SlideShare une entreprise Scribd logo
1  sur  31
Standards, Security, and Audit
Smart Cities – The Security Aspects
Graeme Parker
Managing Director - Parker Solutions Group
Extensive experience delivering Cyber Security, Business Continuity and Risk
Management solutions in multiple sectors including Government, Financial
Services, City Authorities, Health Services, Electrical and Power to
organizations across the globe.
Graeme provides consulting at the strategic, tactical and operational levels,
conducts and leads audits and leads numerous training events worldwide.
Contact Information
+44(0)1609 760293
graeme@parkersolutionsgroup.co.uk
www.parkersolutionsgroup.co.uk
https://uk.linkedin.com/in/graemeparker
twitter.com/parkerinfosol
https://www.facebook.com/Parker-
Solutions-Group-113377915344272/
3
City, Town, Municipality
Definition
• a large or important town.
• (in the U.S.) an incorporated municipality, usually governed by a
mayor and a board of aldermen or councilmen.
• the inhabitants of a city collectively:
• The entire city is mourning his death.
• (in Canada) a municipality of high rank, usually based on population.
• (in Great Britain) a borough, usually the seat of a bishop, upon
which the dignity of the title has been conferred by the crown.
• the commercial and financial area of London, England.
• a city-state.
4
Urbanization
UN 2015
• 50% of today’s world population live in urban areas (3.5 Billion)
• By 2030 this is predicted to rise to 60%
• 60% then now will be much different to 60% today
• 1 in 8 currently live in one of the worlds 28 “Mega Cities”
• By 2050 it is predicted that 64% of the developing world and 86% of
the developed world will be “urbanized”
• 95% of Urban Growth by 2050 is expected to take place in
developing countries
5
Challenges and Opportunities
Challenges
• Greater demand for natural resources – e.g. water and energy
• Demands on services – Education, healthcare, waste management
etc.
• Increasing pollution and impacts on biodiversity
• Climate change impact – cities take up 2% of Earths land but
account for 80% energy use and 75% carbon emissions (UN 2014)
• Pressure on housing and other resources can contribute to poverty
and crime and other social problems
• Cities are at risk of climate change impacts such as flooding and
weather events.
6
Challenges and Opportunities
Its not all bad..
Cities provide many opportunities including:
• Job and career opportunities
• Flow of ideas and business
• Ability to meet social aspirations of people
• Global connectivity and influence
• Incubators for new ideas, business and innovation
• Centres for education and learning
7
Rising to the Challenge
To meet these challenges cities are aiming to become:
But what does that mean??
8
Smart City
BSI 2014 one of many definitions
‘the effective integration of physical, digital and human systems
in the built environment to deliver sustainable, prosperous and
inclusive future for its citizens’ (BSI, 2014).
9
Smart City Vision
http://in.nec.com/en_IN/blog/smart-cities-
shaping-indias-future.html
10
Smart City Examples
Masdar City – A brand new sustainable City
11
Smart City Examples
Rio – An existing city adopting Smart technologies
12
Smart Cities Core Elements
Element Issues
Citizens Trust, accessibility, ease of use, top
down/bottom up, co-creation
Leadership and Strategy Strategy, effective leadership, inclusive
decision making, stakeholder
engagement, partnerships
Innovation and Enterprise Ecosystems, data economy, finance
business models
Infrastructure, technology, and data Future proofing, resilience, sensors, data,
privacy, security and ethics
Measurement and learning City performance, metrics and indicators,
ideas sharing
13
Open Data
Open Data Institute
Open data is data that anyone can access, use or share. Simple
as that. When big companies or governments release non-
personal data, it enables small businesses, citizens and medical
researchers to develop resources which make crucial
improvements to their communities.
14
Smart City Information and System Assets
City Assets
Assets
Infrastructure Publically Owned
Private sector infrastructure
Citizen owned data
Open data
Private data
Sensors and IoT devices
Industrial Control Systems
Citizen assets
Databases
Applications
Smart Devices
15
Threats – Traditional definition
ISO 27000, clause 2.77
Potential cause of an unwanted incident
which may result in harm to a system or an
organization
But what about the city?
The harm is much wider!!
16
Sources of Threat
Threat Source Examples
1 Organized Crime
Theft of personal data
Ransomware
2 Terrorist Groups
Distributed Denial of Service Attack
Intelligence gathering
3 Disgruntled Citizens
Service disruption
Website de-facement
4 Suppliers
Human error
Design and security flaws
5 Foreign Intelligence or Hostile
State
Eavesdropping and surveillance
Sabotage
6 Commercial Entities
Resale of citizen data
Invasion of privacy
7 Natural Events
Floods
Power Outages
17
Security Programme
A city wide security programme is required
To manage the many different assets and potential risks a city
wide security programme is needed
• All cities differ in terms of stakeholders and their contribution
to security but ultimately security policy should be set by the
city authorities (e.g. sponsors of the city initiatives)
