Vous êtes sur la page 1sur 15

Larry Clinton Operations Officer Internet Security Alliance lclinton@eia.

org 703-907-7028 202-236-0001

The Internet Security Alliance

The Internet Security Alliance is a collaborative effort between Carnegie Mellon Universitys Software Engineering Institute (SEI) and its CERT Coordination Center (CERT/CC) and the Electronic Industries Alliance (EIA), a federation of trade associations with over 2,500 members.

Sponsors

The Past

The Present

Source: http://cm.bell-labs.com/who/ches/map/gallery/index.html

Growth in Incidents Reported to the CERT/CC


120000
110,000

100000 80000
55,100

60000 40000

21,756

20000
6 132 252 406 773 1,334 2,340 2,412 2,573 2,134 3,734 9,859

0 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002

Computer Virus Costs (in billions)


$

150
billion

120 90 60 30 0

Range Dam age

'96 '97 '98 '99 '00 '01 '02 '03


(Through Oct 7)

Attacks are Inevitable


According to the US Intelligence community American networks will be increasingly targeted by malicious actors both for the data and the power they possess. National Strategy to Secure Cyberspace, 2/14/02 The significance of previous attacks is not in the amount of damage caused but it foreshadows what we could face in the future CIPB Things are getting worse not better. NYT 1/30/03

Traditional Regulation likely Ineffective


The problem is international The Internet evolves too rapidly The political consensus is deregulatory and the need is urgent

Traditional Regulation Harmful ?


Open process could provide map of vulnerabilities Private Industry has better tools---inadequate tools could lead to less security Political Process encourages compromise. Need max effectiveness so no false sense of security Tech regulation could blunt innovation leading to less choice, economy, security

ISAlliance Best Practices


Cited in US National Draft Strategy to Protect Cyber Space (September 2002) Endorsed by TechNet for CEO Security Initiative (April 2003) Endorsed National Association of Manufacturers

Common Sense Guide Top Ten Practice Topics


Practice #1: Practice #2: Practice #3: Practice #4: Practice #5: Practice #6: Practice #7: Practice #8: Practice #9: Practice #10: General Management Policy Risk Management Security Architecture & Design User Issues System & Network Management Authentication & Authorization Monitor & Audit Physical Security Continuity Planning & Disaster Recovery

ISAlliance Cyber-Insurance Program


Coverage for members Free Assessment through AIG Market incentive for increased security practices 10% discount off best prices from AIG Additional 5% discount for implementing ISAlliance Best Practices (July 2002)

ISAlliance Incentive Model


Model Programs for market Incentives ---AIG ----Nortel ---Visa ----Verizon SemaTech Program Tax Incentives Liability Carrots Procurement Model Research and Development

ISAlliance Qualification Program


No Standardized Certification Program Exists or will exist soon ISAlliance in cooperation with big 4 and insurance industry create quantitative measurement for qualification for ISA discounts as proxy for certification ISA works with CMU CyLab on Certification

Vous aimerez peut-être aussi