OSG Area Coordinators Meeting Security Team Report Kevin Hill 08/14/2013.

Slides:



Advertisements
Similar presentations
Special Ed Director Meeting December 17, Agenda SSEM Statistics/Facts October Follow Up Forms Release SSEM 5.1 Release Current Issues/Questions.
Advertisements

Summer IAVA1 NATIONAL INFORMATION ASSURANCE TRAINING STANDARD FOR SYSTEM ADMINISTRATORS (SA) Minimum.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/02/2014.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 05/15/2013.
Jan 2010 Current OSG Efforts and Status, Grid Deployment Board, Jan 12 th 2010 OSG has weekly Operations and Production Meetings including US ATLAS and.
ITIL: Why Your IT Organization Should Care Service Support
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Key Accomplishments and Work Plans OSG Security Team July 11, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
OSG Area Coordinators Meeting Cross-ProjectArea Report Ruth Pordes 2/8/2011.
Key Project Drivers - FY11 Ruth Pordes, June 15th 2010.
Software Testing Life Cycle
OSG PKI Grid Admin (GA) Training Mine Altunay, Jim Basney OSG PKI Team October 8, 2012.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
OSG Area Coordinators Meeting Operations Rob Quick 2/22/2012.
OSG Security Review Mine Altunay June 19, June 19, Security Overview Current Initiatives  Incident response procedure – top priority (WBS.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011.
Deliverable Readiness Review LexEVS 5.1 December 17, 2009.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 06/25/2014.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Security Update WLCG GDB CERN, 12 June 2013 David Kelsey STFC/RAL.
OSG Security Kevin Hill. Goals Operational Security – Identify software vulnerabilities – observing the practices of our VOs and sites, and sending alerts.
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
Sampleminded® Support Overview Last Updated: 1/22/
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/3/2013.
Discussion Topics DOE Program Managers and OSG Executive Team 2 nd June 2011 Associate Executive Director Currently planning for FY12 XD XSEDE Starting.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
OSG Security Review Mine Altunay December 4, 2008.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Rob Quick OSG Operations Area Coordinator Manager High Throughput Computing Indiana University Integrating OSG Operational Services Rob Quick OSG Operations.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
OSG Cyber Security OSG Site Administrators workshop Indianapolis August Doug Olson LBNL Health.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch OSG Council August 23, 2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 11/02/2011.
Mine Altunay July 30, 2007 Security and Privacy in OSG.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 6/6/2012.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 November 2007.
Meeting Minutes and TODOs TG has no distributed monitoring. During incident response, use a manual twiki page to distribute information TG monitors the.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Agency Name Security Program FY 2009 John Q. Public Agency Director/CIO/ISO.
G Z LIGO's Physics at the Information Frontier Grant and OSG: Update Warren Anderson for Patrick Brady (PIF PI) OSG Executive Board Meeting Caltech.
Status Organization Overview of Program of Work Education, Training It’s the People who make it happen & make it Work.
OSG RA, DOEGrids CA features Doug Olson, LBNL August 2006.
Nodal Program Update Mike Cleary Sr. VP and Chief Technology Officer.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 4/11/2012.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
User Support of WLCG Storage Issues Rob Quick OSG Operations Coordinator WLCG Collaboration Meeting Imperial College, London July 7,
WLCG Operations Coordination report Maria Alandes, Andrea Sciabà IT-SDC On behalf of the WLCG Operations Coordination team GDB 9 th April 2014.
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
OSG PKI Transition Mine Altunay OSG Security Officer
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
Ruth Pordes, March 2010 OSG Update – GDB Mar 17 th 2010 Operations Services 1 Ramping up for resumption of data taking. Watching every ticket carefully.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
New OSG Virtual Organization Security Training OSG Security Team.
WLCG Operations Coordination Andrea Sciabà IT/SDC GDB 11 th September 2013.
OSG Security Review Mine Altunay March 12, Jan Security Overview Current Initiatives  OSG Security roadmap  Technical and operational.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SA1.2 Plans 2013 Security Operations David Kelsey (STFC) 26/02/2013 Operations.
OSG Security Kevin Hill.
Open Science Grid Consortium Meeting
ERCOT Technical Advisory Committee June 2, 2005
ITIL: Why Your IT Organization Should Care Service Support
ITIL: Why Your IT Organization Should Care Service Support
Leigh Grundhoefer Indiana University
ITIL: Why Your IT Organization Should Care Service Support
Presentation transcript:

OSG Area Coordinators Meeting Security Team Report Kevin Hill 08/14/2013

Key Initiatives Traceability – Traceability findings presented to Fermilab CS Board. – Committee was to be formed to draft changes to security policy changes to allow job submission without end user x.509 certificates. – Have not heard back on progress. – This is on the schedule for this Friday's CS Board meeting.

Key Initiatives CILogon Basic CA adoption – Fermilab is now accepting CI Logon Basic CA certificates issued for individuals at University of Illinois University of Wisconsin University of Chicago Indiana University. – Ran test to see how many CEs have CI Logon Basic CA cert installed. Found 25/75 CEs at 4-5 unique sites have it installed currently.

Operational Security There was an issue with a certificate in the OSG CA cert bundle expiring before the new version with a refreshed certificate was available. – This was a case of the igtf lead time vs. the software release freeze time not quite matching up. – In response we've set up a system to alert us if any CA cert is going to expire in the next 60 days. New CA cert bundle released at end of June. Next expected at end of August. Investigated possibility of ca cert bundles cleaning up orphan certificates on removal/upgrades. – This functionality is coming in a future release of fetch-crl, so won't be added to the ca bundle rpms.

Operational Security Recent security advisories – OSG-SEC Security vulnerability in Puppet allowed remote code execution. – OSG-SEC Security vulnerability in PHP allowed remote code execution. – OSG-SEC Security vulnerability in CVMFS allowed local privilege escalation.

Top Issues / Concerns Mine out until October, Kevin Hill acting Security Officer. Extending CILogon adoption: – Chicken/Egg issue in VOs need to register users with the certs as well as sites accepting them. – Now that we can check which sites are ready to accept CI Logon Basic certs, we can approach VOs with numbers on how many sites will accept.

Accomplishments Run security-related meetings with 1 new OSG VO. 1 more coming up. Security Controls assessment mostly complete. Still waiting for a few straggler service owners to complete surveys.

WBS Ongoing Activities 1Incident response and vulnerability assessment Minimizing the end-end response time to an incident, 1 day for a severe incident, 1 week for a moderate incident, and 1 month for a low-risk incient. 2Troubleshooting; processing security tickets including user requests, change requests from stakeholders, technical problems Goal is to acknowledge tickets within one day of receipt. 3Maintaining security scripts (vdt-update-certs, vdt-ca-manage, cert-scripts, etc) Maintain and provide bug fixes according to the severity of bugs. For urgent problems, provide an update in one week; For moderate severity, provide an update in a month; For low risk problems, provide an update in 6 months. 4XSEDE Operational Security Interface Meet weekly 5Supporting OSG RA in processing certificate requests Each certificate request is resolved within one week; requests for GridAdmin and RA Agents are served within 3 days. 6Preparing CA releases (IGTF), modifying OSG software as the changes in releases require CA release for every two months 7Security Policy work with IGTF, TAGPMA, JSPG and EGI Meet with IGTF and TAGPMA twice a year. Attend JSPG and EGI meteings remotely and face-face once a year. Track security policy changes and report to OSG management. 8Security Test and Controls Execute all the controls included in the Security Plan and prepare a summary analysis. 9 Incident Drills and Training Drill Tier3 sites 10Weekly Security Team Meeting to review work items Coordinate weekly work it ems. 11Weekly reporting to OSG-Production Report important items that will affect production; incidents, vulnerabilities, changes to PKI infrastructure 12Monthly reporting to OSG-ET Meet with ET once a month to discuss work items 13Quarterly reporting to Area Coordinator meeting Meet with area coordinators to discuss work items.