But where do we start? Are there any standards?
18
Smart City Standards
BSI
PAS 180:2014 – Smart Cities – Vocabulary
PAS 181:2014 – Smart city framework – Guide to establishing
strategies for smart cities and communities
PAS 182:2014 – Smart city concept model – Guide for establishing a
model for data interoperability
Hypercat – A standard for secure and interoperable IoT for Cities – PAS
212:2016 – Automatic resource discovery for the Internet of Things –
Specification
ITU – FGSSC – Sustainable Cities Focus Groups
19
Security Standards
Standard Purpose
ISO/IEC 27001 Specifies the requirements for an Information
Security Management System
ISO/IEC 27002 Specifies a code of practice and security controls
to manager risks
NIST SP 800-82 Specifies a security programme and control for
SCADA and Industrial Control Systems
OWASP Describes web application security controls
PCI-DSS Details requirements for the security of
cardholder data
ISO/IEC 29100 Specifies the requirements for a Privacy
Framework
Government Standards and
Guides
Designed to address local risks and protect
government assets
ISO/IEC 27035 Designed for Incident Response
But where is the IOT Security Standards???
20
Highlights of the Smart City Security Programme
• Clearly Defined Roles and Responsibilities
• Clear Asset Ownership
• Security by Design
• Privacy Impact Assessments
• Vendor Management and Partnership
• Engagement with Authorities
• Citizen Education and Engagement
• Security Incident Response Processes
21
Roles and Responsbilities
• Roles and Asset Ownership need to be clear
• This could be within a city authority, vendor, or other
organisation but must be clear to all involved
22
Highlights of the Smart City Security Programme
Security by Design
• Security by design means:
• Ensuring security professionals are engaged from the initiation of an
idea
• Defining an approach to Security Architecture
• Ensuring relevant security standards are consulted and minimum
standards are defined
• Challenging vendors and suppliers to meet standards
• Making security criteria part of quality criteria
• Ensuring security is tested at logical points with clear acceptance
criteria
• Considering an Accreditation Strategy
• Agile is not a reason to ignore all of the above
23
Highlights of the Smart City Security Programme
Privacy by Design
• If we consider Security by Design then we need to also consider Citizens
Privacy
• Privacy Impact Assessments should be integral to the launch of all new
Citizen services or to changes in Citizen Services
Privacy impact assessments (PIAs) are a tool that you can use to identify and
reduce the privacy risks of your projects. A PIA can reduce the risks of harm to
individuals through the misuse of their personal information. It can also help
you to design more efficient and effective processes for handling personal
data.
- UK Information Commissioner
24
Highlights of the Smart City Security Programme
Vendor Management
For most smart cities vendors will be appointed or even play an
integral role through public/private partnerships or joint
ventures.
• Ensuring that vendors at all levels address security issues is
vital.
• An error in the chain can have significant impacts
• A clear vendor management process will be central to the
programme.
25
Engagement with Authorities
National, Regional and International Standards
City Authorities should stay ahead of developments and can play
a key role in shaping future standards, laws and regulations.
This could be at an International Level – E.g. ISO standards.
Sector level – E.g. influencing standards on IoT security amongst
vendors
Multinational Level – E.g. influencing policy or guidance at EU or
OECD level
26
Citizen Engagement and Education
Smart Citizens
Engaging Citizens is key to seizing the opportunities of Smart
Cities. It can also ensure understand their rights and how they
can protect themselves and other stakeholders
Citizens can be:
• Consumers
• Producer
• Prosumer
• Co-creators
27
Citizen Engagement and Education
Smart Citizens
How to engage and educate?
• Community Platforms such as Smart Citizen
• Projects aimed at all age groups and sectors of society
• Project Engagement – Waag Society
• Hackathons
• Soliciting feedback/surveys
• Information Security Awareness Campaigns
• Engagement events
28
IncidentsDisaster
Management Incidents and Events
High Risk occurrence
and low impact
Low Risk occurrence and
high impact
 Managed by the incident management
process
 Managed by the business continuity and
emergency management processes
Management of Residual Risk
29
Key Messages
• Smart City Security is a multi stakeholder activity
• It takes leadership and engagement
• It is vital not just to protect information but to protect citizens
and everything that a citizens depend upon
• It is a mutli disciplinary activity with security touching every
part of smart city planning, development, maintenance and
operations
• Industry needs to work on IoT Security Standards so we can
be confident in the devices deployed in Smart Cities
30
Key Messages
A Truly Smart City
http://in.nec.com/en_IN/blog/smart-cities-
shaping-indias-future.html
THANK YOU
?
123 456 789
name.surname@domain.com
www.domain.com
linkedin.com/name.surname
twitter.com/name.surname
fb.com/name.surname

