national information communication security taskforce
play

National Information & Communication Security Taskforce, - PowerPoint PPT Presentation

National Information & Communication Security Taskforce, Executive Yuan, Taiwan R.O.C. Organization Chart NICST Department of Convener: Vice Premier Information Security Cyber Security Deputy Convener: Minister Without Portfolio and one


  1. National Information & Communication Security Taskforce, Executive Yuan, Taiwan R.O.C. Organization Chart NICST Department of Convener: Vice Premier Information Security Cyber Security Deputy Convener: Minister Without Portfolio and one Specified Minister Consulting Committee (Staff Unit) Co-Deputy-Convener: Advisory Committee Member of National Security Council (Consulting Unit) Committee Members: Deputy Ministers of Ministries; Deputy Mayors of Municipalities; Deputy Minister of National Security Bureau; scholars and experts National Center for Cyber Security Technology (TWNCERT) Cybercrime Investigation Critical Infrastructure Other Cyber Security- Cyberspace Protecting System System Protection System Related Systems (Department of Cyber Security) ( MOI / MOJ ) (Office of Homeland Security) (Competent Authorities) Critical Information Personal Government Cyber Cyber Environment Industry Standard and Infrastructure Information Security Protection Awareness and Cybercrime and Internet Development Norm Group Protection Protection and Group Training Group Prevention Group Content Security Group (Department of Management Group Legislation (Department of Cyber (MOE) ( MOI / MOJ ) Group (MOEA) Cyber Security) (Department of Cyber Group Security) (NCC) Security) (MOJ) Information Service Health and Medical Telecommunication National Standard Critical Industry Competition and Financial Affairs Control System E-government Communication Transportation Cyber security Cyber Security Science Park Education Business Industry Standard 1 2016 Taiwan National Computer Emergency Response Team

  2. Critical Infrastructure Sectors Communication & Government Broadcast End Points Energy IT System/IDC Middleware Emergency Services & Public Health Care Network Database Data/Info Communication System Banking Water Resources & Finance High-Tech Transportation Industrial Park 2016 Taiwan National Computer Emergency Response Team 2

  3. Cyber Security Measures of Government Sector • NICST Committee Meeting • National Strategy for Cyber Security • NICST Working Group Meeting • Cyber Security Policy Whitepaper • Cyber Security Technology Workshop • Agency Responsibility Ranking • CIO and CISO Meeting • IT System Classification • Quarterly Workshop for IT Personnel Plan Act Do Check • Agency Business • Baseline Security Measures of Agencies Continuity Drill (ISMS/Dedicated Personnel/Defense-in- • Agency Cyber Drills (e.g. Social Engineering depth/24x7 Monitoring) Drill) • Baseline Security Measures of IT Systems • Annual Internal and 3rd Party Audit (including • Personnel Competence and Certification Cyber Health Check) • Public Private Partnership • Cyber Offensive and Defensive Exercise (G-SOC Co-defense / G-ISAC) • Cyber Governance and Defense Capability Indicator 3 3 2016 Taiwan National Computer Emergency Response Team

  4. Framework of Government ISMS 5 Perspectives / 30 Key Services Situation Awareness 3,039 Agencies Detection Rules • Honeypot R&D and Deployment Alert Intelligences Security Warning • Botnet Tracing Appliances Early • GSN Backbone Intel. Gathering • Domestic Intel Exchange G-ISAC Incident Tickets SIEM • International Intel Exchange Security Logs Platform • Threat and Alert Light Incident Response Services • 2 nd Tier G-SOC for Co-defense Respons Incident • Incident Handling Point of Contact • Alert Projects for National Celebrations CSIRT Team e • Special Projects for Critical Incidents • Digital Forensic Services Incident Report • National Software Asset Control Database • IT System Defense Baseline System Security Services Security • Government Configuration Baseline System IT Assets • Secure Software Development • Penetration Testing • Cyber Health Check System Security Status • Cyber Offensive and Defensive Exercise • Government Mobile App Security Test Customized Controls • Agency Responsibility Ranking Process • IT System Risk Classification Mgmt ISMS • Annual Government IS Audit • Security Governance Maturity and Defense Index Management and Audit Results • Training of IT/IS Officials Awareness Training and Campaigns Training • Certification of IT/IS Officials • IS Competence Training Certification/ Government Accreditation Scheme Officials • Awareness Raising Workshop Test and Accreditation • IS Legal Case Study Booklet 4 4 2016 Taiwan National Computer Emergency Response Team

