledge Center and coordination body for IT &
     Cyber Security (CERT, SIEM, Threat and Malware
     Research)
eGov
 Number of employees : ~250, all technology experts.
 The E-Government unit is built entirely from Hi-tech
  professionals, employed by government tenders for
  technology services.
 Part of E-Government projects are carried out using
  full outsourcing.
 E-Government is regulated by NISA.
 All e-Government employees have required level of
  security clearance
eGov Topology
              Government Offices




              Government Network




                                           e-Gov



                     Internet




Citizen   Business   Citizen    Business
Personalization                                                                                                                         My Gov |
                                                                                                                                        Smart ID



 Doing                                                                                                  Building         Property or
                                                                                             MASLOL                        business
Business                                                                                                permits          registration




                                                                                             Service                                    Cellular |
Multi-channels                                         Web
                                                                                             stations                                      IVR



                                                                                                        Social media |
   Media and                                                                                 Shituf      government      Gov 2.0 |
                                                     Customer
   transparency                                                                                            contact
                                                                                                                         data gov
                                                      service



                                                     Gov Servie    eGov
  Standards                                             bus                          Gov X
                                                                  report



  Government                                                                Search                                                          MASE
  information                                         Gov.il                                   kids
                                                                            engine                                                         project




  Online                   Payment                                Forms
 services                   service                               service



             Web hosting               Information
   ISP                                                                                                                                   BCP/DRP
              and Email                  security
         7
              1997/8       2000/1     2002/3         2004/5       2006       2007    2008     2009         2010            2011            2011/2
eGov Security Group

   An inherent part of eGov core activity
   A technology leader
   A knowledge center and a public sector focal point for all ICT
    security issues
   Promoting Israeli Information Security technologies
Main Threats
 Defacement of Government Sites
      Bank of Israel - 2008
 Denial of Service attacks
      “Cast Lead” in Gaza - 2009
 Theft/Corruption of Government Data
 Corruption / disturbance to National Critical Infrastructure
 Theft of services or money from the Government (E-
    Commerce)
   Identity fraud / theft (E-Forms, PKI Infrastructure)
   Information Leakage
   Using Government Infrastructure as enabler / facilitator of
    Cyber conflict
   Using Public Infrastructure as enabler / facilitator of Cyber
    conflict
Main Protection Principles

   Separation of duties
   Segregation of Networks
   Log Everything
   Pass only what we can monitor
   No remote administration
   No single point of failure - “2 mistakes”
   Secure Development Lifecycle
   Identifying Cross-application and cross-domain
    influences
Organizational Chart


                               Head of
                                                                                             Head of IT
                             Information                                                   Infrastructure
                               Security

                               Cyber,              Information   Operation Centre
  Technology and
                           Methodology and           Security                                                    Systems
Incident Response
                             Application
                                                                  (Network and            Hosting Services
      Team                                                                                                     Administration
                            Security Team            Officer        Security)


                                                                     1st Level Security        Platforms and          Security
    CERT and Analysis            Pen. Testing                        Monitoring and               Systems         Implementation
                                                                          response               Hardening        (AV, FW, Mail…)


    2nd Level Monitoring
        and Forensics
                               Security Research
Regulatory Environment
                                               Industry
               NISA                           Standards
              Critical                           and
          Infrastructure     Government      Regulations:
                                CIO          ISO 27001,
                                                 PCI


Privacy
 ILITA
                                               National Cyber
                                                   Bureau
                                   Self
             National and       Regulation
            Internationals       and Best
              Laws and          Practices…
             Regulations
Cooperation efforts
  Standards             Industry                         Israeli and
  institution            Peers                         foreign CERT
   of Israel                                           organizations


                                      National Cyber
                                          Bureau

                                                            Israeli
                Cyber Defense                             technology
                 Community                                companies
Government         Peers
enterprises                        Universities and
                                       research
                                      intuitions
Focus on the CERT Organization
Member in a Global CERT Org.
Creation of a Nation-Wide View

                                     National CERT  Procedures, Guidelines and
                                                        Immediate Actions



   Government
   )CERT.Gov.il(
                                      Academy
                                     )CERT.ac.il(
                                                                           Alerts
                                                                   Private Sector
                                                                                        Financial
                                                                                         Sector
                                                                                                                     Critical
                                                                                                                 Infrastructure
                                                                                                                                                  Defense



                                                    Procedures, Guidelines and
                                                        Immediate Actions