Contenu connexe

Tendances

Internet of things (IoT)
Internet of things (IoT)Internet of things (IoT)
Internet of things (IoT)Tarika Verma
 
Overcoming the cybersecurity challenges of smart cities
Overcoming the cybersecurity challenges of smart citiesOvercoming the cybersecurity challenges of smart cities
Overcoming the cybersecurity challenges of smart citiesSaeed Al Dhaheri
 
Introduction to IOT & Smart City
Introduction to IOT & Smart CityIntroduction to IOT & Smart City
Introduction to IOT & Smart CityDr. Mazlan Abbas
 
Internet of things startup basic
Internet of things  startup basicInternet of things  startup basic
Internet of things startup basicMathan kumar
 
Internet of Things Iot presentation with module
Internet of Things Iot presentation with moduleInternet of Things Iot presentation with module
Internet of Things Iot presentation with moduleIsp university Multan
 
The Role of Big Data in Smart Cities
The Role of Big Data in Smart CitiesThe Role of Big Data in Smart Cities
The Role of Big Data in Smart CitiesSuyati Technologies
 
iot smart city project
iot smart city projectiot smart city project
iot smart city projectbmuhire
 
Internet of Things for Smart Cities
Internet of Things for Smart CitiesInternet of Things for Smart Cities
Internet of Things for Smart CitiesMphasis
 
Internet of Things and its applications
Internet of Things and its applicationsInternet of Things and its applications
Internet of Things and its applicationsPasquale Puzio
 
Challenges and application of Internet of Things
Challenges and application of Internet of ThingsChallenges and application of Internet of Things
Challenges and application of Internet of ThingsAshutosh Bhardwaj
 
Internet of things
Internet of thingsInternet of things
Internet of thingsNaiyer Khan
 
IoT Security: Problems, Challenges and Solutions
IoT Security: Problems, Challenges and SolutionsIoT Security: Problems, Challenges and Solutions
IoT Security: Problems, Challenges and SolutionsLiwei Ren任力偉
 
Smart city implication on future urban mobility and transportation
Smart city implication on future urban mobility and transportationSmart city implication on future urban mobility and transportation
Smart city implication on future urban mobility and transportationSuvodip Das
 
How to make Smart City a Reality?
How to make Smart City a Reality?How to make Smart City a Reality?
How to make Smart City a Reality?Jong-Sung Hwang
 
Internet of things (IOT)
Internet of things (IOT)Internet of things (IOT)
Internet of things (IOT)Oshin Kandpal
 

Tendances (20)

Internet of things (IoT)
Internet of things (IoT)Internet of things (IoT)
Internet of things (IoT)
 
Overcoming the cybersecurity challenges of smart cities
Overcoming the cybersecurity challenges of smart citiesOvercoming the cybersecurity challenges of smart cities
Overcoming the cybersecurity challenges of smart cities
 
Introduction to IOT & Smart City
Introduction to IOT & Smart CityIntroduction to IOT & Smart City
Introduction to IOT & Smart City
 
Internet of things startup basic
Internet of things  startup basicInternet of things  startup basic
Internet of things startup basic
 
Internet of Things Iot presentation with module
Internet of Things Iot presentation with moduleInternet of Things Iot presentation with module
Internet of Things Iot presentation with module
 
The Role of Big Data in Smart Cities
The Role of Big Data in Smart CitiesThe Role of Big Data in Smart Cities
The Role of Big Data in Smart Cities
 
iot smart city project
iot smart city projectiot smart city project
iot smart city project
 
