CLOUD INITIATIVES FOR A SMART NATION

Size: px
Start display at page:

Download "CLOUD INITIATIVES FOR A SMART NATION"

Transcription

1 OUTLINE CLOUD INITIATIVES FOR A SMART NATION 11 April TAO YAO SING ASSIST. DIRECTOR, STANDARDS, IMDA Impediments to Cloud Adoption Cloud Security Virtualization Security for Servers Cloud Resiliency Cloud Outage Incident Response Cloud Professionals Development Body of Knowledge for Cloud Computing Cloud for Services (-as-a-service Pilot) Moving Forward 2 IMPEDIMENTS TO CLOUD ADOPTION OVERVIEW MTCS Addressing cloud adoption issues 1. Surveys have consistently confirmed that cloud security is Number 1 concern in adoption 2. Concern & tolerance of security differs from users to users 3. We need a security standard to provide visibility & clarity of security provisions of CSPs for better matching of users needs Industry Specific Standards (e.g. Govt, Finance & Healthcare industries) More Specific Controls Multi-tier Cloud Security Standards Cloud Related Controls ISO (ISMS) Base Standards 3 4

2 FRAMEWORK OF MTCS STANDARD MTCS is based on a multi-tiered framework comprising 3 levels of IS requirements SUMMARY OF STATUS (1 OF 2) MTCS SS584 was launched at CloudAsia in Nov 2013 >200 copies sold Level Overview Security Control Focus Non-business critical data & systems Most business critical data & systems Regulated organizations with specific requirements & more stringent security needs Baseline security controls for potentially low-impact information systems A set of more stringent security controls for potentially moderate-impact information systems Additional set of security controls for potentially high-impact information systems Accreditation scheme by Singapore Accreditation Council available since 29 Oct 2014 Certification services offered by 7 CBs. 6 have already been accredited Cross-certifying with other int l standards/frameworks (ISO27001 & CSA OCF/STAR) 5 6 SUMMARY OF STATUS (2 OF 2) MTCS CERTIFICATION STATUS Mapping with ISO27018 (CoP for PII Protection in Public Cloud) completed & published ServiceNow Alignment of MTCS standards with specific industry sectors Mapping of MTCS to Healthcare IT Security Policies & Standards completed Currently more than 20 IaaS & SaaS ISVs/CSPs (with >80 cloud services 66 IaaS/PaaS vs 16 SaaS) have been MTCS certified L3: AWS, ClearManage, Microsoft, Alibaba, Ribose, ServiceNow L2: SoftLayer/IBM, Tata Comms L1: Acclivis, Acscenix, ICONZ-WebVisions, IIJ, M1, Starhub, NME, ReadySpace, Telin, Auctorizium, BlazeClan, Evvo, Inspire-Tech, Reachfield, Wizlearn 7 8

3 9 VIRTUALIZATION SECURITY FOR SERVERS TR30 Servers Virtualization Security published in Joint project in 2014 with CSA to publish a whitepaper in Apr 2015 Initial NWI submission to in Apr 2015 to kick-off a 6- month study period. SP report approved and NWIP ISO meeting in Apr 2016 Ballot was called and project approved in Aug Currently in Working Draft stage. CLOUD RESILIENCY OUTAGE INCIDENT RESPONSE IN SCOP E OUT OF SCOPE 10 To develop a tiered COIR framework to ensure transparency in Cloud Service Providers (CSPs) cloud outage incident responses thus enabling cloud users to evaluate accordingly. This framework will help cloud users opt for the appropriate level of outage protection to complement their BC/DR capabilities. Cloud outages directly associated with: Operational mistakes; Infrastructure or system failure; Environment issues (like flooding/fire) Cyber-security incidents and malicious acts REGULATORS Standardise BCM requirements for CSPs Feb 2016 IDA COIR guidelines launch Feb 2016 NWI Approved by ITSC ITSC WG formed/kicked off in Jul 2016 Industry engagement briefing & FG sessions in Jan-Feb 2017 Public consultation in May-Jun 2017 CLOUD USERS Transparency of service provided by CSPs WHO BENEFITS? CSPs Aligned to market demand on the services expectation COIR OVERVIEW - MULTI-TIERED FRAMEWORK 4 tiers were defined in the COIR Framework based on impact of outage to business, sector, economy and human life COIR OVERVIEW - 17 CRITERIA DEFINITION FOR EACH TIER Minimal Operational Business Critical Life Threatening For cloud services hosting functions that are least important to an organisation s ops. Alternative means/fallback mechanisms are available. Duration of outage in days is tolerable. Low urgency to access data during outage period 11 Tier D Tier C Tier B For cloud services hosting functions that are essential to an organisation s ops. Ops restored within same day. Medium urgency to access data during outage period. Else outage will impact org s op l efficiency/ effectiveness significantly. For cloud services hosting functions that are critical to an org s ops. Any outage can impact biz severely Ops shall be restored within hours. Have a high urgency to access data during this period. Else, survival is at stake if outage prolongs Tier A For cloud services hosting functions that are mission critical to human safety or stability of economy, mkt, industry (systemic). The impact is beyond organisation s ops. Any outage will put human safety/stability of market, economy or industry at stake. 12

