160 likes | 709 Views
Polish National System FOR Cyber Defence. COL. PIOTR GRZYBOWSKI , Director, Classified Information Protection Department. Agenda. Polish National System of the Cyber Defence - structures and operation,
E N D
Polish National System FORCyber Defence COL. PIOTR GRZYBOWSKI, Director, Classified InformationProtection Department UNCLASSIFIED
Agenda • Polish National System of the Cyber Defence - structures and operation, • Policy, doctrine, resource and armaments related issues of the development and operation of the Cyber Defence System of the POL MoND. UNCLASSIFIED
Cyber Security capabilities - how to get? • Legal framework • Military regulations • National regulations • International regulations • Organizational structures • MIL-CERT • GOV-CERT CYBER SECURITY • Technical enhancement • IT security measures UNCLASSIFIED
Cyber Defence in Military Sphere CyberSpace Critical Infrastructure IT CI UNCLASSIFIED
Response for computer and IT systems incidents National Cyber Defence System Governmental Coordination Centre Security Policy for CyberDefence CyberCrime CyberTerrorism, CyberWar MoND MCIS Internal Security Agency FOCUS POINT OF CONTACT MILITARY POLICE POLICE MIL CERT CERT GOV CERT PL CERT Teams (eg. ABUSE Forum) UNCLASSIFIED
Legal basis of POL Military CIRC • MoND Decision No 357/MON dated 29 Jul 2008 about organization and functioning Computer Incident Response System in MoND. • MoNDDecision No 38/MON dated16 Jan 2012 – which establishedtherole of Representative of the Minister of National Defence for Cyber Security • Guidelines and Directions of Military Counter-Intelligence Service. • Computer Incident Response Capability Handbook – in co-ordination with Military Counter-Intelligence Service. • CIRC Standard Operational Procedures in MoND. • Strategy of IT development within Ministry of National Defence Republic of Poland. • Vision of Polish Armed Forces 2030. UNCLASSIFIED
Responsibilities NCIRC TC NATO CERT Polska Research and Academic Network in Poland (NASK) CERT.gov.pl Internal Security Agency Military Counter-Intelligence Service MILITARY POLICE Polish Military Contingent MIL-CERT military sphere MILREP MOU between NATO CDMA and POL NSA concerning cooperation on Cyber Defence POC for military network is MCISA Agreement between DoD of US and MoND the Republic of Poland concerning cooperation on IA and CND UNCLASSIFIED
Cyber Defence Structure in POL MoND Coordination Centre ======================= IT&T DEPARTMENT The Polish computer incident response system has been created as NATO initiative three-layered organisational structure Technical Support Centre division of MCISA RAPID REACTION TEAM IT Systems Administrators military units (Div, Brig) and organizational cells of MoND UNCLASSIFIED UNCLASSIFIED
Information sharing of military CERT related to Cyber Defence Non - governmental organisations International bodies Governmental entities NATO CIRC Coordination Centre and Technical Support Centre Internal Security Agency CERT GOV PL CERT PL NASK NATO agencies Service of military counter intelligence ABUSE Forum Other CSIRT US agencies POLICE HQ ….but not only. Other CSIRT (CERT Team) MILITARY POLICE HEADQUARERS UNCLASSIFIED
Cyber Security activities • International cooperation: • Information Assurance/Computer Network DefenceMoU (signed in June 2010) with DoD US - forms basis for cyber defence cooperation • sharing information with NATO CIRC TC; • Cooperative Cyber Defence Centre of Excellence - planned. • Exercises: • International Cyber Defence Workshops; • Cyber Endeavor; • NATO Cyber Defence workshops ; • EU Cyber Defence workshops; • National Cyber Defence workshops. • Courses, symposia, conferences, and other form. UNCLASSIFIED
Nearest future… • Development of „National Policy for Cyberspace Security ” and„Security Policy for Cyber Defence”; • Reorganization and extending MIL CERT Poland; • Introducing Early Warning System; • Implementation of (dynamic modification) Incident Handling Manual with Standard Operational Procedures. UNCLASSIFIED
Final remarks on POL CIRC activities • Close cooperation amonggovernmental and non-governmental organizations (corporations and ISP’s); • Synergy of technical, legal and organizational actions is the key issue; • Necessity of fast adaptation to new threats and conditions; • Users’ awareness enhancement in the field of current threats and ways of protection; • Critical infrastructure protection – essential to assure security of the country. UNCLASSIFIED
THANK YOU for yourattention UNCLASSIFIED