Internet of Things for Smart Cities
Internet of Things for Smart CitiesInternet of Things for Smart Cities
Internet of Things for Smart Cities
 
The future of IOT
The future of IOTThe future of IOT
The future of IOT
 
Future of IOT
Future of IOTFuture of IOT
Future of IOT
 
Internet of Things and its applications
Internet of Things and its applicationsInternet of Things and its applications
Internet of Things and its applications
 
Challenges and application of Internet of Things
Challenges and application of Internet of ThingsChallenges and application of Internet of Things
Challenges and application of Internet of Things
 
Iot and ai
Iot and aiIot and ai
Iot and ai
 
Internet of things
Internet of thingsInternet of things
Internet of things
 
Iot audit
Iot auditIot audit
Iot audit
 
IOT in SMART Cities
IOT in SMART CitiesIOT in SMART Cities
IOT in SMART Cities
 
IoT Security: Problems, Challenges and Solutions
IoT Security: Problems, Challenges and SolutionsIoT Security: Problems, Challenges and Solutions
IoT Security: Problems, Challenges and Solutions
 
Smart city implication on future urban mobility and transportation
Smart city implication on future urban mobility and transportationSmart city implication on future urban mobility and transportation
Smart city implication on future urban mobility and transportation
 
How to make Smart City a Reality?
How to make Smart City a Reality?How to make Smart City a Reality?
How to make Smart City a Reality?
 
Internet of things (IOT)
Internet of things (IOT)Internet of things (IOT)
Internet of things (IOT)
 

Similaire à Smart Cities – The Security Aspects

Smart Cities - The Security Aspects
Smart Cities - The Security AspectsSmart Cities - The Security Aspects
Smart Cities - The Security AspectsGraeme Parker
 
John Bosco Arends- Emerging Threats Against Public Sector
John Bosco Arends- Emerging Threats Against Public SectorJohn Bosco Arends- Emerging Threats Against Public Sector
John Bosco Arends- Emerging Threats Against Public Sectoritnewsafrica
 
A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...Judith Beckhard Cardoso
 
Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...
Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...
Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...Smart City
 
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMwareVMUG IT
 
White Paper on Smart Cities
White Paper on Smart CitiesWhite Paper on Smart Cities
White Paper on Smart CitiesDAYWATCHER.COM
 
ISO Smart City Infrastucture Frameworkv2
ISO Smart City Infrastucture Frameworkv2ISO Smart City Infrastucture Frameworkv2
ISO Smart City Infrastucture Frameworkv2Jonathan L. Tan, M.B.A.
 
A Quintessential smart city infrastructure framework for all stakeholders
A Quintessential smart city infrastructure framework for all stakeholdersA Quintessential smart city infrastructure framework for all stakeholders
A Quintessential smart city infrastructure framework for all stakeholdersJonathan L. Tan, M.B.A.
 
Breaking down the cyber security framework closing critical it security gaps
Breaking down the cyber security framework closing critical it security gapsBreaking down the cyber security framework closing critical it security gaps
Breaking down the cyber security framework closing critical it security gapsIBM Security
 
SMARTCITY –a hype or reality ?
SMARTCITY –a hype or reality ?SMARTCITY –a hype or reality ?
SMARTCITY –a hype or reality ?Panduit
 
Analysis of smart city opportunities in latin america
Analysis of smart city opportunities in latin americaAnalysis of smart city opportunities in latin america
Analysis of smart city opportunities in latin americaLeandro Scalize
 
Future of digital identity Programme summary - 15 dec 2018 lr
Future of digital identity  Programme summary - 15 dec 2018 lrFuture of digital identity  Programme summary - 15 dec 2018 lr
Future of digital identity Programme summary - 15 dec 2018 lrFuture Agenda
 

Similaire à Smart Cities – The Security Aspects (20)

Smart Cities - The Security Aspects
Smart Cities - The Security AspectsSmart Cities - The Security Aspects
Smart Cities - The Security Aspects
 
John Bosco Arends- Emerging Threats Against Public Sector
John Bosco Arends- Emerging Threats Against Public SectorJohn Bosco Arends- Emerging Threats Against Public Sector
John Bosco Arends- Emerging Threats Against Public Sector
 
Securing Smart Cities
Securing Smart CitiesSecuring Smart Cities
Securing Smart Cities
 
A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...
 
Smart cities
Smart citiesSmart cities
Smart cities
 
Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...
Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...
Making a Smart Community: Finding Resiliency & Efficiencies through Infrastru...
 