4 CLOUD PROFESSIONALS DEVELOPMENT Objective To establish consistent measure for assessment & recognition of cloud professionals in SG Body of knowledge (BOK) on cloud computing will form the basis for: Designing training courses to attain proficiency in cloud computing; Establishing a professional certification scheme; and Awarding continuing education credits or professional proficiency points IMDA completed initial draft and handed over to SCS Cloud Chapter for implementation considerations BoK BCM conference on 17 Mar 2017 CLOUD FOR DATA SERVICES DAAS PILOT Led by exponential growth of data & demand for data/datasets. Many business strategies & decisions are now made based on availability of timely data A DaaS pilot was piloted in Mar 2014 for 2 years exploring ways to enhance SG data ecosystem: sets discovery (Federated Namespace Registry) sets access (APIs) quality (DQM) CONCEPTUAL REPRESENTATION OF DAAS PILOT set access via developer-friendly APIs DAAS PILOT SEEKS TO ENHANCE DATA ECOSYSTEM Challenges Mash Ups Analytics Provider #1 sets Quality Tool set Registry (DSR) #1 Contains set catalogue quality dashboard Provider #2 sets DSR #2 Quality Tool Cross-Provider set Discovery Provider #N sets DSR #N Quality Tool Through providing ease in dataset discovery across industry verticals With a dataset discovery mechanism Through helping potential buyers make better-informed purchases With a data quality dashboard Through delivering datasets via developer-friendly APIs With guidelines for data access APIs 15 Federated set Registry (FDSR) 16

5 TECHNICAL REFERENCE 41 : 2015 (TR 41 : 2015) Guidelines recommending a baseline set of data quality metrics which are industry domain agnostic for structured & machine-readable datasets Relevance & completeness Punctuality & timeliness Accessibility or availability TECHNICAL REFERENCE 33 : 2013 (TR 33 : 2013) Guidelines & best practices for design & implementation of APIs & access protocols Use existing architecture & standards for web services Standardize web resource identification, design & data representation Security mechanism 17 Ease of use Reliability & trustworthiness More information can be Versioning convention 18 API documentation (documentation template) Use of metadata More information can be SOME OF THE TYPES OF DATASETS ON DAAS CLOUD FOR DATA SERVICES DAAS PILOT Business Singapore consumer classification Corporate financial data from BizInsights Singapore consumer classification Strategic corporate information data Company directory SingPost 6D Postal Code Environment Singapore weather data Sample haze data Shopping Footfall and location datasets Population in shopping malls Social media buzz of malls sample dataset 2013, 2014 Transport Traffic data Taxi queue information sample data Live parking availability Real Estate Melbourne apartments for rent/sale Singapore property caveats Real Estate listing data Real Estate agent data Scientific Singapore hydrodynamic hindcast Model - L Model Habitat fragmentation in a birdpollinated eucalypt Results Piloted 28 data providers with 81 datasets Held 2 -Driven Innovation Challenges for Institutes of Higher Learning and a Discovery Challenge to promote datasets sharing/mashup Lessons Learnt Getting datasets owners to share is not easy Motivation to share usually not monetary driven Effective mashup needs to standardize (common) data definitions & formats Next phase Explore possible means to deliver significant impact & value through sharing and mashup of datasets 19 20

6 MOVING FORWARD Driving for cloud adoption Broad-based adoption through certified SaaS for SMEs Self-assessment tool for SMEs are now available for download Sectorial adoption through identified domains (e.g. Healthcare) Singapore has improved adoption from 24.6% (2013) to 28.9% (2015) overall Enhancing cloud service resiliency & recoverability Cloud outage incident response (COIR) WIP Promote self-regulation for cloud industry Identify specialised areas of cloud computing in selected sectors E.g. Artificial Intelligence, Marketplace (explore data use cases) LIST OF USEFUL LINKS MTCS Standard SS584: dza==&keyword=ss%20584 MTCS Certification Scheme & Self-Assessment Tool List of MTCS Certified Cloud Services List of Accredited Certification Bodies MTCS Certification Grant Support IMDA COIR Guidelines Virtualization Security for Servers TR30: dza==&keyword=tr% THE END 23

STANDARDS TO HELP COMPLY WITH EU LEGISLATION. EUROPE HAS WHAT IT TAKES INCLUDING THE WILL?

STANDARDS TO HELP COMPLY WITH EU LEGISLATION. EUROPE HAS WHAT IT TAKES INCLUDING THE WILL? ETSI SUMMIT Releasing the Flow Data Protection and Privacy in a Data-Driven Economy 19 April 2018 STANDARDS TO HELP COMPLY WITH EU LEGISLATION. EUROPE HAS WHAT IT TAKES INCLUDING THE WILL? Presented by

More information

Copyright 2011 EMC Corporation. All rights reserved.