                                                                                                                               Transportation
        Government

                     Public Sector

                                     Universities




                                                               Telecomm




                                                                                                                                                           Industries
                                                                                                  Insurance
                                                    Colleges




                                                                                                                                                            Defense
                                                                                        Banking




                                                                                                                                                Military
          Offices




                                                                                                              Energy

                                                                                                                       Water
e-Gov




                                                                                 SMBs
                                                                          ISPs
Our Legacy            Our Routine            Our Vision
Protecting            Participate in         Serving as a liaison
Government Internet   designing secured      between the public
Gateway and Servers   systems and            and cyber defense
                      preventing malicious   agencies and
                      intents via advanced   government bodies
                      monitoring             to protect our way of
                                             life in the
                                             information era.




   20
Ministry of Finance –E-Government Division




           Thank you !

Contenu connexe

Tendances

Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02
Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02
Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02Faizal Adiputra
 
Bridgewater Systems 2008 Marketing Report
Bridgewater Systems 2008 Marketing ReportBridgewater Systems 2008 Marketing Report
Bridgewater Systems 2008 Marketing ReportTMX Equicom
 
Grabovsky a.t.kearney telco-form_08.06.11
Grabovsky a.t.kearney telco-form_08.06.11Grabovsky a.t.kearney telco-form_08.06.11
Grabovsky a.t.kearney telco-form_08.06.11Андрей Лукин
 
David Kerr - Strategy Analytics
David Kerr - Strategy AnalyticsDavid Kerr - Strategy Analytics
David Kerr - Strategy AnalyticsBen Allen
 
Palestra "Technology Trends To Watch In 2012 and beyond"
Palestra "Technology Trends To Watch In 2012 and beyond"Palestra "Technology Trends To Watch In 2012 and beyond"
Palestra "Technology Trends To Watch In 2012 and beyond"Dígitro Tecnologia
 
Wi-Fi Driving Mobile Internet Explosion in Next Generation Networks
Wi-Fi Driving Mobile Internet Explosion in Next Generation NetworksWi-Fi Driving Mobile Internet Explosion in Next Generation Networks
Wi-Fi Driving Mobile Internet Explosion in Next Generation NetworksGreen Packet
 
Harnessing the benefits of utility compute for government savvis white paper ...
Harnessing the benefits of utility compute for government savvis white paper ...Harnessing the benefits of utility compute for government savvis white paper ...
Harnessing the benefits of utility compute for government savvis white paper ...Gill Hawkins
 
20100521 Laying down the building blocks for eGovernment
20100521 Laying down the building blocks for eGovernment20100521 Laying down the building blocks for eGovernment
20100521 Laying down the building blocks for eGovernmentMiguel A. Amutio
 
Orange Smart City portfolio in MENA
Orange Smart City portfolio in MENAOrange Smart City portfolio in MENA
Orange Smart City portfolio in MENAMarc Berchoud
 
Orange Smart City in MENA, an outline
Orange Smart City in MENA, an outlineOrange Smart City in MENA, an outline
Orange Smart City in MENA, an outlineMarc Berchoud
 
Government’s digital future & NAO’s changing approach
Government’s digital future & NAO’s changing approachGovernment’s digital future & NAO’s changing approach
Government’s digital future & NAO’s changing approachUK National Audit Office
 
Smart city leboucher
Smart city leboucherSmart city leboucher
Smart city leboucherCIRB_CIBG
 
From Knowledge Economy to Inclusive Information Society. Experiences from Ind...
From Knowledge Economy to Inclusive Information Society. Experiences from Ind...From Knowledge Economy to Inclusive Information Society. Experiences from Ind...
From Knowledge Economy to Inclusive Information Society. Experiences from Ind...USAID CEED II Project Moldova
 
Smarter Computing in a New Era of IT - Dr. Gururaj Rao
Smarter Computing in a New Era of IT - Dr. Gururaj RaoSmarter Computing in a New Era of IT - Dr. Gururaj Rao
Smarter Computing in a New Era of IT - Dr. Gururaj RaoJyothi Satyanathan
 
Introduction for Korea IT Industry Promotion Agency
Introduction for Korea IT Industry Promotion AgencyIntroduction for Korea IT Industry Promotion Agency
Introduction for Korea IT Industry Promotion AgencyJacob Heejeong Yang, Ph.D.
 