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
 
White Paper on Smart Cities
White Paper on Smart CitiesWhite Paper on Smart Cities
White Paper on Smart Cities
 
ISO Smart City Infrastucture Frameworkv2
ISO Smart City Infrastucture Frameworkv2ISO Smart City Infrastucture Frameworkv2
ISO Smart City Infrastucture Frameworkv2
 
AM Briefing: Security for the internet of things
AM Briefing: Security for the internet of things AM Briefing: Security for the internet of things
AM Briefing: Security for the internet of things
 
Tan smart city infrastucture framework
Tan smart city infrastucture frameworkTan smart city infrastucture framework
Tan smart city infrastucture framework
 
Tan Smart City Infrastucture Framework
Tan Smart City Infrastucture FrameworkTan Smart City Infrastucture Framework
Tan Smart City Infrastucture Framework
 
A Quintessential smart city infrastructure framework for all stakeholders
A Quintessential smart city infrastructure framework for all stakeholdersA Quintessential smart city infrastructure framework for all stakeholders
A Quintessential smart city infrastructure framework for all stakeholders
 
Tan Smart City Infrastucture Framework
Tan Smart City Infrastucture FrameworkTan Smart City Infrastucture Framework
Tan Smart City Infrastucture Framework
 
Breaking down the cyber security framework closing critical it security gaps
Breaking down the cyber security framework closing critical it security gapsBreaking down the cyber security framework closing critical it security gaps
Breaking down the cyber security framework closing critical it security gaps
 
SMARTCITY –a hype or reality ?
SMARTCITY –a hype or reality ?SMARTCITY –a hype or reality ?
SMARTCITY –a hype or reality ?
 
MESA- Cyber & Smart Cities - Updated
MESA- Cyber & Smart Cities - UpdatedMESA- Cyber & Smart Cities - Updated
MESA- Cyber & Smart Cities - Updated
 
Smart cities presentation
Smart cities presentationSmart cities presentation
Smart cities presentation
 
Analysis of smart city opportunities in latin america
Analysis of smart city opportunities in latin americaAnalysis of smart city opportunities in latin america
Analysis of smart city opportunities in latin america
 
Future of digital identity Programme summary - 15 dec 2018 lr
Future of digital identity  Programme summary - 15 dec 2018 lrFuture of digital identity  Programme summary - 15 dec 2018 lr
Future of digital identity Programme summary - 15 dec 2018 lr
 

Plus de PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 

Plus de PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Dernier

Food safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfFood safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfSherif Taha
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...Nguyen Thanh Tu Collection
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfDr Vijay Vishwakarma
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfNirmal Dwivedi
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxDenish Jangid
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxDr. Sarita Anand
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Jisc
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.pptRamjanShidvankar
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.MaryamAhmad92
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structuredhanjurrannsibayan2
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxmarlenawright1
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfPoh-Sun Goh
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...Poonam Aher Patil
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSCeline George
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxheathfieldcps1
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxVishalSingh1417
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxJisc
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseAnaAcapella
 

Dernier (20)

Food safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfFood safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdf
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
Spatium Project Simulation student brief
Spatium Project Simulation student briefSpatium Project Simulation student brief
Spatium Project Simulation student brief
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structure
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdf
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please Practise
 