Copyright 2011 EMC Corporation. All rights reserved. 1 2 How risky is the Cloud? 3 Is Cloud worth it? YES! 4 Cloud adds the concept of Supply Chain 5 Cloud Computing Definition National Institute of Standards and Technology (NIST Special Publication 800-145

More information

Introduction to AWS GoldBase

Introduction to AWS GoldBase Introduction to AWS GoldBase A Solution to Automate Security, Compliance, and Governance in AWS October 2015 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved. Notices This document

More information

8 July 2010 Certification in IT Business Continuity Management (CITBCM) 1

8 July 2010 Certification in IT Business Continuity Management (CITBCM) 1 Wong Tew Kiat, CBCP, MBCI, SMSCS, COMIT Senior Chairman, CITBCM Resource Panel & Board of Assessors President, SCS - Business Continuity Group Service Delivery Director, NCS Pte Ltd 8 July 2010 Certification

More information

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services Enhancing infrastructure cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services European Union Agency for Network and Information Security Securing Europe s Information society 2

More information

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services Enhancing infrastructure cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services European Union Agency for Network and Information Security Securing Europe s Information society 2

More information

Washington State Emergency Management Association (WSEMA) Olympia, WA

Washington State Emergency Management Association (WSEMA) Olympia, WA Washington State Emergency Management Association (WSEMA) Olympia, WA Request for Proposals Website Redesign and Content Management and Maintenance System Proposal Submittal Deadline: I. Introduction and

More information

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION Cathy Bates Senior Consultant, Vantage Technology Consulting Group January 30, 2018 Campus Orientation Initiative and Project Orientation Project

More information

Identity Assurance Framework: Realizing The Identity Opportunity With Consistency And Definition

Identity Assurance Framework: Realizing The Identity Opportunity With Consistency And Definition Identity Assurance Framework: Realizing The Identity Opportunity With Consistency And Definition Sept. 8, 2008 Liberty Alliance 1 Welcome! Introduction of speakers Introduction of attendees Your organization

More information

United States Government Cloud Standards Perspectives

United States Government Cloud Standards Perspectives United States Government Cloud Standards Perspectives in the context of the NIST initiative to collaboratively build a USG Cloud Computing Technology Roadmap NIST Mission: To promote U.S. innovation and

More information

Managing SaaS risks for cloud customers

Managing SaaS risks for cloud customers Managing SaaS risks for cloud customers Information Security Summit 2016 September 13, 2016 Ronald Tse Founder & CEO, Ribose For every IaaS/PaaS, there are 100s of SaaS PROBLEM SaaS spending is almost

More information

Infocomm Professional Development Forum 2011

Infocomm Professional Development Forum 2011 Infocomm Professional Development Forum 2011 1 Agenda Brief Introduction to CITBCM Certification Business & Technology Impact Analysis (BTIA) Workshop 2 Integrated end-to-end approach in increasing resilience

More information

State Planning Organization Information Society Department

State Planning Organization Information Society Department Information Society Department - October TR. Information Society Department Information Society Strategy Duration / Pro- Post- 1 Formulating the Information Society Strategy All Public Institutions Universities

More information

The HPE Living Progress Challenge

The HPE Living Progress Challenge December 15, 2015 The HPE Living Progress Challenge Overview Chris Wellise Director, Strategic Initiatives The power of digital inclusion The potential for technology to break down barriers is limitless,

More information

In Accountable IoT We Trust

In Accountable IoT We Trust In Accountable IoT We Trust AIOTI WG3 Security & Privacy-in-IoT Taskforces, and H2020 CSA CREATE-IoT & LSPs AG Trust in IoT Arthur van der Wees Managing Director Arthur s Legal, the global tech-by-design

More information

INFORMATION TECHNOLOGY ONE-YEAR PLAN

INFORMATION TECHNOLOGY ONE-YEAR PLAN INFORMATION TECHNOLOGY ONE-YEAR PLAN 2016-2017 Information and Communications Technology One-year Plan 2016-2017 The purpose of this document is to identify the activities being undertaken this year by

More information

CLOUD GOVERNANCE SPECIALIST Certification

CLOUD GOVERNANCE SPECIALIST Certification CLOUD GOVERNANCE SPECIALIST Certification The Cloud Professional (CCP) program from Arcitura is dedicated to excellence in the fields of cloud computing technology, mechanisms, platforms, architecture,

More information

NIS Directive : Call for Proposals

NIS Directive : Call for Proposals National Cyber Security Centre, in Collaboration with the Research Institute in Trustworthy Inter-connected Cyber-physical Systems (RITICS) Summary NIS Directive : Call for Proposals Closing date: Friday

More information

SME License Order Working Group Update - Webinar #3 Call in number:

SME License Order Working Group Update - Webinar #3 Call in number: SME License Order Working Group Update - Webinar #3 Call in number: Canada Local: +1-416-915-8942 Canada Toll Free: +1-855-244-8680 Event Number: 662 298 966 Attendee ID: check your WebEx session under

More information

Council, 26 March Information Technology Report. Executive summary and recommendations. Introduction

Council, 26 March Information Technology Report. Executive summary and recommendations. Introduction Council, 26 March 2014 Information Technology Report Executive summary and recommendations Introduction This report sets out the main activities of the Information Technology Department since the last

More information

SWIFT Customer Security Controls Framework and self-attestation via The KYC Registry Security Attestation Application FAQ

SWIFT Customer Security Controls Framework and self-attestation via The KYC Registry Security Attestation Application FAQ SWIFT Customer Security Controls Framework and self-attestation via The KYC Registry Security Attestation Application FAQ 1 SWIFT Customer Security Controls Framework Why has SWIFT launched new security

More information

TEL2813/IS2820 Security Management

TEL2813/IS2820 Security Management TEL2813/IS2820 Security Management Security Management Models And Practices Lecture 6 Jan 27, 2005 Introduction To create or maintain a secure environment 1. Design working security plan 2. Implement management

