230 likes | 327 Views
Introduction. Peter De Witte Information Security Officer for the IT Department Advisor for Software Development Infrastructure. Introduction SVB. SVB Sociale Verzekeringsbank 15 different national insurance schemes. Child Benefits, AOW Pensions, Anw Survivor Benefits
E N D
Introduction • Peter De Witte • Information Security Officerfor the IT Department • Advisor for • Software Development • Infrastructure
Introduction SVB • SVB SocialeVerzekeringsbank • 15 different national insurance schemes. • Child Benefits, AOW Pensions, Anw Survivor Benefits • 100 years + • 5 Million Clients • € 35 Billion on a yearly basis.
how can SVB assure adequate levels of securityand gaincustomers trust, while maximizingqualityandeffectivenessof citizen service? 25 may 2012
Security, Trust, Quality & Effectiveness • Awareness • Provide a secure IT • Proper use of availablechannels • Adequate response to incidents
Employee Awareness • Code ofConduct • Security Guidelines • Classification ofinformation • Incident response • Organisation ofInformation Security
Employee Awareness • Email policy
Provide a secure IT • NEN-ISO/IEC 27002:2007 nl (BS27002) • CMMi • ITIL • OWASP • Security testing • Standard forwebapplicationsprovidedbyLogius in cooperation with NCSC
3 Security levels for DIGID: Basis: login code (username + password) Middle: login code + textmessage on a mobile phone High:electronicidentifier (notyetimplemented)
Shared secret Soon: 2 way sslauthentications Open A Select server Soon: SAML Server
Response to incidents: Case Diginotar • Diginotar: certificateswere no longertrusted • DIGID was affecteddirectly, SVB indirectly • Ifcustomerswantedto login, theyreceived a warningof anunsafecertificate
Case Diginotar: response SVB (short term) • Form aninternal crisisteam • Inventory of SVB certificates • Link up withother sister organisationsandMinistry of the Interior and Kingdom Relations • Communication to the customer, ifnecessary
Case Diginotar: response SVB (long term) • Back-up CA • Investigation of the Dutch Safety Board • CooperatewithLogiusand sister organisationstodevelopandimplement new standards frameworkfor users of DIGID • Start of expert center intiatedby public service providers
Responses fromexternalparties SUWI: “the SVB has a technical and organizational infrastructure of such a standard, that such an incident can be adequately addressed.Apparently the citizens understood where the problems where and have enough confidence in the SVB web service to continue itsuse.” Dutch Safety Board (stillunofficial): Indicationtowards a positivereaction National Ombudsman: Positivereactiontowardshow SVB deals withcustomersand customer data
Future • Keep ourown security up to date • Proactivetowards new developments, likecloud. • Cooperation withexternalparties