Presentation is loading. Please wait.

Presentation is loading. Please wait.

Pascal JACQUES – ESTAT B0 Local Informatics Security Officer

Similar presentations


Presentation on theme: "Pascal JACQUES – ESTAT B0 Local Informatics Security Officer"— Presentation transcript:

1 Pascal JACQUES – ESTAT B0 Local Informatics Security Officer
ESS Security Practitioners Network “Item Towards an ESS secure architecture“ Pascal JACQUES – ESTAT B0 Local Informatics Security Officer 12-13 Jun 2012 2nd SISAI Meeting

2 EU ETS €30M Cybercrime in the UK £27B/year
Internet Security - What is the problem? An evolving scenario – Threats and risks Steady growth in number, scope, sophistication of attacks A few key examples… …? 10% probability Of a major CII breakdown in the next 10 years – potential global economic cost of over $250B (Source WEF) Estonia Lithuania --- Georgia Cables cuts in the Mediterranean Stuxnet Emission Trading System (EU ETS) --- French Government EC and EEAS Sony DigiNotar EU ETS €30M Global cybercrime: $388B/year $175M Cybercrime in the UK £27B/year 12-13 Jun 2012 2nd SISAI Meeting

3 Study Steps towards a truly Internal Market for e-communications In the run-up to 2020
Differences in security regulations represent a (semi-) natural barrier to operating in multiple countries and to achieving global economies of scale. These differences lead to replication costs (up to 27 times) for pan-European operators. Harmonisation could lead to some economies of scale, but these differences are more or less inherent to the level of discretion enjoyed by the individual Member States regarding security and privacy. Harmonising the implementation of regulation aimed at security and consumer protection is seen as an 'avoidable barrier'. 12-13 Jun 2012 2nd SISAI Meeting

4 Challenges (1) Improve statistical production chain efficiency
Streamline data transfer between MS an ESTAT EDAMIS project under revision Towards web services? Revise validation process (1st and 2nd validation) GSAST, TRIS, EBB/EVE remote validation and exchange of validation rules Revise specific production chains SIMSTAT NAPS Rationalise data dissemination Census HUB Provide access to confidential data for research purposes Needs to increase IT security in order to build trust between ESS partners HLC-IT. Rationalisation of EU IT Development. Item on trans-european networks Fight against Cyber-criminality Standards, interoperability, policies/compliance Costs 12-13 Jun 2012 2nd SISAI Meeting

5 Challenges (2) Implementation of the vision COM 404/2009 and the ESS Joint Strategy (May 2010) and the proposed 4 strategic directions Network Secure connection of large databases Transfer/Access of confidential information between ESS partners Secure data formats and protocols Networks integration Information Stores More and more exchange of microdata sets for data linking Combination of confidential/non confidential/administrative datasets. Security/confidentiality of the output? Set up an ESS secured data warehouse architecture Modular Production Towards more exchange of SW. Ensure SW to be shared is secure (certification?) Optimal Collaboration Secured access to datasets/rules for validation Procedures for collaboration/accesses/sharing/User management AAA Protocol: Authentication/Autorisation/Auditing. Traceability/Privacy/Monitoring/Reporting 12-13 Jun 2012 2nd SISAI Meeting

6 CIA: the attributes of Information Security
Networks Information Stores Modular Production Optimal Collaboration 12-13 Jun 2012 2nd SISAI Meeting

7 Related projects/programmes
ESSnet projects data warehouse decentralised access EGR VIP projects SICON Data Validation CENSUS Hub FP7 projects: Data Without Boundaries DASISH, ENGAGE, EUDAT Programmes Digital Agenda, ISA Programme (sTESTA,etc) Regulation 923/2009, 831/2002, EuroGroup Register, FRIBS 12-13 Jun 2012 2nd SISAI Meeting

8 Role of the Network Know better each other and our specificities
Exchange of Best Practices in IT security in MS Agree on common rules, procedures, guidelines and standards for secure communication ( s) and data storage/exchange/transfer – BUILD MUTUAL TRUST Agree on security level of shared applications, services, processes Exchange information on Security measures used in MS for data protection, data centre, access to microdata for research purposes (Confidential) Projects/programmes linked to information security IT architecture in MS to better understand the MS’s capacity to join a shared secured datawarehouse Set up a repository of information on people, roles, procedures, best practices and documentation of infrastructures (CROS portal?) 12-13 Jun 2012 2nd SISAI Meeting

9 Actions Finalise the MS consultation and get feedback on the initiative (SISAI) Already positive feedback from AT, CH, DE, ES, NL, PT, SE, SI, UK Waiting more information: FR, IT Visits to some NSIs to understand their infrastructure Present a draft action plan to ITDG (October 2012) Organise an « Enterprise Architecture Security Workshop » end of 2012 Possible pilot project with a few MS to exchange secure messages on CCN (Common Communication Network of DG TAXUD) 12-13 Jun 2012 2nd SISAI Meeting


Download ppt "Pascal JACQUES – ESTAT B0 Local Informatics Security Officer"

Similar presentations


Ads by Google