Leading in the converged future becoming an agile telco
Leading in the converged future becoming an agile telcoLeading in the converged future becoming an agile telco
Leading in the converged future becoming an agile telcoInfosys BPM
 
Mobile Developer 101 (mHealth Edition)
Mobile Developer 101 (mHealth Edition)Mobile Developer 101 (mHealth Edition)
Mobile Developer 101 (mHealth Edition)Caroline Lewko
 

Tendances (20)

Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02
Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02
Frostsullivanindonesiaict2outlook2012thebigleapahead 120216211906-phpapp02
 
Bridgewater Systems 2008 Marketing Report
Bridgewater Systems 2008 Marketing ReportBridgewater Systems 2008 Marketing Report
Bridgewater Systems 2008 Marketing Report
 
Grabovsky a.t.kearney telco-form_08.06.11
Grabovsky a.t.kearney telco-form_08.06.11Grabovsky a.t.kearney telco-form_08.06.11
Grabovsky a.t.kearney telco-form_08.06.11
 
David Kerr - Strategy Analytics
David Kerr - Strategy AnalyticsDavid Kerr - Strategy Analytics
David Kerr - Strategy Analytics
 
Palestra "Technology Trends To Watch In 2012 and beyond"
Palestra "Technology Trends To Watch In 2012 and beyond"Palestra "Technology Trends To Watch In 2012 and beyond"
Palestra "Technology Trends To Watch In 2012 and beyond"
 
Wi-Fi Driving Mobile Internet Explosion in Next Generation Networks
Wi-Fi Driving Mobile Internet Explosion in Next Generation NetworksWi-Fi Driving Mobile Internet Explosion in Next Generation Networks
Wi-Fi Driving Mobile Internet Explosion in Next Generation Networks
 
Harnessing the benefits of utility compute for government savvis white paper ...
Harnessing the benefits of utility compute for government savvis white paper ...Harnessing the benefits of utility compute for government savvis white paper ...
Harnessing the benefits of utility compute for government savvis white paper ...
 
20100521 Laying down the building blocks for eGovernment
20100521 Laying down the building blocks for eGovernment20100521 Laying down the building blocks for eGovernment
20100521 Laying down the building blocks for eGovernment
 
Corporate ppt tech_treeit
Corporate ppt tech_treeitCorporate ppt tech_treeit
Corporate ppt tech_treeit
 
Orange Smart City portfolio in MENA
Orange Smart City portfolio in MENAOrange Smart City portfolio in MENA
Orange Smart City portfolio in MENA
 
Governalia
GovernaliaGovernalia
Governalia
 
Orange Smart City in MENA, an outline
Orange Smart City in MENA, an outlineOrange Smart City in MENA, an outline
Orange Smart City in MENA, an outline
 
Government’s digital future & NAO’s changing approach
Government’s digital future & NAO’s changing approachGovernment’s digital future & NAO’s changing approach
Government’s digital future & NAO’s changing approach
 
Smart city leboucher
Smart city leboucherSmart city leboucher
Smart city leboucher
 
From Knowledge Economy to Inclusive Information Society. Experiences from Ind...
From Knowledge Economy to Inclusive Information Society. Experiences from Ind...From Knowledge Economy to Inclusive Information Society. Experiences from Ind...
From Knowledge Economy to Inclusive Information Society. Experiences from Ind...
 
Ibm smart cloud solutions m-cloud
Ibm smart cloud solutions   m-cloudIbm smart cloud solutions   m-cloud
Ibm smart cloud solutions m-cloud
 
Smarter Computing in a New Era of IT - Dr. Gururaj Rao
Smarter Computing in a New Era of IT - Dr. Gururaj RaoSmarter Computing in a New Era of IT - Dr. Gururaj Rao
Smarter Computing in a New Era of IT - Dr. Gururaj Rao
 
Introduction for Korea IT Industry Promotion Agency
Introduction for Korea IT Industry Promotion AgencyIntroduction for Korea IT Industry Promotion Agency
Introduction for Korea IT Industry Promotion Agency
 
Leading in the converged future becoming an agile telco
Leading in the converged future becoming an agile telcoLeading in the converged future becoming an agile telco
Leading in the converged future becoming an agile telco
 
Mobile Developer 101 (mHealth Edition)
Mobile Developer 101 (mHealth Edition)Mobile Developer 101 (mHealth Edition)
Mobile Developer 101 (mHealth Edition)
 

Similaire à Shuky peleg e_gov_cyber_presentation_information_sharing

PSN Summit - Session A1 - Building on PSN
PSN Summit - Session A1 - Building on PSNPSN Summit - Session A1 - Building on PSN
PSN Summit - Session A1 - Building on PSNMikePSNGB
 