More information

DIGITIZING INDUSTRY, ICT STANDARDS TO

DIGITIZING INDUSTRY, ICT STANDARDS TO DIGITIZING INDUSTRY, ICT STANDARDS TO DELIVER ON DIGITAL SINGLE MARKET OBJECTIVES ETSI When Standards Support Policy 14 November 2016 Emilio Davila Gonzalez Unit Start ups & Innovation, EC DG Connect 72%

More information

EUROCONTROL SWIM Standards Evolution Workshop

EUROCONTROL SWIM Standards Evolution Workshop EUROCONTROL SWIM Standards Evolution Workshop Introduction & SWIM Context Dennis Hart dennis.hart@eurocontrol.int Head of System Wide Information Management Unit 2 3 4 National Regulatory Authorities ISO

More information

Security Management Models And Practices Feb 5, 2008

Security Management Models And Practices Feb 5, 2008 TEL2813/IS2820 Security Management Security Management Models And Practices Feb 5, 2008 Objectives Overview basic standards and best practices Overview of ISO 17799 Overview of NIST SP documents related

More information

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure Executive Order 13800 Update July 2017 In Brief On May 11, 2017, President Trump issued Executive Order 13800, Strengthening

More information

Stakeholder consultation process and online consultation platform

Stakeholder consultation process and online consultation platform Stakeholder consultation process and online consultation platform Grant agreement no.: 633107 Deliverable No. D6.2 Stakeholder consultation process and online consultation platform Status: Final Dissemination

More information

IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION

IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION Briefing for OFPP Working Group 19 Feb 2015 Emile Monette GSA Office of Governmentwide Policy emile.monette@gsa.gov Cybersecurity Threats are

More information

EU Code of Conduct on Data Centre Energy Efficiency

EU Code of Conduct on Data Centre Energy Efficiency EUROPEAN COMMISSION DIRECTORATE-GENERAL JRC JOINT RESEARCH CENTRE Institute for Energy Renew able and Energy Efficiency Unit EU Code of Conduct on Data Centre Energy Efficiency Introductory guide for all

More information

NCSF Foundation Certification

NCSF Foundation Certification NCSF Foundation Certification Overview This ACQUIROS accredited training program is targeted at IT and Cybersecurity professionals looking to become certified on how to operationalize the NIST Cybersecurity

More information

Accelerate Your Cloud Journey

Accelerate Your Cloud Journey Dubai, UAE 20th March 2013 Accelerate Your Cloud Journey James Spearman Dimension Data - Solutions Architect Cloud 2012 2011 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Dimension

More information

UAE National Space Policy Agenda Item 11; LSC April By: Space Policy and Regulations Directory

UAE National Space Policy Agenda Item 11; LSC April By: Space Policy and Regulations Directory UAE National Space Policy Agenda Item 11; LSC 2017 06 April 2017 By: Space Policy and Regulations Directory 1 Federal Decree Law No.1 of 2014 establishes the UAE Space Agency UAE Space Agency Objectives

More information

13.f Toronto Catholic District School Board's IT Strategic Review - Draft Executive Summary (Refer 8b)

13.f Toronto Catholic District School Board's IT Strategic Review - Draft Executive Summary (Refer 8b) AGENDA ADDENDU TE REGULAR EETING OF TE AUDIT COITTEE COITTEE PUBLIC SESSION Tuesday, June 6, 2017 6:30 P.. Pages 13. Staff Reports 13.f Toronto Catholic District School Board's IT Strategic Review - Draft

More information

AWS Webinar. Navigating GDPR Compliance on AWS. Christian Hesse Amazon Web Services

AWS Webinar. Navigating GDPR Compliance on AWS. Christian Hesse Amazon Web Services AWS Webinar Navigating GDPR Compliance on AWS Christian Hesse Amazon Web Services What is the GDPR? What is the GDPR? The "GDPR" is the General Data Protection Regulation, a significant new EU Data Protection

More information

ICT PROFESSIONAL MICROSOFT OFFICE SCHEDULE MIDRAND

ICT PROFESSIONAL MICROSOFT OFFICE SCHEDULE MIDRAND ICT PROFESSIONAL MICROSOFT OFFICE SCHEDULE MIDRAND BYTES PEOPLE SOLUTIONS Bytes Business Park 241 3rd Road Halfway Gardens Midrand Tel: +27 (11) 205-7000 Fax: +27 (11) 205-7110 Email: gauteng.sales@bytes.co.za

More information

COMPLIANCE IN THE CLOUD

COMPLIANCE IN THE CLOUD COMPLIANCE IN THE CLOUD 3:45-4:30PM Scott Edwards, President, Summit 7 Dave Harris Society for International Affairs COMPLIANCE IN THE CLOUD Scott Edwards scott.edwards@summit7systems.com 256-541-9638

More information

APNIC History and Overview

APNIC History and Overview APNIC History and Overview AfriNIC Meeting Cape Town, May 2000 APNIC History and Overview Formation and development Current status Resource status Meetings and coordination Questions APNIC History 1992

More information

Directive on security of network and information systems (NIS): State of Play

Directive on security of network and information systems (NIS): State of Play Directive on security of network and information systems (NIS): State of Play Svetlana Schuster Unit H1 Cybersecurity and Digital Privacy DG Communications Networks, Content and Technology, European Commission

