Πέμπτη 18 Δεκεμβρίου 2014

ENISA CERT training

ENISA has launched a new section on its website introducing the ENISA CERT training program. In the new section, you can find all the publicly available training resources and the training courses currently provided by ENISA.
The material has been categorized into 4 main topics:
  • Technical,
  • Operational,
  • Setting up a CERT, and
  • Legal and cooperation.
Additionally, various tools for hands-on training (such as Virtual Machines) are provided. In 2014 training scenarios were added covering various topics in the area of artifact handling and analysis. Artifact analysis involves receiving information about artifacts that are used in attacks, reconnaissance, and other unauthorized or disruptive activities. The created course covers the topics of building an artifact handling and analysis environment, the fundamentals for artifact analysis, as well as advanced artifact analysis and a common framework for artifact analysis activities.

Visit the new page and material here.

Topics

Technical
  • Building artifact handling and analysis environment
  • Processing and storing artifacts
  • Artifact analysis fundamentals
  • Advanced artifact handling
  • Developing Countermeasures
  • Common framework for artifact analysis activities
  • Identification and handling of electronic evidence
  • Digital forensics
  • Mobile threats indident handling
  • Proactive incident detection
  • Automation in incident handling
  • Network forensics
  • Honeypots
  • Vulnerability handling
  • Presenting, correlating and filtering various feeds
Operational
  • Incident handling during an attack on Critical Information Infrastructure
  • Advanced Persistent Threat incident handling
  • Social networks used as an attack vector for targeted attacks
  • Writing Security Advisories
  • Cost of ICT incident
  • Incident handling in live role playing
  • Incident handling in the cloud
  • Large scale incident handling
Setting Up a CERT
  • Triage & Basic Incident Handling
  • Incident handling procedure testing
  • Recruitment of CERT staff
  • Developing CERT infrastructure
Legal and Cooperation
  • Establishing external contacts
  • Cooperation with law enforcement
  • Assessing and Testing Communication Channels with CERTs and all their stakeholders
  • Identifying and handling cyber-crime traces
  • Incident handling and cooperation during phishing campaign
  • Cooperation in the Area of Cybercrime
  • CERT participation in incident handling related to the Article 13a obligations
  • CERT participation in incident handling related to the Article 4 obligations

Τετάρτη 19 Νοεμβρίου 2014

ENISA Set to Establish a Framework for Cyber Security Competitions


Today the European Union Agency for Network and Information Security (ENISA) announced the planning of the 1st pan-European Cyber Security Competition in 2015. The competition is organised jointly in collaboration with experienced organisations from EU Member States for students.

The Organizing Committee of the 1st pan-European Cyber Security Challenge is composed of the following representatives: 
  • Norbert Pohlmann - Cyber Security Challenge Germany;
  • Joe Pichlmayr — Cyber Security Challenge Austria;
  • Andrei Avădănei —DefCamp Romania; 
  • Raúl Riesco- INTECO Spain;
  • Okonweze Austen — Cyber Security Challenge UK;
  • Bernhard Tellenbach — Swiss Cyber Storm;
  • Demosthenes Ikonomou- ENISA and
  • Rafael Tesoro-Carretero- EC DG CONNECT.
Cybersecurity competitions — the status in Europe

ENISA also publishes a new report analyzing the current situation concerning cybersecurity- challenge competitions in Europe. The experience gathered constitutes the basis for the development of the pan-European competition on cybersecurity.

The European Cyber Security Challenge Competition 2015 aims to be the result of a public–private partnership comprised of capable players, aiming at improving the ICT educational approach to Europe’s digital citizens.

The report provides a general overview of existing cybersecurity- challenge competitions in Member States and outlines a roadmap for a future pan-European cyber-challenge competitions. The first part presents the experience of five countries while the second comprises of a short ‘how to’ guide containing the steps in organizing a challenge. The third part gives details on concrete developments concerning a pan-European challenge. The last part of the report contains several recommendations that should be taken into account. Graphics providing additional content are provided in the annex.

Κυριακή 16 Νοεμβρίου 2014

Startups Awarded in Cyber Security & Privacy, by EIT ICT Labs

It is a big challenge to protect security and privacy of enormous amounts of data being collected, processed and stored in the cyber space. Lack of timely technical solutions may put at risk privacy and liberty of citizens and may endanger the growth of ICT-enabled products and services, whereas security breaches can have significant negative impact on people’s lives, jobs and property. The existing gaps between currently available techniques and the situation in practice should be filled by innovative solutions following the "privacy & security by design" paradigm.
This can stimulate innovative applications, e.g. related to social networks, e-payment, e-voting, e-health, smart spaces and smart energy, as well as cloud computing, big data and Internet of Things. Special attention should be devoted to privacy-preserving digital identity management, user profiling, intrusion detection and prevention and protection against malicious software, especially for mobile platforms and applications.