  5. G-ISAC for Early Warning Gov. Agencies G-ISAC 3,039 Agencies Government Information Sharing and Analysis Center HoneyBEAR G-SOC APT CIIP Authorities Telecom (NCC) / Banking(FSC) Threat Intelligence Generation Utilities & e-Commerce (MOEA) Threat Precursor Analysis Information Sharing Indicators Internet Service Provider Botnet Tracer Of Botnet Gov.(GSN) /Academic Compromise (TANET) /All private ISPs MSSP Malware Chunghwa Telecom / Acer HoneyNET TradeVAN / ISSDU … etc 5 International Cooperation FIRST / APCERT / US-CERT SPAM CERT-EU … etc Legend HoneyBEAR: Behavior-based Email Anomaly Reconnaissance NCC : National Communication Commission FSC : Financial Supervisory Commission MOEA : Ministry of Economic Affairs GSN : Government Service Network MSSP: Managed Security Service Provider 5 2016 Taiwan National Computer Emergency Response Team FIRST: Forum for Incident Response and Security Teams

  6. G-ISAC Intelligence Sharing E-Commerce CERT (EC-CERT) Law Enforcement Gov. Intelligence CERT Agencies TWCERT Gov. Service Network TWCSIRT G-ISAC TW Network Info. Center TACERT Antivirus & Academic ISAC Related Industry (A-ISAC) Private TWAREN ISAC Sectors Intelligence Telecom ISAC MSSPs ISPs (NCC-ISAC) Financial ISAC (F- ISAC) ● G-ISAC has covered IPs of GSN, Academic Network and 34 Stocks Banks ISPs (Taiwan IP coverage > 99%) Insurance 6 2016 Taiwan National Computer Emergency Response Team

  7. Domestic Information Sharing Status 160000 2016 2011 2012 2013 2014 2015 144,079 (Q3) 140000 135,527 120000 112,516 ANA 720 1,432 1,646 756 1,222 1,410 ANA 107,405 100000 90,311 EWA 79,260 84,027 INT 84,210 17,327 6,455 3,710 3,865 4,782 2,410 EWA 80000 76,757 DEF 60,980 60000 INT 60,980 135,527 84,210 107,405 76,757 48,051 FBI 52,850 Total 48,051 40000 69 507 407 225 867 582 DEF 20000 164 158 338 265 399 397 FBI 0 Total 79,260 144,079 90,311 112,516 84,027 52,850 2011 2012 2013 2014 2015 2016(Q3) From: 2011/1/1 ~ 2016/9/30 2016 Taiwan National Computer Emergency Response Team 7

  8. Collaboration of Members - Mobile Device Malware Sample Sharing ● Criminal Investigating Bureau (CIB) established mobile device malware sample sharing channel with SOC members via G-ISAC TWNCERT 1. CIB Collect suspicious fraud messages , URL, and APK from various sources 2 3 4 2. TWNCERT receives intel, extracts malicious APKs and shares with SOC members 3. SOC members feedback APK 1 analysis results 4 4. TWNCERT integrates all results G-ISAC and share the results with all members 2 3 4 Receive Intel Source Share Intel with SOC Members SOC Members Feedback Results Integrate & Share the Final Results 8 2016 Taiwan National Computer Emergency Response Team

  9. 2nd Tier G-SOC for Co-Defense ● Build government-wide situation awareness of cyber security ● Promote Public-private-partnership for better decision making National-Level Decision Making Support 3 rd Tier NICST Government-Wide Situation Awareness Actionable Intelligence 2 nd Tier Classification Trend Statistics Data Modeling Prediction G -SOC Co-defense Monitoring Detection Rules Data 1 st Tier Incident External Existing Regulation MSSP Handling Threat Vulnerability Compliance 9 2016 Taiwan National Computer Emergency Response Team

  10. Current Situation Review ● Public-Private-Partnership now is weighted more on public sectors ● There are only three ISACs established (G-ISAC, NCC-ISAC and A-ISAC), although all operate and collaborate smoothly, but the sector coverages are limited ● Moreover, the sector level CERTs are also very few, thus the incident handlings do not performed very effectively ● There were no specific working groups for CI & CII sectors until this year in NICST organization ● There are no comprehensive regulations for cyber security, most cyber security tasks were limited within government agencies 10 2016 Taiwan National Computer Emergency Response Team

  11. The Fifth National IC Security Development Plan Cyber Security Industry National Security Technology R&D Talent Incubation Management Development 4. Complete national cyber 1. Develop national cyber 10. Combine and raise the 12. Perfect the incubation 8. Promote related policies security policies, security risk assessment values of academic and and demand of cyber and development of cyber regulation & standards security industries mechanism industrial cyber security security professionals R & D capabilities 5. Enhance cyber security 2. Establish national 13. Promote cyber security 9. Reduce cyber security defense among gov. network and 11. Develop a privacy awareness and child risks for industry supply and CI & CII sectors communication protected digital online protection chains 6. More International emergency recovery identification framework collaborations mechanism 7. Increase cyber crime 3. Build national network prevention and solve defensive and offensive effectiveness capabilities 11 2016 Taiwan National Computer Emergency Response Team

Recommend


More recommend