More information

DoD Environmental Security Technology Certification Program (ESTCP) Tim Tetreault DoD August 15, 2017

DoD Environmental Security Technology Certification Program (ESTCP) Tim Tetreault DoD August 15, 2017 DoD Energy Testbed DoD Environmental Security Technology Certification Program (ESTCP) Tim Tetreault DoD August 15, 2017 Tampa Convention Center Tampa, Florida About ESTCP Established in 1995 to: Improve

More information

NZ Certificate in Credit Management (Level 4)

NZ Certificate in Credit Management (Level 4) NZ Certificate in Credit Management (Level 4) The current certificate is designed for people working in, or intending to work in, a credit management role. It is designed to help develop and enhance the

More information

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 ISO / IEC 27001:2005 A brief introduction Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 Information Information is an asset which, like other important business assets, has value

More information

EU Cloud Computing Policy. Luis C. Busquets Pérez 26 September 2017

EU Cloud Computing Policy. Luis C. Busquets Pérez 26 September 2017 EU Cloud Computing Policy Luis C. Busquets Pérez 26 September 2017 The digital revolution is built on data Most economic activity will depend on data within a decade Potential of the data-driven economy

More information

Programs that Work. March 7,

Programs that Work. March 7, Programs that Work March 7, 2017 www.workforcedqc.org @workforcedqc Panelists Jenna Leventoff, Workforce Data Quality Campaign Kermit Kaleba, National Skills Coalition David W. Ramsay, Office of Research

More information

Solutions Technology, Inc. (STI) Corporate Capability Brief

Solutions Technology, Inc. (STI) Corporate Capability Brief Solutions Technology, Inc. (STI) Corporate Capability Brief STI CORPORATE OVERVIEW Located in the metropolitan area of Washington, District of Columbia (D.C.), Solutions Technology Inc. (STI), women owned

More information

IoT & SCADA Cyber Security Services

IoT & SCADA Cyber Security Services RIOT SOLUTIONS PTY LTD P.O. Box 10087 Adelaide St Brisbane QLD 4000 BRISBANE HEAD OFFICE Level 22, 144 Edward St Brisbane, QLD 4000 T: 1300 744 028 Email: sales@riotsolutions.com.au www.riotsolutions.com.au

More information

Why you should adopt the NIST Cybersecurity Framework

Why you should adopt the NIST Cybersecurity Framework Why you should adopt the NIST Cybersecurity Framework It s important to note that the Framework casts the discussion of cybersecurity in the vocabulary of risk management Stating it in terms Executive

More information

Information Technology (CCHIT): Report on Activities and Progress

Information Technology (CCHIT): Report on Activities and Progress Certification Commission for Healthcare Information Technology Certification Commission for Healthcare Information Technology (CCHIT): Report on Activities and Progress Mark Leavitt, MD, PhD Chair, CCHIT

More information

Big Data Value cppp Big Data Value Association Big Data Value ecosystem

Big Data Value cppp Big Data Value Association Big Data Value ecosystem Big Data Value cppp Big Data Value Association Big Data Value ecosystem Laure Le Bars, SAP, BDVA President and BDVe lead Nuria de Lama, ATOS, BDVA Deputy Secretary General, BDVe co-lead Ana García Robles,

More information

Framework for Improving Critical Infrastructure Cybersecurity

Framework for Improving Critical Infrastructure Cybersecurity Framework for Improving Critical Infrastructure Cybersecurity May 2017 cyberframework@nist.gov Why Cybersecurity Framework? Cybersecurity Framework Uses Identify mission or business cybersecurity dependencies

More information

Cloud First Policy General Directorate of Governance and Operations Version April 2017

Cloud First Policy General Directorate of Governance and Operations Version April 2017 General Directorate of Governance and Operations Version 1.0 24 April 2017 Table of Contents Definitions/Glossary... 2 Policy statement... 3 Entities Affected by this Policy... 3 Who Should Read this Policy...

More information

Organizational Privacy Transformation: A case study from Critical Issues to Award Winning Success

Organizational Privacy Transformation: A case study from Critical Issues to Award Winning Success Organizational Privacy Transformation: A case study from Critical Issues to Award Winning Success Norine Primeau-Menzies VP Customer Services, Chief Privacy Officer May 2012 Agenda Overview of OTN Setting

More information

Cybersecurity Risk Management:

Cybersecurity Risk Management: Cybersecurity Risk Management: Building a Culture of Responsibility G7 ICT and Industry Multistakeholder Conference September 25 2017 Adam Sedgewick asedgewick@doc.gov Cybersecurity in the Department of

More information

C106: DEMO OF THE INFORMATION SECURITY MANAGEMENT SYSTEM - ISO: 27001:2005 AWARENESS TRAINING PRESENTATION KIT

C106: DEMO OF THE INFORMATION SECURITY MANAGEMENT SYSTEM - ISO: 27001:2005 AWARENESS TRAINING PRESENTATION KIT C106: DEMO OF THE INFORMATION SECURITY MANAGEMENT SYSTEM - ISO: 27001:2005 AWARENESS TRAINING PRESENTATION KIT Buy: http://www.globalmanagergroup.com/iso27001training.htm Chapter-1.0 CONTENTS OF ISO 27001-2005