Information Society SA, Public Sector ICT CeBIT 2013 presentation
Information Society SA, Public Sector ICT CeBIT 2013 presentationInformation Society SA, Public Sector ICT CeBIT 2013 presentation
Information Society SA, Public Sector ICT CeBIT 2013 presentationInformation Society SA
 
IJCER (www.ijceronline.com) International Journal of computational Engineeri...
 IJCER (www.ijceronline.com) International Journal of computational Engineeri... IJCER (www.ijceronline.com) International Journal of computational Engineeri...
IJCER (www.ijceronline.com) International Journal of computational Engineeri...ijceronline
 
e-Government introduction
e-Government introductione-Government introduction
e-Government introductionMuhammad Farooq
 
eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...
eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...
eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...Arab Federation for Digital Economy
 
Government ic tv3
Government ic tv3Government ic tv3
Government ic tv3JOEL0607
 
Mobile payments will only be able to disrupt if user is king.
Mobile payments will only be able to disrupt if user is king. Mobile payments will only be able to disrupt if user is king.
Mobile payments will only be able to disrupt if user is king. Tieto Corporation
 
Enabling the digital economy: Postal services 2020
Enabling the digital economy: Postal services 2020Enabling the digital economy: Postal services 2020
Enabling the digital economy: Postal services 2020angelic961
 
Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...
Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...
Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...Smart Cities Project
 
Business Model - EasyTaxi
Business Model - EasyTaxiBusiness Model - EasyTaxi
Business Model - EasyTaxiThiago Paiva
 
Microsoft Power Point BAHWAN CYBERTEK Corporate Profile
Microsoft Power Point   BAHWAN CYBERTEK Corporate ProfileMicrosoft Power Point   BAHWAN CYBERTEK Corporate Profile
Microsoft Power Point BAHWAN CYBERTEK Corporate Profileindiraniyazali
 
CSI Piemonte international
CSI Piemonte internationalCSI Piemonte international
CSI Piemonte internationalDebora Colò
 
MphasiS - insurance and technology
MphasiS -  insurance and technologyMphasiS -  insurance and technology
MphasiS - insurance and technologyMphasis
 
Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011
Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011
Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011QITCOM
 

Similaire à Shuky peleg e_gov_cyber_presentation_information_sharing (20)

Huawei eCtiy solution
Huawei eCtiy solutionHuawei eCtiy solution
Huawei eCtiy solution
 
eGovernment in Israel
eGovernment in IsraeleGovernment in Israel
eGovernment in Israel
 
PSN Summit - Session A1 - Building on PSN
PSN Summit - Session A1 - Building on PSNPSN Summit - Session A1 - Building on PSN
PSN Summit - Session A1 - Building on PSN
 
Information Society SA, Public Sector ICT CeBIT 2013 presentation
Information Society SA, Public Sector ICT CeBIT 2013 presentationInformation Society SA, Public Sector ICT CeBIT 2013 presentation
Information Society SA, Public Sector ICT CeBIT 2013 presentation
 
IJCER (www.ijceronline.com) International Journal of computational Engineeri...
 IJCER (www.ijceronline.com) International Journal of computational Engineeri... IJCER (www.ijceronline.com) International Journal of computational Engineeri...
IJCER (www.ijceronline.com) International Journal of computational Engineeri...
 
e-Government introduction
e-Government introductione-Government introduction
e-Government introduction
 
eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...
eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...
eGovernment Transformation: GCC eServices Delivery Standards and Recent Devel...
 
10 Living Labs and Smart Cities Margarete Donovang-Kuhlisch
10 Living Labs and Smart Cities Margarete Donovang-Kuhlisch10 Living Labs and Smart Cities Margarete Donovang-Kuhlisch
10 Living Labs and Smart Cities Margarete Donovang-Kuhlisch
 
Government ic tv3
Government ic tv3Government ic tv3
Government ic tv3
 
Mobile payments will only be able to disrupt if user is king.
Mobile payments will only be able to disrupt if user is king. Mobile payments will only be able to disrupt if user is king.
Mobile payments will only be able to disrupt if user is king.
 
Enabling the digital economy: Postal services 2020
Enabling the digital economy: Postal services 2020Enabling the digital economy: Postal services 2020
Enabling the digital economy: Postal services 2020
 
Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...
Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...
Smart Cities - Learning from Intel Cities - The Community of Practice as a vi...
 
