Who’s on the other end of your digital transaction? COMPUTER AND COMMUNICATION SYSTEMS SECURITY The Italian Way Forward Presented By Donato Cardarelli.

Slides:



Advertisements
Similar presentations
Steps towards E-Government in Syria
Advertisements

ITU Regional Seminar on E-commerce Bucharest, Romania May 2002 National E-commerce Strategies for Development Dr. Susanne Teltscher United Nations.
Launching Egyptian Root CA and Inaugurating E-Signature Dr. Sherif Hazem Nour El-Din Information Security Systems Consultant Root CA Manager, ITIDA.
AFACT eCOO WG interim meeting - Conference Call 1st March of 2011 Mahmood Zargar eCOO Experiences and Standards.
Course: e-Governance Project Lifecycle Day 1
August 2004 Providing Industry-wide Security and Identity Management Solutions.
Linking BRICS innovation potential through Innovation Networking Platform Sergey Korotkov Director, UNIDO CIIC Russia.
Standardization Framework (Myanmar) Ye Yint Win President Myanmar Computer Professionals Association Chair-Standardization Committee, Myanmar Computer.
Professional Development in INTOSAI – a whitepaper Jan van Schalkwyk (SAI SA) INTOSAI Capacity Building Committee - Meeting in Lima, Peru 9-11 September.
DIGITAL SIGNATURE AND ELECTRONIC DOCUMENTS IN ITALY Prof. Pierluigi Ridolfi AIPA Authority for Information Technology in the Public Administration V. Solferino,
6/2/2015Information Technology Standing Committee of the IMO 1 Digital Certificate Initiative Guy Springgay Holiday Inn - Oakville.
Page 1 ©2000 Bull Major Challenges in e-Government Value System in modern IS’s for Public services Claude Boulle, European Affairs FP 6 Consultation Meeting.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Quality Management Systems
The Knowledge Resources Guide The SUVOT Project Sustainable and Vocational Tourism Rimini, 20 October 2005.
The Evolution of the Payment Systems
IT security seminar Copenhagen, April 4th 2002 M. Jean-Michel HUBERT Chairman of the French Regulation Authority IRG Chairman.
European Public Sector Information Systems Conference -- September 30, 1998 Case Study: Building the Skills that Produce Success - A Case Study from the.
National Smartcard Project Work Package 8 – Security Issues Report.
E-Business Romania Adriana Ţicău State Secretary for Information Technology Conferinţele Piaţa Financiară Bucharest, the 26 th of March 2002.
“NATIONAL CHAMBER OF PRIVATE BAILIFF OFFICERS ” in the new era of the online execution SIAIP INTRODUCTION 16 th of December 2014.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
ALPINE SEARCH AND RESCUE FOR SLOVENIA AND ITALY. ALPSAR IN SHORT  Budget: € ,00  EC Contribution: € ,25 (75%)  Duration: 24 Months 
Giandonato CAGGIANO ENISA MANAGEMENT BOARD REPRESENTATIVE LEGAL ADVISER ON EUROPEAN AFFAIRS OF THE MINISTRY OF COMMUNICATIONS U. OF ROMA TRE LAW FACULTY.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
TTBIZLINK PROJECT MINISTRY OF TRADE, INDUSTRY, INVESTMENT & COMMUNICATIONS.
1 - 1 Copyright © 2006, The McGraw-Hill Companies, Inc. All rights reserved.
Dao Dinh Kha National Centre of Digital Signature Authentication - Agency of Information Technology Application A vision on a national Electronic Authentication.
Business Register Interoperability Throughout Europe Vito Giannella European Business Register eeig.
Trust 2 ™ Share your confidential information assets without headaches about unauthorized leakage WIM COULIER, SENIOR PROJECT MANAGER CERTIPOST
INTERNATIONAL COOPERATION PUBLIC CONSULTATION FIRST OVERVIEW EXPORTIC 27 March 2008 JF SOUPIZET HEAD OF INTERNATIONAL RELATIONS DG INFSO These view are.
TFTM Interim Trust Mark/Listing Approach Paper Analysis of Current Industry Trustmark Programs and GTRI PILOT Approach Discussion Deck TFTM Committee.
Transboundary Trust Space September 19, 2012 Development trends of legal acts in forming valid transboundary electronic interaction Alexander Sazonov Regional.
