Technologies with the potential to enhance resilience - An overview on the activities of ENISA

Similar documents
NIS Standardisation ENISA view

Securing Europe's Information Society

Securing Europe s IoT Devices and Services

Cyber Security in Europe

ENISA EU Threat Landscape

Improving Resilience in European e-communication networks MTP 1

European Union Agency for Network and Information Security

ENISA S WORK ON ICS AND SMART GRID SECURITY

Introductory Speech to the Ramboll Event on the future of ENISA. Speech by ENISA s Executive Director, Prof. Dr. Udo Helmbrecht

ENISA activities in ICT security certification Dr. Prokopios Drogkaris NIS Expert NLO Meeting Athens

The NIS Directive and Cybersecurity in

Development, Analysis and Evaluation of Cyber Resilience Strategies

Information sharing in the EU policy on NIS & CIIP. Andrea Servida European Commission DG INFSO-A3

ENISA Cooperation in the EU / NIS Directive

Enhancing the security of CIIPs in Europe - ENISA s Approach Dimitra Liveri Network and Information Security Expert

The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

The Network and Information Security Directive - ENISA's contribution

EU policy on Network and Information Security & Critical Information Infrastructures Protection

EISAS Enhanced Roadmap 2012

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

Security Aspects of Trust Services Providers

Infrastructures and Service Dimitra Liveri Network and Information Security Expert, ENISA

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

CompTIA Security+ Study Guide (SY0-501)

Cyber Security in Europe and CEER s new PEER initiative

Supply Chain Integrity and Security Assurance for ICT. Mats Nilsson

Critical Infrastructure Protection & Resilience Europe / Asia. Conference Discussion Reviews

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

Cyber Security Beyond 2020

ENISA s Position on the NIS Directive

Valérie Andrianavaly European Commission DG INFSO-A3

Achieving Global Cyber Security Through Collaboration

ENISA And Standards Adri án Belmonte ETSI Security Week Event Sophia Antipolis (France) 22th June

Security and resilience in Information Society: the European approach

Innovation policy for Industry 4.0

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017

Network and Information Security Directive

EUROPEAN COMMISSION JOINT RESEARCH CENTRE. Information Note. JRC activities in the field of. Cybersecurity

Enhancing infrastructure cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

GDPR Update and ENISA guidelines

Critical Infrastructure Protection in the European Union

The Challenges of Risk Assessment for Smart Grid

Security and resilience in the Information Society: the role of CERTs/CSIRTs in the context of the EU CIIP policy

The role of ICT in managing the complex Smart Grid Infrastructure. Nampuraja Enose Infosys Labs

TEL2813/IS2820 Security Management

Technical guidelines implementing eidas

Security Management Models And Practices Feb 5, 2008

CHAIR S SUMMARY: G7 ENERGY MINISTERS MEETING

An Update on Security and Emergency Preparedness Standards for Utilities

Discussion on MS contribution to the WP2018

INFRASTRUCTURE. A Smart Strategy Global Water Asset Management Lead, Ove Arup NYC FORUM -

ISO/IEC JTC 1 Study Group on Smart Cities

Outreach and Partnerships for Promoting and Facilitating Private Sector Emergency Preparedness

Grid Modernization Challenges for the Integrated Grid

The NIST Cybersecurity Framework

Security for smart Electricity GRIDs

Minutes of National Laison Officer s Meeting,

H2020 Opportunities in the Area of Security and Critical Infrastructure Protection

The Role of ENISA in the Implementation of the NIS Directive Anna Sarri Officer in NIS CIP Workshop Vienna 19 th September 2017

ERCI cybersecurity seminar Guildford ERCI cybersecurity seminar Guildford

Long-Term Power Outage Response and Recovery Tabletop Exercise

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Call for Expressions of Interest

Summary of Cyber Security Issues in the Electric Power Sector

External Supplier Control Obligations. Cyber Security

United States Space Weather Strategy and Action Plan. Terry Onsager Physicist, NOAA Space Weather Prediction Center

How to ensure control and security when moving to SaaS/cloud applications

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt

The EU Cybersecurity Package: Implications for ENISA Dr. Steve Purser Head of ENISA Core Operations Athens, 30 th January 2018

DISASTER RISK MANAGEMENT (DRM/DRR) TEAM

Energy Assurance Plans

Cybersecurity Strategy of the Republic of Cyprus

Google Cloud & the General Data Protection Regulation (GDPR)

What You Should Know About Communication Systems: Business Strategies and Options

IEEE Standards Activities in the Smart Grid Space (ICT Focus)

Challenges in Maritime and Supply Chains Security

Standards for Smart Grids

IST FP6 Co-ordination Action Project: CI 2 RCO

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

Cybersecurity & Digital Privacy in the Energy sector

Legislative Framework

SECURING EUROPE S INFORMATION SOCIETY General Report 2011

ENISA & Cybersecurity. Dr. Udo Helmbrecht Executive Director, European Network & Information Security Agency (ENISA) 25 October 2010