More information

The NIS Directive and Cybersecurity in

The NIS Directive and Cybersecurity in The NIS Directive and Cybersecurity in ehealth Dr. Athanasios Drougkas Officer in NIS Belgian Hospitals Meeting on Security Brussels 13 th October European Union Agency For Network And Information Security

More information

An Overview of ISO/IEC family of Information Security Management System Standards

An Overview of ISO/IEC family of Information Security Management System Standards What is ISO/IEC 27001? The ISO/IEC 27001 standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), is known as Information

More information

DMR Interoperability Process DMR Association

DMR Interoperability Process DMR Association DMR Interoperability Process DMR Association Introduction This white paper gives the background to the development of the DMR Interoperability Process by the DMR Association, explains the value of the

More information

Service Description: CNS Federal High Touch Technical Support

Service Description: CNS Federal High Touch Technical Support Page 1 of 1 Service Description: CNS Federal High Touch Technical Support This service description ( Service Description ) describes Cisco s Federal High Touch Technical support (CNS-HTTS), a tier 2 in

More information

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 I. Vision A highly reliable and secure bulk power system in the Electric Reliability Council of Texas

More information

Striving for efficiency

Striving for efficiency Ron Dekker Director CESSDA Striving for efficiency Realise the social data part of EOSC How to Get the Maximum from Research Data Prerequisites and Outcomes University of Tartu, 29 May 2018 Trends 1.Growing

More information

Data Quality Assessment Tool for health and social care. October 2018

Data Quality Assessment Tool for health and social care. October 2018 Data Quality Assessment Tool for health and social care October 2018 Introduction This interactive data quality assessment tool has been developed to meet the needs of a broad range of health and social

More information

Increasing use of standards for products, services, processes and systems either by regulation or voluntary regimes Regulation on grounds of health,

Increasing use of standards for products, services, processes and systems either by regulation or voluntary regimes Regulation on grounds of health, y y y y y Increasing use of standards for products, services, processes and systems either by regulation or voluntary regimes Regulation on grounds of health, safety, environment mandated under WTO Agreements

More information

Directive on Security of Network and Information Systems

Directive on Security of Network and Information Systems European Commission - Fact Sheet Directive on Security of Network and Information Systems Brussels, 6 July 2016 Questions and Answers The European Parliament's plenary adopted today the Directive on Security

More information

[NEC Group Internal Use Only] IoT Security. - Challenges & Standardization status. Sivabalan Arumugam.

[NEC Group Internal Use Only] IoT Security. - Challenges & Standardization status. Sivabalan Arumugam. [NEC Group Internal Use Only] IoT Security - Challenges & Standardization status Sivabalan Arumugam Outline IoT Security Overview IoT Security Challenges IoT related Threats

More information

Policy. Business Resilience MB2010.P.119

Policy. Business Resilience MB2010.P.119 MB.P.119 Business Resilience Policy This policy been prepared by the Bi-Cameral Business Risk and Resilience Group and endorsed by the Management Boards of both Houses. It is effective from December to

More information

Compliance and Security in a Cloud-First Era

Compliance and Security in a Cloud-First Era Compliance and Security in a Cloud-First Era Regions: Dublin (EU-West) 3 x Availability Zones Launched in 2007 Frankfurt (EU-Central) 2 x Availability Zones Launched 2014 Edge Locations: Amsterdam,

More information

UKAS Guidance for Bodies Offering Certification of Anti-Bribery Management Systems

UKAS Guidance for Bodies Offering Certification of Anti-Bribery Management Systems CIS 14 Edition 1 September 2018 UKAS Guidance for Bodies Offering Certification of Anti-Bribery Management Systems CIS 14 Edition 1 Page 1 of 10 Contents 1. Introduction 3 2. UKAS Assessment Approach 3

More information

How UAE is Driving Smart Sustainable Cities: key Achievements and Future Considerations

How UAE is Driving Smart Sustainable Cities: key Achievements and Future Considerations How UAE is Driving Smart Sustainable Cities: key Achievements and Future Considerations By Dr. Saeed Al Dhaheri @DDSaeed Chairman, We are the leading Smart Solutions Integrator. With our far sight and

More information

EuroCloud Europe. Key success factors for trustworthy Cloud Adoption in the EU. 16-JUNE-2015 Riga Andreas Weiss. Trust in Cloud

EuroCloud Europe. Key success factors for trustworthy Cloud Adoption in the EU. 16-JUNE-2015 Riga Andreas Weiss. Trust in Cloud EuroCloud Europe a.s.b.l EuroCloud Deutschland_eco e.v. EuroCloud Europe Key success factors for trustworthy Cloud Adoption in the EU 16-JUNE-2015 Riga Andreas Weiss European Activities Expert Groups in

More information

Information Security Management Systems Standards ISO/IEC Global Opportunity for the Business Community

Information Security Management Systems Standards ISO/IEC Global Opportunity for the Business Community Information Security Management Systems Standards ISO/IEC 27001 Global Opportunity for the Business Community Prof. Edward (Ted) Humphreys IPA Global Symposium 2013 23 rd May 2013, Tokyo, Japan CyberSecurity

More information

UAE Space Policy Efforts Towards Long Term Sustainability of Space Activities Agenda Item 4; COPUOS June 2017 By: Space Policy and