The Global Centre for Information and Communication Technologies in Parliament 14 June 2006 V Legislative XML Workshop Towards European Standards for Legislative.
European Commission Competitiveness and Innovation Framework Programme (CIP)
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
1 EAP and EAI Alignment: FiXs Pilot Project December 14, 2005 David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Towards a European network for digital preservation Ideas for a proposal Mariella Guercio, University of Urbino.
Logo Add Your Company Slogan China Financial Certification Authority Third-party certification authority Team 13 :吉露露、吴莹莹、潘韦韦 ( CFCA )
WIPO Pilot Project - Assisting Member States to Create an Adequate Innovation Infrastructure to Support University – Industry Collaboration.
Massella Ducci Teri Italian approach to long-term digital preservation Policies for Digital Preservation ERPANET Training Seminar.
THE NEW DIMENSIONS OF THE EUROPEAN PUBLIC PROCUREMENT POLICY Christian SERVENAY DG MARKT/Unit C1.
Transboundary Trust Space February 16, 2012 Ensuring trust in information exchange – proposal and approaches from Russia and CIS-states (RCC states) National.
EPC Roadmap One year on, how are we doing? EPC Strategy Off-site, Durbuy, 2 October 2005 Gerard Hartsink, EPC Chair PRES.
1 European eGovernment Awards 2007 European eGovernment Awards 2007 Workshop for Finalists July, Brussels LIMOSA Belgium Reference project number.
European Commission - DG Research - Directorate B – “Structuring the European Research Area” Jean-David MALO – Bucharest, February 12-13, NOT LEGALLY.
LEFIS Steering Committee Meeting Brussels, 11th November 2005 SOCRATES PROGRAMME ERASMUS - Thematic Network projects LEFIS - APTICE: Legal Framework for.
Features Governmental organization Critically important ICT objects Distributed infrastructure Three levels of confidentiality Dozens of subsidiary organizations.
TeleTrusT PKI WG Information and Activities PKI-Forum, 19-Jun-2001 Fritz Bauspiess Secorvo Security Consulting GmbH Albert-Nestler-Straße.
© UPU 2010 – All rights reserved International e-services Farah Abdallah E-Postal Services Programme UPU.
TPO Services An institutional perspective By: Miguel CAMACHO & Ann PENISTAN, TS/DBIS Date: 31 March 2011.
Vienna 14 March 2006 Andrew J. Popham Vice-President of FEE Partner, PricewaterhouseCoopers LLP The New Directive on Statutory Audit in the EU.
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
Joint UNECE/Eurostat work session on statistical data confidentiality October 2015 Helsinki, Finland Circle of trust Maurice Brandt DESTATIS.
The role of the EBA The EBA was established by Regulation (EC) No. 1093/2010 of the European Parliament and EU Council; came into being on 1 January 2011;
Sicherheitsaspekte beim Betrieb von IT-Systemen Christian Leichtfried, BDE Smart Energy IBM Austria December 2011.
BIMILACI 2007 Partners for Quality Infrastructure: The FIDIC Vision Washington, May 10, 2007 Dr. Jorge Díaz Padilla FIDIC President.
Towards a European Shared Environmental Information System in Support of Environmental Policies: INSPIRE: an Inspired revolution for a knowledge-based.
André Hoddevik, Project Director Enlargement of the PEPPOL-consortium 2009.
Incorporating Privacy Into Systems Development Methodology Phil Moleski Director Corporate Information Technology Branch Saskatchewan Health
Frank Schipplick Work Package Coordinator WP1 - eSignatures.
Bob Jones EGEE Technical Director
The ePhyto Solution A Guide to implement the ePhyto System
E-Commerce for Developing Countries (EC-DC)
The Government Role in BOT
a. Financing b. Designing c. Construction d. Operating
Working Group on Statistical Confidentiality Item 3 of the Agenda
Neopay Practical Guides #2 PSD2 (Should I be worried?)
Presentation transcript:

