60 likes | 219 Views
Lessons learned and not learned. Enn Tyugu Leading research scientist NATO Cooperative Cyber Defense Center of Excellence. Who am I?. Educator and researcher at a technical university. Adviser at a center of excellence for cyber security. Citizen of a very small country. Who are we?.
E N D
Lessons learned and not learned Enn Tyugu Leading research scientist NATO Cooperative Cyber Defense Center of Excellence
Who am I? Educator and researcher at a technical university. Adviser at a center of excellence for cyber security. Citizen of a very small country.
Who are we? • Estonia is a small East European country highly dependent on IT: • 85% of income tax declarations are submitted via Internet • 98% of all banking operations are performed electronically (very few bank offices for public use) • E-Government provides services for citizens over Internet • Close to a big country that wishes to keep us in its “sphere of influence”.
How are we? • Cyber attcks on Estonia in spring 2007 demonstrated real threats in the cyber space. • A survey of the country’s CII disclosed that the most important weakness is lack of competent IA personal: Shortage of personal x x x x x x x x x x x x x Human factor x x x x x Insufficient IDS x x x x x Legal aspects x x x Insufficient resources x x x Physical dangers x x x Bosses don’t care x x Security problems x
Who should educate? • Insufficient competence in the universities • Insufficient teaching skills in the business and industry. • It is not the responsibility of military. • Only coordinated effort of the universities, military and industry can do it well.
What to teach? A CD master studies core competence: • Organizational aspects, incl. risk analysis • Legal aspects • Cryptography • Network security • Malware • Attacks and defense • IDS and log analysis • Simulation and practical work