Ne gp
Ne gpNe gp
Ne gp
 
Business Model - EasyTaxi
Business Model - EasyTaxiBusiness Model - EasyTaxi
Business Model - EasyTaxi
 
Microsoft Power Point BAHWAN CYBERTEK Corporate Profile
Microsoft Power Point   BAHWAN CYBERTEK Corporate ProfileMicrosoft Power Point   BAHWAN CYBERTEK Corporate Profile
Microsoft Power Point BAHWAN CYBERTEK Corporate Profile
 
Shared Services In Government A Model For The Web
Shared Services In Government   A Model For The WebShared Services In Government   A Model For The Web
Shared Services In Government A Model For The Web
 
CSI Piemonte international
CSI Piemonte internationalCSI Piemonte international
CSI Piemonte international
 
MphasiS - insurance and technology
MphasiS -  insurance and technologyMphasiS -  insurance and technology
MphasiS - insurance and technology
 
Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011
Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011
Mr. Ali Bin Saleh Al-Soma's presentation at QITCOM 2011
 
The Development of Digital Economy
The Development of Digital EconomyThe Development of Digital Economy
The Development of Digital Economy
 

Plus de E-Government Center Moldova

The nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data AnalyticsThe nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data AnalyticsE-Government Center Moldova
 
Prezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariucPrezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariucE-Government Center Moldova
 
Can e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterCan e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterE-Government Center Moldova
 
Driving government efficiency and innovation through cloud computing k...
Driving government efficiency and  innovation through      cloud computing  k...Driving government efficiency and  innovation through      cloud computing  k...
Driving government efficiency and innovation through cloud computing k...E-Government Center Moldova
 
Unleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moranUnleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moranE-Government Center Moldova
 
Government innovation through cloud computing arthur riel
Government innovation through cloud computing arthur rielGovernment innovation through cloud computing arthur riel
Government innovation through cloud computing arthur rielE-Government Center Moldova
 

Plus de E-Government Center Moldova (20)

The new era of smart
The new era of smart The new era of smart
The new era of smart
 
The nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data AnalyticsThe nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data Analytics
 
Digital Transformation by Richard Baird
Digital Transformation by Richard BairdDigital Transformation by Richard Baird
Digital Transformation by Richard Baird
 
Mpay&Mcloud
Mpay&McloudMpay&Mcloud
Mpay&Mcloud
 
Presentation cert gov-md 05.03.2013
Presentation cert gov-md 05.03.2013Presentation cert gov-md 05.03.2013
Presentation cert gov-md 05.03.2013
 
Hannes astok data protection agency
Hannes astok data protection agencyHannes astok data protection agency
Hannes astok data protection agency
 
Prezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariucPrezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariuc
 
Hannes astok policy development
Hannes astok policy developmentHannes astok policy development
Hannes astok policy development
 
Digital security hannes astok
Digital security hannes astokDigital security hannes astok
Digital security hannes astok
 
Assessing cybersecurity_Anto Veldre
Assessing cybersecurity_Anto VeldreAssessing cybersecurity_Anto Veldre
Assessing cybersecurity_Anto Veldre
 
MCloud operational framework
MCloud operational frameworkMCloud operational framework
MCloud operational framework
 
Arhitectura de securitate_MCloud
Arhitectura de securitate_MCloudArhitectura de securitate_MCloud
Arhitectura de securitate_MCloud
 
Ibm security virtual server protection
Ibm security virtual server protectionIbm security virtual server protection
Ibm security virtual server protection
 
Can e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterCan e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedter
 
Driving government efficiency and innovation through cloud computing k...
Driving government efficiency and  innovation through      cloud computing  k...Driving government efficiency and  innovation through      cloud computing  k...
Driving government efficiency and innovation through cloud computing k...
 
Star storage m cloud week
Star storage m cloud weekStar storage m cloud week
Star storage m cloud week
 
Unleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moranUnleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moran
 
Government innovation through cloud computing arthur riel
Government innovation through cloud computing arthur rielGovernment innovation through cloud computing arthur riel
Government innovation through cloud computing arthur riel
 
4 francisco garcia_moran_moldova_2013
4 francisco garcia_moran_moldova_20134 francisco garcia_moran_moldova_2013
4 francisco garcia_moran_moldova_2013
 
3 platforma tehnologica_m-cloud
3 platforma tehnologica_m-cloud3 platforma tehnologica_m-cloud
3 platforma tehnologica_m-cloud
 