From 479 teams across the EU that applied for the Idea Challenge in autumn, 230 ideas addressed the topics Internet of things and Cyber Security & Privacy. On November 13th, the best 21 startups in these two categories were invited to present their ideas at pitch finals in Trento and Stockholm. At these events, which were initiated by EIT ICT Labs and its partners Trento Rise and STING, a jury consisting of industry experts, investors, business accelerators, and entrepreneurs selected the best six teams based on the quality of innovation and their respective business model.

EIT ICT Labs is one of the first Knowledge and Innovation Communities set up by the European Institute of Innovation and Technology, as an initiative of the European Union. By linking education, research and business, EIT ICT Labs empowers ICT top talents for the future and brings ICT innovations to life. EIT ICT Labs’ partners represent global companies, leading research centres, and top ranked universities in the field of ICT.



Cyber Security & Privacy

First place, 40.000 €: CHINO - from Italy - provides safe and regulatory compliant data storage for mobile health applications, giving to application developers the opportunity to focus on users' needs.

Second place, 25.000 €: Cleafy - from Italy - defends and certifies web-page source-code integrity in real time.

Third place, 15.000 €: Sentryo - from France - protects critical industrial networks against cyber attacks and provides network managers with full awareness over the situation.

Παρασκευή 14 Νοεμβρίου 2014

How does Trust looks like?

A trustmark is a sign displayed on an eCommerce website, it has the purpose to provide an independent guarantee of the trustworthiness and reliability of the webshop.

The aim of trustmarks is to guarantee the quality and security of the online transaction. In some countries, there are trustmarks and trustmark providers that inform consumers whether the website complies with a certain set of rules. The trustmarks can be certified according to a national certification scheme and supervised by the competent authority, or based on mutual agreements. Trustmarks can boost consumer confidence in cyberspace. However, trustmark schemes are often unknown to consumers. As a result, consumers in EU can find it difficult to identify reputable e-merchants in other EU markets and are therefore reluctant to shop online from another country.

The Digital Agenda for Europe clearly pursues the creation of an online internal market, putting in place policies fostering cross-border eCommerce in the EU. One of the key factors of eCommerce, be it cross-border or at national level, is trust between the parties: the purchaser and the merchant. Trustmarks can play a role in establishing trust relations. Trustmarks are especially useful for smaller e-shops that are not (yet) a strong online brand of their own.

The e-Mark U Trust Competition invited all EU design/art students to submit their most innovative designs. Students from all over the European Union were invited to design a simple, original and clever trustmark which conveys a sense of trust and reassurance and indicates that Internet users can carry out their online transactions in a safe, convenient and secure way. On 15 September 2014, 95 logos were submitted within the deadline. The winner and the final ranking will be announced in 2015.

The three finalists, in random order, are:


Image by ELSE
Image by EUSAFE
Image by Noblesse Oblige

Remember, in a few months one of these will be a medal of honor for any site capable of earning it!

Δευτέρα 29 Σεπτεμβρίου 2014

European Data Authorities vs. Google

In order for Google to comply with European Union law, EU privacy regulators recommended to the company to make its privacy policies easier to find and understand, by publishing exhaustive lists of what data it holds and processes.

On September 23rd, EU addressed a letter  to Larry Page where asks Google to determine the means to achieve these legal requirements: "Google must meet its obligations with respect to the European and national data protection legal frameworks..."

Google received the package of recommendations from the Article 29 Working Party (WP29), a group of European data protection authorities. While WP29 has no power to sanction the company, its members have imposed fines in a number of cases following Google's 2012 changes to its privacy policy, which several national privacy regulators found breached EU rules.
The guidelines are just one way the company could comply with the law, and are not compulsory, but neither do they pre-empt enforcement actions by national authorities, the WP29 said, adding that it remains open to discussing any other measures that Google would propose to address the legal requirements.

The privacy policy should have clear, unambiguous and comprehensive information regarding data processing, including an exhaustive list of the types of personal data processed. In case that should prove too much information for some, WP29 also suggested personalizing the privacy policy for authenticated users, showing them only the data processing it is performing on their data.
Google must also provide users with more elaborate tools to manage their personal data and to control the usage of their personal data between all Google services, WP29 said. This could be done by making the current dashboard more accessible and including all Google services in that dashboard, in order to allow users to control the use of their personal data.

There is no deadline set for Google to respond to the suggestions of the group. The WP29 is considering issuing guidance on specific issues to the entire industry at a later stage.

Τετάρτη 24 Σεπτεμβρίου 2014

Eiopa issues cyber warning

The European Insurance and Occupational Pensions Authority (Eiopa), one of EU financial regulator has called state regulators to check that insurance companies and other financial institutions devote sufficient resources to protect against growing IT risks. 

The risks facing the EU financial system have not changed substantially since the previous Joint Committee Report on Risk and Vulnerabilities, but recent developments illustrate that a number of key risks continue to challenge the stability of the European financial system:
  • prolonged period of low growth combined with high indebtedness  in private and public sectors; 
  • search-for-yield behavior risks that could be exacerbated by potential snapbacks; 
  • risks stemming from emerging market economies; 
  • risks from the deteriorating conduct of business by financial institutions; 
  • Increased concern about IT risks and cyber-attacks.
For more details you can read the full report