Smart Cities – The Security Aspects

  • 1. Standards, Security, and Audit Smart Cities – The Security Aspects
  • 2. Graeme Parker Managing Director - Parker Solutions Group Extensive experience delivering Cyber Security, Business Continuity and Risk Management solutions in multiple sectors including Government, Financial Services, City Authorities, Health Services, Electrical and Power to organizations across the globe. Graeme provides consulting at the strategic, tactical and operational levels, conducts and leads audits and leads numerous training events worldwide. Contact Information +44(0)1609 760293 graeme@parkersolutionsgroup.co.uk www.parkersolutionsgroup.co.uk https://uk.linkedin.com/in/graemeparker twitter.com/parkerinfosol https://www.facebook.com/Parker- Solutions-Group-113377915344272/
  • 3. 3 City, Town, Municipality Definition • a large or important town. • (in the U.S.) an incorporated municipality, usually governed by a mayor and a board of aldermen or councilmen. • the inhabitants of a city collectively: • The entire city is mourning his death. • (in Canada) a municipality of high rank, usually based on population. • (in Great Britain) a borough, usually the seat of a bishop, upon which the dignity of the title has been conferred by the crown. • the commercial and financial area of London, England. • a city-state.
  • 4. 4 Urbanization UN 2015 • 50% of today’s world population live in urban areas (3.5 Billion) • By 2030 this is predicted to rise to 60% • 60% then now will be much different to 60% today • 1 in 8 currently live in one of the worlds 28 “Mega Cities” • By 2050 it is predicted that 64% of the developing world and 86% of the developed world will be “urbanized” • 95% of Urban Growth by 2050 is expected to take place in developing countries
  • 5. 5 Challenges and Opportunities Challenges • Greater demand for natural resources – e.g. water and energy • Demands on services – Education, healthcare, waste management etc. • Increasing pollution and impacts on biodiversity • Climate change impact – cities take up 2% of Earths land but account for 80% energy use and 75% carbon emissions (UN 2014) • Pressure on housing and other resources can contribute to poverty and crime and other social problems • Cities are at risk of climate change impacts such as flooding and weather events.
  • 6. 6 Challenges and Opportunities Its not all bad.. Cities provide many opportunities including: • Job and career opportunities • Flow of ideas and business • Ability to meet social aspirations of people • Global connectivity and influence • Incubators for new ideas, business and innovation • Centres for education and learning
  • 7. 7 Rising to the Challenge To meet these challenges cities are aiming to become: But what does that mean??
  • 8. 8 Smart City BSI 2014 one of many definitions ‘the effective integration of physical, digital and human systems in the built environment to deliver sustainable, prosperous and inclusive future for its citizens’ (BSI, 2014).
  • 10. 10 Smart City Examples Masdar City – A brand new sustainable City
  • 11. 11 Smart City Examples Rio – An existing city adopting Smart technologies
  • 12. 12 Smart Cities Core Elements Element Issues Citizens Trust, accessibility, ease of use, top down/bottom up, co-creation Leadership and Strategy Strategy, effective leadership, inclusive decision making, stakeholder engagement, partnerships Innovation and Enterprise Ecosystems, data economy, finance business models Infrastructure, technology, and data Future proofing, resilience, sensors, data, privacy, security and ethics Measurement and learning City performance, metrics and indicators, ideas sharing
  • 13. 13 Open Data Open Data Institute Open data is data that anyone can access, use or share. Simple as that. When big companies or governments release non- personal data, it enables small businesses, citizens and medical researchers to develop resources which make crucial improvements to their communities.
  • 14. 14 Smart City Information and System Assets City Assets Assets Infrastructure Publically Owned Private sector infrastructure Citizen owned data Open data Private data Sensors and IoT devices Industrial Control Systems Citizen assets Databases Applications Smart Devices
  • 15. 15 Threats – Traditional definition ISO 27000, clause 2.77 Potential cause of an unwanted incident which may result in harm to a system or an organization But what about the city? The harm is much wider!!
  • 16. 16 Sources of Threat Threat Source Examples 1 Organized Crime Theft of personal data Ransomware 2 Terrorist Groups Distributed Denial of Service Attack Intelligence gathering 3 Disgruntled Citizens Service disruption Website de-facement 4 Suppliers Human error Design and security flaws 5 Foreign Intelligence or Hostile State Eavesdropping and surveillance Sabotage 6 Commercial Entities Resale of citizen data Invasion of privacy 7 Natural Events Floods Power Outages
  • 17. 17 Security Programme A city wide security programme is required To manage the many different assets and potential risks a city wide security programme is needed • All cities differ in terms of stakeholders and their contribution to security but ultimately security policy should be set by the city authorities (e.g. sponsors of the city initiatives) But where do we start? Are there any standards?