UAE Space Policy Efforts Towards Long Term Sustainability of Space Activities Agenda Item 4; COPUOS June 2017 By: Space Policy and UAE Space Policy Efforts Towards Long Term Sustainability of Space Activities Agenda Item 4; COPUOS 2017 07-16 June 2017 By: Space Policy and Regulations Directory 1 The UAE will build the first city on

More information

Federal Data Center Consolidation Initiative (FDCCI) Workshop I: Initial Data Center Consolidation Plan

Federal Data Center Consolidation Initiative (FDCCI) Workshop I: Initial Data Center Consolidation Plan Federal Data Center Consolidation Initiative (FDCCI) Workshop I: Initial Data Center Consolidation Plan June 04, 2010 FDCCI Workshop I Agenda for June 4, 2010 1. Welcome Katie Lewin GSA Director Cloud

More information

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com Cybersecurity Presidential Policy Directive Frequently Asked Questions kpmg.com Introduction On February 12, 2013, the White House released the official version of the Presidential Policy Directive regarding

More information

ISO/ IEC (ITSM) Certification Roadmap

ISO/ IEC (ITSM) Certification Roadmap ISO/ IEC 20000 (ITSM) Certification Roadmap Rasheed Adegoke June 2013 Outline About First Bank Motivations Definitions ITIL, ISO/IEC 20000 & DIFFERENCES ISO/ IEC 20000 Certification Roadmap First Bank

More information

Work to establish standard ENTSOE STAKEHOLDER COMMITTEE 1

Work to establish standard ENTSOE STAKEHOLDER COMMITTEE 1 Work to establish standard EN50549-1 EN50549-2 EN50549-10 2017-03-14 ENTSOE STAKEHOLDER COMMITTEE 1 SOMMAIRE Summary Key points TC8X / WG31 01 Schedule1 TC8X / approach1 02 03 Next steps 04 Others considerations1

More information

Section One of the Order: The Cybersecurity of Federal Networks.

Section One of the Order: The Cybersecurity of Federal Networks. Summary and Analysis of the May 11, 2017 Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure. Introduction On May 11, 2017, President Donald

More information

PRIOR LEARNING ASSESSMENT AND RECOGNITION (PLAR)

PRIOR LEARNING ASSESSMENT AND RECOGNITION (PLAR) PRIOR LEARNING ASSESSMENT AND RECOGNITION (PLAR) 1. INTRODUCTION 1.1 Purpose of the Guidelines These guidelines have been developed by TVETA to guide TVET Providers on how to: (i) Prepare, plan, and implement

More information

SERVICE DEFINITION G-CLOUD 7 THALES PSN REMOTE ACCESS. Classification: Open

SERVICE DEFINITION G-CLOUD 7 THALES PSN REMOTE ACCESS. Classification: Open SERVICE DEFINITION G-CLOUD 7 THALES PSN REMOTE ACCESS Classification: Open Classification: Open ii MDS Technologies Ltd 2015. Other than for the sole purpose of evaluating this Response, no part of this

More information

INNOVATIONS CENTER. Fariz T. JAFAROV Director. e-gov Development Center of Azerbaijan

INNOVATIONS CENTER. Fariz T. JAFAROV Director. e-gov Development Center of Azerbaijan INNOVATIONS CENTER Fariz T. JAFAROV Director e-gov Development Center of Azerbaijan 1 Contextual environment 2 Billions GDP Growth in Azerbaijan four periods of development 100 80 60 40 20 0 Survival Explosive

More information

Project Refresh. Bureau of Primary Health Care Reformatted Survey Report January 18, Copyright, The Joint Commission

Project Refresh. Bureau of Primary Health Care Reformatted Survey Report January 18, Copyright, The Joint Commission Project Refresh Bureau of Primary Health Care Reformatted Survey Report January 18, 2018 1 What is Project Refresh? A series of inter-related and/or interdependent process improvement initiatives underway

More information

Ofqual. Ofqual Supporting a Cloud-First Programme. Client Testimonial

Ofqual. Ofqual Supporting a Cloud-First Programme. Client Testimonial Ofqual Ofqual Supporting a Cloud-First Programme Client Testimonial 2017 CoreAzure Limited. All rights reserved. This document is provided "as-is". Information and views expressed in this document, including

More information

Green Squared Certification Manual

Green Squared Certification Manual SCS Global Services Manual Green Squared Certification Manual Environmental Certification Services Division 2000 Powell Street, Ste. 600, Emeryville, CA 94608 USA +1.510.452.8000 main +1.510.452.8001 fax

More information

Data Security Standards

Data Security Standards Data Security Standards Overall guide The bigger picture of where the standards fit in 2018 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information Centre is a

More information

Interoperability and transparency The European context

Interoperability and transparency The European context JOINING UP GOVERNMENTS EUROPEAN COMMISSION Interoperability and transparency The European context ITAPA 2011, Bratislava Francisco García Morán Director General for Informatics Background 2 3 Every European

More information

How ISO helps organisation to achieve operational readiness Ong Liong Chuan 26 Apr 2016

How ISO helps organisation to achieve operational readiness Ong Liong Chuan 26 Apr 2016 How ISO 22301 helps organisation to achieve operational readiness Ong Liong Chuan 26 Apr 2016 Copyright SP PowerGrid Ltd Threat Threat 1 Threat 2 Organisation Threat 3 2 Threat - Terrorist actions ST 19Mar16

