CYBER SECURITY in UKRAINE NATO LIAISON OFFICE, KYIV

Post on 08-Jan-2018

245 views 3 download

description

AGENDA What to protect? Cybersecurity governance/framework Standards Public-private sector cooperation Risk based management Cybersecurity dictionary InfoSec problems Awareness rising Trust Fund How NATO can support?

transcript

WELCOME

CYBER SECURITY IN UKRAINE

MUSTAFA AYDINLINATO LIAISON OFFICE, KYIV

AGENDA• What to protect?• Cybersecurity governance/framework• Standards• Public-private sector cooperation• Risk based management• Cybersecurity dictionary• InfoSec problems• Awareness rising• Trust Fund• How NATO can support?

What to protect

State assets orIndividual’s Rights

Cyber Security Governance/Framework

• Governance– Central authority to overarch– Strategy, policy and action plans

• Framework– Cybersecurity strategy– Legislative regulations– Well defined roles and responsiblities

5

Standards• Effective cooperation in cross-border and cross-community.• Different standards are being used– Competing – Contradictory– Excessively restrictive – Not interoperable

• Who will decide on the standards?• NATO standards for security and defence sector

Public-Private Sector Cooperation

• Critical infrastructures operated by private sector• Private sector has huge technical and personel

capacity• Lack of cooperation and collaboration • Requires legislative regulations

• Estonia

Risk Based Management• Risk assessment is curicial• Define risk management procedures• Evaluate risks• Report risks and possible solutions• Prioritize risks and evaluate acceptance• Risk should be shared between public and private

sector• Accurate and timely information sharing

Cybersecurity Dictionary

• Wide range of interest• IT system administrators,• Forensic experts,• Prosecuters,• Judges,• Law enforcment bodies• .......

• Need for a common understanding of cybersecurity • Easily updatable

InfoSec Problems

• Usage of old Soviet GOST standards• Some standards 40 years old• Very strict rules prevents develeopment of new

systems over Internet• Usage of foreign crypto systems is forbiden• Imlementing NATO compatible projects requires

exceptions

Awareness Rising

Cyber Defence Trust Fund• Established and Romania is entrusted as Lead

Nation.• Aim– Develop defensive CERT type capabilities– Provide training and advisory support

• Projects derived from the requirements of Ukrainian institutions.

• SBU is the executive agent for Ukrainian side.

How NATO can Support?

• Help legislation process.• Provide unclassified standards.• Classified standards.• Workshops/conferences under the SPS programs.• Trust Funds.• Assessing as a policy goal in ANP.

National Museum of the History of the Great Patriotic Warİstanbul Bosphorus

Any question?

THANK YOU