WORK PROGRAMME 2015 INCLUDING MULTI-ANNUAL PLANNING

Integrating Distributed Resources into Distribution Planning and Operations R&D Priorities

Regulatory Impacts on Research Topics. Jennifer T. Sterling Director, Exelon NERC Compliance Program

Quality Assurance in 5G SME Engagement

Twilio cloud communications SECURITY

An Overview of Smart Sustainable Cities and the Role of Information and Communication Technologies (ICTs)

ehealth action in the EU

Table of Contents. Sample

FEMA Update. Tim Greten Technological Hazards Division Deputy Director. NREP April 2017

ENISA & Cybersecurity. Steve Purser Head of Technical Competence Department December 2012

Lecture 14. Course wrap up & Smartgrid Architectures. Professor Lars Nordström Dept of Industrial Information & Control systems, KTH

Improving recognition of ICT security standards Recommendations for the Member States for the conformance to NIS Directive

MASP Chapter on Safety and Security

Appendix 3 Disaster Recovery Plan

EU Technology Platform SmartGrids WG2 Network Operations

IoT and Smart Infrastructure efforts in ENISA

Transcription:

Technologies with the potential to enhance resilience - An overview on the activities of ENISA Demosthenes.Ikonomou@enisa.europa.eu 5 th International Conference on Critical Information Infrastructures Security

About Resilience Resilient are the networks that provide and maintain an acceptable level of service in face of faults affecting their normal operation. The main aim of the resilience is for faults to be invisible to users.

About Resilience Improving the resilience of a network is an issue of risk management which includes : risk identification; evaluation and; acceptance or mitigation. A wide accepted list of risks to the resilience of networks includes : flash crowd events cyber attacks outages of other support services natural disasters and system failings The mitigation of identified risks involves technical measures such as : resilient design resilient transmission media resilient equipment and technologies that improve resilience

Why ENISA? EC Communication on CIIP - "Protecting Europe from large scale cyber-attacks and disruptions: enhancing preparedness, security and resilience, March 2009; ENISA is addressing the following areas: Regulatory and policy aspects; Network operators practices; Technologies with a potential to improve resilience characteristics of networks; http://eur-lex.europa.eu/lexuriserv/lexuriserv.do?uri=com:2009:0149:fin:en:pdf

Video on Importance of Resilience http://www.youtube.com/user/enisasta

Simplification of ITU-T ontological model of cyber-security stressing resilience

Gap analysis in standardisation Definition of resilience ETSI TR 102 445 Emergency issues ISO/IEC 27*, BS 25999 Business Continuity Management Technical standards Some metrics ITU-T: IP service availability, IP Packet Loss Ratio, IP Packet Transfer Delay, IP Packet Delay Variation, IETF: IP Packet Delay Variation, One-Way Packet Loss,

Gap analysis in standardisation Promote work items in the SDOs to support the specification of metrics and supporting test and validation criteria to be used in the assessment of resilience; Promote work items in the SDOs to support the development of a taxonomy for resilience; Encourage telco SDOs to build links from their work to the output of bodies dealing with ancillary features (eg, power, environmental control, etc.); Add resilience as a keyword in classifying standards in the SDOs; Update SDOs procedures in approving work items to address how resilience will be achieved, e.g. in case a system fails;

Technologies with a potential to have an impact in terms of resilience cloud computing; real-time detection & diagnosis systems; future wireless networks, adhoc networks; smart grids and SCADA; sensor networks; supply chain integrity (SCI); interconnected networks;

PROCENT Priorities of research on current and emerging network trends Assessment of the impact of new technologies Identification of need for research Areas of biggest interest Cloud Computing Real-Time Detection and Diagnosis Systems Future Wireless Networks Sensor Networks Integrity of Supply Chain

End-to-end (e2e) resilience Device OS Host OS UI Ap p I O Communication I O Ap p d B Supporting services

DNSSEC activities of ENISA 2008 Survey Deployment Status; Paper on the security features and the problems it solves; Stocktaking operators on the perceived security enchantments. 2009 Study costs of deployment; Good Practice Guide on deploying DNSSEC. 2010 Pilot actions; Create end user // educational // promotional material.

ENISA Special Session 'Cyberwar ante portas! Identifying the role of the academic community in national cyber defence exercises, Prof. D. Gritzalis from AUEB, Athens; 'Quality of Resilience Metrics: State-of-the-Art and Future Trends, Dr. Chold, AGH University of Science and Technology, Kraków, Poland; Panel Discussion;

Further information European Network and Information Security Agency Science and Technology Park of Crete (ITE) P.O. Box 1309 71001 Heraklion - Crete Greece http://www.enisa.europa.eu https://www.enisa.europa.eu/act/res/technologies