110 likes | 250 Views
Pacific Northwest Digital Summit, Tacoma, Washington June 21, 2005. Wireless Security Policies Session How the Port of Seattle Is Proceeding. Ernie Hayden, CISSP Chief Information Security Officer Port of Seattle. Today’s Agenda. Brief Overview of the Port of Seattle
E N D
Pacific Northwest Digital Summit, Tacoma, Washington June 21, 2005 Wireless Security Policies SessionHow the Port of Seattle Is Proceeding Ernie Hayden, CISSP Chief Information Security Officer Port of Seattle
Today’s Agenda • Brief Overview of the Port of Seattle • Underpinnings of Information Security Concerns and Wireless Technologies • High Level Overview of Our Process
Information Security & WirelessUnderpinnings • The “Convenience” Factor • Management, Management And Management
The “Convenience Factor” Increased Security Convenience More Less
The “Convenience Factor” Increased Liability Convenience More Less
Crossover Point moves based on Security Needs, etc. Where Does Wireless Fit? The “Convenience Factor” Increased Increased Liability Security Convenience More Less
Management, Management and Management • You Need To Educate MANAGEMENT About Wireless • Strengths, Weaknesses, Liabilities, Constraints • You Need To MANAGE The Wireless System & Environment • SSIDs, WEP Keys, MAC Addresses, Access Point Management, Locations, Rogue Access Points, Legacy Equipment • You Need To Watch Out for MANAGEMENT To Be Sure Their Enthusiasm Isn’t Too Excessive • Best Buy / Circuit City / Frye’s Purchases for Work and Play!
Port of Seattle Actions • Wireless Applications • Police Cars (Wireless & CDMA for Mobile Network Interface) • Hot Spots in Key Areas for Port of Seattle Police • Using In Motion; Plan to move to CISCO Mobile Router • Conference Rooms / Conference Areas • Evaluating for Future Deployment • Policies & Procedures • Still Under Development • Appropriate Use Procedure Requires CIO Written Approval for ANY Access Point Deployment
Conference Room Deployment • CISCO Access Points • 802.11g with WPA • SSIDs are Hidden • Access ONLY to Internet via Separate VLAN • Continued Access to Intranet is Via VPN Access and Authorization
Other Actions • Low-Tech Search for Rogue Access Points • Examining Future Deployment of 802.11i with 802.1x Authentication and AES Encryption • Bluetooth Concerns • Possible Compromise • Substantial Use on Smart Phones • Considering Security Policy / Guideline at a Minimum
Thanks! Ernie Hayden, CISSP CISO Port of Seattle 2711 Alaskan Way – Pier 69 Seattle, WA 98121 206-728-3460 Hayden.e@portseattle.org