  • 18. 18 Smart City Standards BSI PAS 180:2014 – Smart Cities – Vocabulary PAS 181:2014 – Smart city framework – Guide to establishing strategies for smart cities and communities PAS 182:2014 – Smart city concept model – Guide for establishing a model for data interoperability Hypercat – A standard for secure and interoperable IoT for Cities – PAS 212:2016 – Automatic resource discovery for the Internet of Things – Specification ITU – FGSSC – Sustainable Cities Focus Groups
  • 19. 19 Security Standards Standard Purpose ISO/IEC 27001 Specifies the requirements for an Information Security Management System ISO/IEC 27002 Specifies a code of practice and security controls to manager risks NIST SP 800-82 Specifies a security programme and control for SCADA and Industrial Control Systems OWASP Describes web application security controls PCI-DSS Details requirements for the security of cardholder data ISO/IEC 29100 Specifies the requirements for a Privacy Framework Government Standards and Guides Designed to address local risks and protect government assets ISO/IEC 27035 Designed for Incident Response But where is the IOT Security Standards???
  • 20. 20 Highlights of the Smart City Security Programme • Clearly Defined Roles and Responsibilities • Clear Asset Ownership • Security by Design • Privacy Impact Assessments • Vendor Management and Partnership • Engagement with Authorities • Citizen Education and Engagement • Security Incident Response Processes
  • 21. 21 Roles and Responsbilities • Roles and Asset Ownership need to be clear • This could be within a city authority, vendor, or other organisation but must be clear to all involved
  • 22. 22 Highlights of the Smart City Security Programme Security by Design • Security by design means: • Ensuring security professionals are engaged from the initiation of an idea • Defining an approach to Security Architecture • Ensuring relevant security standards are consulted and minimum standards are defined • Challenging vendors and suppliers to meet standards • Making security criteria part of quality criteria • Ensuring security is tested at logical points with clear acceptance criteria • Considering an Accreditation Strategy • Agile is not a reason to ignore all of the above
  • 23. 23 Highlights of the Smart City Security Programme Privacy by Design • If we consider Security by Design then we need to also consider Citizens Privacy • Privacy Impact Assessments should be integral to the launch of all new Citizen services or to changes in Citizen Services Privacy impact assessments (PIAs) are a tool that you can use to identify and reduce the privacy risks of your projects. A PIA can reduce the risks of harm to individuals through the misuse of their personal information. It can also help you to design more efficient and effective processes for handling personal data. - UK Information Commissioner
  • 24. 24 Highlights of the Smart City Security Programme Vendor Management For most smart cities vendors will be appointed or even play an integral role through public/private partnerships or joint ventures. • Ensuring that vendors at all levels address security issues is vital. • An error in the chain can have significant impacts • A clear vendor management process will be central to the programme.
  • 25. 25 Engagement with Authorities National, Regional and International Standards City Authorities should stay ahead of developments and can play a key role in shaping future standards, laws and regulations. This could be at an International Level – E.g. ISO standards. Sector level – E.g. influencing standards on IoT security amongst vendors Multinational Level – E.g. influencing policy or guidance at EU or OECD level
  • 26. 26 Citizen Engagement and Education Smart Citizens Engaging Citizens is key to seizing the opportunities of Smart Cities. It can also ensure understand their rights and how they can protect themselves and other stakeholders Citizens can be: • Consumers • Producer • Prosumer • Co-creators
  • 27. 27 Citizen Engagement and Education Smart Citizens How to engage and educate? • Community Platforms such as Smart Citizen • Projects aimed at all age groups and sectors of society • Project Engagement – Waag Society • Hackathons • Soliciting feedback/surveys • Information Security Awareness Campaigns • Engagement events
  • 28. 28 IncidentsDisaster Management Incidents and Events High Risk occurrence and low impact Low Risk occurrence and high impact  Managed by the incident management process  Managed by the business continuity and emergency management processes Management of Residual Risk
  • 29. 29 Key Messages • Smart City Security is a multi stakeholder activity • It takes leadership and engagement • It is vital not just to protect information but to protect citizens and everything that a citizens depend upon • It is a mutli disciplinary activity with security touching every part of smart city planning, development, maintenance and operations • Industry needs to work on IoT Security Standards so we can be confident in the devices deployed in Smart Cities
  • 30. 30 Key Messages A Truly Smart City http://in.nec.com/en_IN/blog/smart-cities- shaping-indias-future.html
  • 31. THANK YOU ? 123 456 789 name.surname@domain.com www.domain.com linkedin.com/name.surname twitter.com/name.surname fb.com/name.surname