Who’s on the other end of your digital transaction? COMPUTER AND COMMUNICATION SYSTEMS SECURITY The Italian Way Forward Presented By Donato Cardarelli Identrus project director Actalis Bucharest September 23th

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 2 Agenda ACTALIS: the company product and services ACTALIS and Identrus The italian banks approach to Identrus steps goals the GUII the project European Directive and AIPA a case study: banks will join (CNIPA) AIPA and Identrus

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 3 December 2001 ACTALIS was founded by SIA (Società Interbancaria per l’Automazione) and SSB (Società per i Servizi Bancari) March 2002 ACTALIS has been enrolled in the italian Public Register of Certification Authorities for digital signatures, assuming the role of Certification Authority acting on his own and on behalf of SIA and SSB

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 4 January 2003 SECETI Certification Authority branch joins ACTALIS for digital signature purposes. SECETI being part of the shareholders May 2003 BNL Multiservizi Certification Authority and e-security branches merge in ACTALIS that increase his capital and the shareholders

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 5 The company mission ACTALIS acts both as PKI competence center and ICT security player in Italy and in foreign countries. Integrity, confidentiality, non repudiation, secure transmission over networks and strong authentication are the key words of our knowledge Today ACTALIS is also a full-service provider for the design, the deployment and the integration with the customer applications of digital signature systems (PKI - Public Key Infrastructure) In this specific area, ACTALIS is operating different Certification Authorities following the market requests: - electronic signatures customer tailored - digital signatures under the italian law - in full outsourcing for Identrus banks

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 6 Products and Services Certificationservices Digital Signature Products Consulting and Training

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 7 The ACTALIS approach to Identrus: “let banks focusing on business” ACTALIS started in 2001 to talk with banks about Identrus as following: make banks have a full understanding the “trust framework” of Identrus (knowledge transfer) address specific issues on specific themes via working groups (business, legal, organisational, technical) identify all possible sharing solutions (cooperative project ) providing outsourcing services (as Thirdy Party Processor)

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 8 Agenda ACTALIS: the company product and services ACTALIS and Identrus The italian banks approach to Identrus steps goals the GUII the project European Directive and AIPA a case study: banks will join (CNIPA) AIPA and Identrus

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 9 Initiatives of the Identrus italian banks The following italian banks participate in Identrus in 2002: Banca di Roma (Capitalia Group) (*) Banca Intesa (*) Banca Lombarda Banca Monte dei Paschi di Siena (*) Banca Nazionale del Lavoro SanPaolo Imi(*) UniCredit

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 10 The steps of italian banks September-December SSB Identrus Feasibility study – eleven banks involved 28th February 2002 – seven banks formally signed the participation agreement in Identrus (Candidate Participant Agreement) March 2002 – four of these banks implemented measures to be operational during 2003 (Project goals definition ) December 2002 – the phase of technical certification by Identrus LLC (interoperability and pre-production test) has been undertaken 2003 – completion of the on-boarding and production process for the first Business Application

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 11 Feasibility study executive summary (dec 2001) Identrus is the best solution for those seeking a PKI standard with a global international valence for corporate services Identrus is considered one of the major international initiatives for a world-wide interoperability of the financial services Identrus is designed and evolves in accordance with the needs shared by the bank industry The dissemination of Identrus with the major financial operators of the single european market creates the conditions for strong competition Identrus can play a major role also in the domestic security of on-line services