More information

San Francisco Department of Public Health. IT and Epic Project Update

San Francisco Department of Public Health. IT and Epic Project Update San Francisco Department of Public Health IT and Epic Project Update Health Commission, April 16, 2019 IT: Infrastructure Accomplishments Sweeping Improvements Across DPH Thousands of devices are Epic

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 27006 Second edition 2011-12-01 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems

More information

Pre-Commercial Procurement project - HNSciCloud. 20 January 2015 Bob Jones, CERN

Pre-Commercial Procurement project - HNSciCloud. 20 January 2015 Bob Jones, CERN Pre-Commercial Procurement project - HNSciCloud 20 January 2015 Bob Jones, CERN PCP PPI Why PCP? Commercial IaaS exists but not certified, integrated with public e-infrastructures, offering std interfaces

More information

Asks for clarification of whether a GOP must communicate to a TOP that a generator is in manual mode (no AVR) during start up or shut down.

Asks for clarification of whether a GOP must communicate to a TOP that a generator is in manual mode (no AVR) during start up or shut down. # Name Duration 1 Project 2011-INT-02 Interpretation of VAR-002 for Constellation Power Gen 185 days Jan Feb Mar Apr May Jun Jul Aug Sep O 2012 2 Start Date for this Plan 0 days 3 A - ASSEMBLE SDT 6 days

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 1: Processes and tiered assessment of conformance

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 1: Processes and tiered assessment of conformance INTERNATIONAL STANDARD This is a preview - click here to buy the full publication ISO/IEC 19770-1 Second edition 2012-06-15 Information technology Software asset management Part 1: Processes and tiered

More information

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017 in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017 European Union Agency for Network and Information Security Positioning ENISA activities CAPACITY Hands on activities POLICY Support MS & COM

More information

EA-01/01 List of EA Publications

EA-01/01 List of EA Publications Publication Reference EA-01/01 List of EA Publications 21 September 2006 1 of 9 Authorship This document has been prepared by the EA Secretariat. Official language The text may be translated into other

More information

CERTIFICATE SCHEME THE MATERIAL HEALTH CERTIFICATE PROGRAM. Version 1.1. April 2015

CERTIFICATE SCHEME THE MATERIAL HEALTH CERTIFICATE PROGRAM. Version 1.1. April 2015 CERTIFICATE SCHEME For THE MATERIAL HEALTH CERTIFICATE PROGRAM Version 1.1 April 2015 Copyright Cradle to Cradle Products Innovation Institute, 2015 1 Purpose The intention of the Certificate Scheme is

More information

Cloud Services. Infrastructure-as-a-Service

Cloud Services. Infrastructure-as-a-Service Cloud Services Infrastructure-as-a-Service Accelerate your IT and business transformation with our networkcentric, highly secure private and public cloud services - all backed-up by a 99.999% availability

More information

INAB Mandatory and Guidance Documents Policy and Index

INAB Mandatory and Guidance Documents Policy and Index INAB Mandatory and Guidance s Policy and Index This publication is aimed at assisting in determining what documents are relevant to various organisations and at providing contact points for accessing such

More information

Toward Horizon 2020: INSPIRE, PSI and other EU policies on data sharing and standardization

Toward Horizon 2020: INSPIRE, PSI and other EU policies on data sharing and standardization Toward Horizon 2020: INSPIRE, PSI and other EU policies on data sharing and standardization www.jrc.ec.europa.eu Serving society Stimulating innovation Supporting legislation The Mission of the Joint Research

More information

Cloud Essentials for Architects using OpenStack

Cloud Essentials for Architects using OpenStack Cloud Essentials for Architects using OpenStack Course Overview Start Date 5th March 2015 Duration 2 Days Location Dublin Course Code SS15-13 Programme Overview Cloud Computing is gaining increasing attention

More information

SOC 3 for Security and Availability

SOC 3 for Security and Availability SOC 3 for Security and Availability Independent Practioner s Trust Services Report For the Period October 1, 2015 through September 30, 2016 Independent SOC 3 Report for the Security and Availability Trust

More information

CORPORATE PRESENTATION

CORPORATE PRESENTATION CORPORATE PRESENTATION SUMMARY Our mission and vision 4 Our values Our figures 4 5 Organisation chart Areas of Activity Defence and Security Space Transport Public Administration ICT Energy 6 8 Ingeniería

More information

ARKANSAS TECH UNIVERSITY DEPARTMENT OF PARKS, RECREATION & HOSPITALITY ADMINISTRATION

ARKANSAS TECH UNIVERSITY DEPARTMENT OF PARKS, RECREATION & HOSPITALITY ADMINISTRATION ARKANSAS TECH UNIVERSITY DEPARTMENT OF PARKS, RECREATION & HOSPITALITY ADMINISTRATION Recreation & Park Administration Assessment Plan -11 Arkansas Tech University is accredited by the Higher Learning

More information

DG CONNECT (Unit H5) Update on Data Centre Activities

DG CONNECT (Unit H5) Update on Data Centre Activities DG CONNECT (Unit H5) Update on Data Centre Activities Svetoslav Mihaylov Scientific/Technical Project Officer Smart Cities and Sustainability Directorate-General Communications Networks, Content and Technology

More information