180 likes | 388 Views
Janet, Security & ESISS. September 2013. Janet, Security & ESISS. Janet and Security An introduction to ESISS New services What won ’ t be changing Q&A. Janet and Security. Operates CSIRT
E N D
Janet, Security & ESISS • September 2013
Janet, Security & ESISS • Janet and Security • An introduction to ESISS • New services • What won’t be changing • Q&A
Janet and Security • Operates CSIRT • Works with UK Gov’t Cabinet Office and Cyber security Information Sharing Partnership (CISP), collaborating as required. • Presence on UK e-Infrastructure Leadership Council and Security stream • Range of products including server certificates • Increasingly investing in security projects (recent funding on threat information service) • Reviewing ISO27001 • And… Janet ESISS
Janet ESISS • From August 1st, Janet will be taking on the operations of ESISS.. • Now some history...
A Shared Issue • The same challenges • Different resources • Desire to collaborate
Incorporating into Janet • Share Service Manager • Share skills between teams • Roadmap not shared • Targets not shared • New Business Processes! Janet Strategic Technologies Operations Product Management Based in Loughborough University CSIRT ESISS Based in Janet Offices, Harwell Service Manager: Wally Jackson
The Initial Services • Automated Penetration Testing • Manual Penetration Testing • Consultancy • 6 month review for other services
Automated Penetration Testing • On demand testing for potential vulnerabilities on external systems and websites • Testing is specifically designed to check for the most common vulnerabilities • Continuously updated vulnerability database • Easy to use web interface for management of scanning and reporting • Provides remediation advice on securing vulnerabilities
Manual Penetration Testing • Manual testing by experienced and certified testers, carried out to industry standards • Team members have wide experience of common educational applications • A complete service from scoping, project management, through to testing and reporting • Report provides executive overview, graphical summary and detailed analysis
Consultancy • Janet has had the skills internally, however has lacked the route • Supporting the outcomes from penetration testing • ... also providing support for security issues arising from the work of CSIRT • ... and other security work, best practises, security management incident response training
Key Points • Service as normal for existing ESISS customers, including price • Same certified testing team • For the sector, by the sector • Several new contracts since taking ESISS into Janet
WHY? • How does penetration testing help your organisation? • Part of an audit: security, IT, financial • Compliance: PCI-DSS, data protection • To improve your security
PENETRATION TESTING AS A CONTROL • Penetration testing won’t make a system 100% secure (nothing will) • Reduces the likelihood that the system can be compromised, and so reduces the risk • Demonstrates a certain standard of care towards your information
HOW SHOULD IT BE USED • Perhaps around your most sensitive assets and applications • When new applications are first deployed • As part of the QA and release processes for software development. • When needed - on demand • Scheduled - check for unexpected changes, new vulnerabilities • A mix of the above depending on the risks
THANK YOU Janet, Lumen House Library Avenue, Harwell OxfordDidcot, Oxfordshire t: +44 (0) 1235 822200 f: +44 (0) 1235 822399 e: service@ja.net