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 12 The main working areas Organisation Rules Technologies Business Auditing The italian banks have a clear and common understanding that the main are of work are strictly related to the rules that Identrus identify and manage in order to guarantee interoperability

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 13 Project goals  To define and to develope a first Business Application which effectively exploits the services offered by Identrus  To manage the on-boarding process (necessary phase to obtain Identrus certification with the bank in ‘live’ mode ) in a regime of interbank co-operation, to maximise policy sharing and project documentation  The realization of an Identrus compliant PKI technological environment, shared among several banks and customised for domestic type needs (co-existence/interoperability with the AIPA framework)  Identification of ACTALIS as solution provider

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 14 GUII (Gruppo Utenti Identrus Italia - Identrus Italy Users Group)  GUII has the following objectives:  to promote adoption of the Identrus standard;  to co-ordinate all the activities based on Identrus-related themes in a domestic environment, harmonizing with international themes;  to put in place specific workgroups focusing on themes of common interest and to verify areas of co-operation, if applicable, in the framework of business applications;  to identify criteria and methods of representing and co-ordinating communications activities, both in relation to Identrus and in relation to the market

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 15 GUII relationships Founder members Banca di Roma Banca Intesa Banca Lombarda Banca MPS BNL Sanpaolo Imi UniCredito New participants …... GUII ABI (Italian Bankers’ Association) Bank of Italy SWIFT ASSOCERTIFICATORI CIPA ……… IEWG EBA

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 16 The italian project The project output includes : the definition and the realisation of the complete infrastructure for issuing and validating certificates including test, production, disaster recovery environment; the realisation of the signing and validation software for customer (ISIL-ISPI DSMS); the definition of deliverable for the Identrus on-boarding; the definition of OBS (organisational breakdown structure) in which 4 banks and Actalis work together

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 17 The italian project (...) The project output includes : the definition and respect of the approval process for all deliverables; the relationship with Identrus; professional services for technical, operational, legal aspects; integration tests of the infrastructure with SWIFT TRUSTACT; the accreditation process to AIPA; the outsourcing for CA and VA services

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 18  Decision-making levels  Operational levels Steering Committee Project Committee Policies and Procedures Testing and Inspection Bank-Side Components Service Components Peripheral Components Architecture Dealings with Identrus Legal Aspects Communications Plan Service Agreements Business Sub-committee Technical/Org. Workgroup. Legal Workgroup Business Pilot Definition Project Structure

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 19 Up to date Timeschedule JulyAugustSeptember Key ceremony Certificates issuing SWEEP November Delivery CCAG legal opinion October Infrastructure delivery Identrus RAP

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 20 Agenda ACTALIS: the company product and services ACTALIS and Identrus The italian banks approach to Identrus steps goals the GUII the project European Directive and AIPA a case study: banks will join (CNIPA) AIPA and Identrus

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 21 The italian banks: will leverage the investments; will propose their customer with certificate spending in differente areas; will provide a legal opinion compliant with italian law; will be Certification Authority in respect to the italian law (AIPA); will issue “qualified certificates” which are the highest level of certificate in the italian environment. A qualified certificate will be legally binding and is the only certificated accepted by Public Administration in Italy European directive and AIPA

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 22 Use of the Identrus certificate the certificate issued by an italian banks to their customers will be spent in coherence with: Identrus, as close circuit (made by banks for banks); italian law, as it gives legal proof to document signed with “accredited digital signature”; european directive, which represents the trade union between the two ….. TYPE 5 ! QES and SSCD (qualified electronic signature and secure device)

COMPUTER AND COMMUNICATION SYSTEMS SECURITY 23 Lesson learned The key factors are Business, Methodology, Joint Forces Business is the driver from which every customer starts; in the Identrus project banks went forward because they were aware of it Methodology is the easy approach to permit large organisation to focus and gain intra customer communication and inter customers communication Joint Forces permit to gain common understanding, and achieving results (reducing significantly cost and identifying easily solutions)