Shuky peleg e_gov_cyber_presentation_information_sharing

  • 1. Information Sharing A requirement for Cyber Defense Shuky Peleg, CISA, CISSP Head of Information Security, eGov October 2012 | Ministry of Finance - eGovernment
  • 2. What is eGov? Providing citizens and businesses with better access to government information. eGov simplifies and shortens bureaucratic processes, offers online services and implements advanced government technologies in order to benefit citizens and businesses.
  • 3. Improving Improving Raising government’s service image Saving government for money production businesses Better New service for online citizens services Increasing efficiency Reducing bureaucracy Vision Raising productivity and Increasing Goals transparency Managing platform for 24/7 Providing Technological inter-ministries service better, processes efficient advancements online service
  • 4. eGov The Internet Frontier of the Israeli Government  eGov Services for Citizens and Businesses  Secure ISP/ASP/ESB/Connectivity providers for the Ministries  IT & Cyber Security Service Providers for Ministries  Knowledge Center and coordination body for IT & Cyber Security (CERT, SIEM, Threat and Malware Research)
  • 5. eGov  Number of employees : ~250, all technology experts.  The E-Government unit is built entirely from Hi-tech professionals, employed by government tenders for technology services.  Part of E-Government projects are carried out using full outsourcing.  E-Government is regulated by NISA.  All e-Government employees have required level of security clearance
  • 6. eGov Topology Government Offices Government Network e-Gov Internet Citizen Business Citizen Business
  • 7. Personalization My Gov | Smart ID Doing Building Property or MASLOL business Business permits registration Service Cellular | Multi-channels Web stations IVR Social media | Media and Shituf government Gov 2.0 | Customer transparency contact data gov service Gov Servie eGov Standards bus Gov X report Government Search MASE information Gov.il kids engine project Online Payment Forms services service service Web hosting Information ISP BCP/DRP and Email security 7 1997/8 2000/1 2002/3 2004/5 2006 2007 2008 2009 2010 2011 2011/2
  • 8. eGov Security Group  An inherent part of eGov core activity  A technology leader  A knowledge center and a public sector focal point for all ICT security issues  Promoting Israeli Information Security technologies
  • 9. Main Threats  Defacement of Government Sites  Bank of Israel - 2008  Denial of Service attacks  “Cast Lead” in Gaza - 2009  Theft/Corruption of Government Data  Corruption / disturbance to National Critical Infrastructure  Theft of services or money from the Government (E- Commerce)  Identity fraud / theft (E-Forms, PKI Infrastructure)  Information Leakage  Using Government Infrastructure as enabler / facilitator of Cyber conflict  Using Public Infrastructure as enabler / facilitator of Cyber conflict
  • 10. Main Protection Principles  Separation of duties  Segregation of Networks  Log Everything  Pass only what we can monitor  No remote administration  No single point of failure - “2 mistakes”  Secure Development Lifecycle  Identifying Cross-application and cross-domain influences
  • 11. Organizational Chart Head of Head of IT Information Infrastructure Security Cyber, Information Operation Centre Technology and Methodology and Security Systems Incident Response Application (Network and Hosting Services Team Administration Security Team Officer Security) 1st Level Security Platforms and Security CERT and Analysis Pen. Testing Monitoring and Systems Implementation response Hardening (AV, FW, Mail…) 2nd Level Monitoring and Forensics Security Research
  • 12. Regulatory Environment Industry NISA Standards Critical and Infrastructure Government Regulations: CIO ISO 27001, PCI Privacy ILITA National Cyber Bureau Self National and Regulation Internationals and Best Laws and Practices… Regulations
  • 13. Cooperation efforts Standards Industry Israeli and institution Peers foreign CERT of Israel organizations National Cyber Bureau Israeli Cyber Defense technology Community companies Government Peers enterprises Universities and research intuitions
  • 14. Focus on the CERT Organization
  • 15. Member in a Global CERT Org.
  • 16. Creation of a Nation-Wide View National CERT Procedures, Guidelines and Immediate Actions Government )CERT.Gov.il( Academy )CERT.ac.il( Alerts Private Sector Financial Sector Critical Infrastructure Defense Procedures, Guidelines and Immediate Actions Transportation Government Public Sector Universities Telecomm Industries Insurance Colleges Defense Banking Military Offices Energy Water e-Gov SMBs ISPs
  • 17. Our Legacy Our Routine Our Vision Protecting Participate in Serving as a liaison Government Internet designing secured between the public Gateway and Servers systems and and cyber defense preventing malicious agencies and intents via advanced government bodies monitoring to protect our way of life in the information era. 20
  • 18. Ministry of Finance –E-Government Division Thank you !