Notes de l'éditeur

  1. https://en.wikipedia.org/wiki/City A city is a large and permanent human settlement. Although there is no agreement on how a city is distinguished from a town in general English language meanings, many cities have a particular administrative, legal, or historical status based on local law. Cities generally have complex systems for sanitation, utilities, land usage, housing, and transportation. The concentration of development greatly facilitates interaction between people and businesses, sometimes benefiting both parties in the process, but it also presents challenges to managing urban growth. A big city or metropolis usually has associated suburbs and exurbs. Such cities are usually associated with metropolitan areas and urban areas, creating numerous business commuters traveling to urban centers for employment. Once a city expands far enough to reach another city, this region can be deemed a conurbation or megalopolis. Damascus is arguably the oldest city in the world. In terms of population, the largest city proper is Shanghai, while the fastest-growing is Dubai. The following article gives some interesting reading on urban growth: https://www.theguardian.com/cities/2015/nov/23/cities-in-numbers-how-patterns-of-urban-growth-change-the-world
  2. https://en.wikipedia.org/wiki/City A city is a large and permanent human settlement. Although there is no agreement on how a city is distinguished from a town in general English language meanings, many cities have a particular administrative, legal, or historical status based on local law. Cities generally have complex systems for sanitation, utilities, land usage, housing, and transportation. The concentration of development greatly facilitates interaction between people and businesses, sometimes benefiting both parties in the process, but it also presents challenges to managing urban growth. A big city or metropolis usually has associated suburbs and exurbs. Such cities are usually associated with metropolitan areas and urban areas, creating numerous business commuters traveling to urban centers for employment. Once a city expands far enough to reach another city, this region can be deemed a conurbation or megalopolis. Damascus is arguably the oldest city in the world. In terms of population, the largest city proper is Shanghai, while the fastest-growing is Dubai. The following article gives some interesting reading on urban growth: https://www.theguardian.com/cities/2015/nov/23/cities-in-numbers-how-patterns-of-urban-growth-change-the-world
  3. https://en.wikipedia.org/wiki/City A city is a large and permanent human settlement. Although there is no agreement on how a city is distinguished from a town in general English language meanings, many cities have a particular administrative, legal, or historical status based on local law. Cities generally have complex systems for sanitation, utilities, land usage, housing, and transportation. The concentration of development greatly facilitates interaction between people and businesses, sometimes benefiting both parties in the process, but it also presents challenges to managing urban growth. A big city or metropolis usually has associated suburbs and exurbs. Such cities are usually associated with metropolitan areas and urban areas, creating numerous business commuters traveling to urban centers for employment. Once a city expands far enough to reach another city, this region can be deemed a conurbation or megalopolis. Damascus is arguably the oldest city in the world. In terms of population, the largest city proper is Shanghai, while the fastest-growing is Dubai. The following article gives some interesting reading on urban growth: https://www.theguardian.com/cities/2015/nov/23/cities-in-numbers-how-patterns-of-urban-growth-change-the-world
  4. https://en.wikipedia.org/wiki/City A city is a large and permanent human settlement. Although there is no agreement on how a city is distinguished from a town in general English language meanings, many cities have a particular administrative, legal, or historical status based on local law. Cities generally have complex systems for sanitation, utilities, land usage, housing, and transportation. The concentration of development greatly facilitates interaction between people and businesses, sometimes benefiting both parties in the process, but it also presents challenges to managing urban growth. A big city or metropolis usually has associated suburbs and exurbs. Such cities are usually associated with metropolitan areas and urban areas, creating numerous business commuters traveling to urban centers for employment. Once a city expands far enough to reach another city, this region can be deemed a conurbation or megalopolis. Damascus is arguably the oldest city in the world. In terms of population, the largest city proper is Shanghai, while the fastest-growing is Dubai. The following article gives some interesting reading on urban growth: https://www.theguardian.com/cities/2015/nov/23/cities-in-numbers-how-patterns-of-urban-growth-change-the-world
  5. https://en.wikipedia.org/wiki/City A city is a large and permanent human settlement. Although there is no agreement on how a city is distinguished from a town in general English language meanings, many cities have a particular administrative, legal, or historical status based on local law. Cities generally have complex systems for sanitation, utilities, land usage, housing, and transportation. The concentration of development greatly facilitates interaction between people and businesses, sometimes benefiting both parties in the process, but it also presents challenges to managing urban growth. A big city or metropolis usually has associated suburbs and exurbs. Such cities are usually associated with metropolitan areas and urban areas, creating numerous business commuters traveling to urban centers for employment. Once a city expands far enough to reach another city, this region can be deemed a conurbation or megalopolis. Damascus is arguably the oldest city in the world. In terms of population, the largest city proper is Shanghai, while the fastest-growing is Dubai. The following article gives some interesting reading on urban growth: https://www.theguardian.com/cities/2015/nov/23/cities-in-numbers-how-patterns-of-urban-growth-change-the-world