You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 26 Next »


GÉANT Security and Privacy white paper:

White paper

GÉANT Security and Privacy activities

White paper

Annex 1: Baselining for Products Services and Organisations 


Annexes (Action templates)


Annex 2: Firewall on Demand











GN4-3 Security White Paper outline for download

We aim to provide guidance for security activities for GÉANT and th

e NRENs for the period of 2018 – 2022. In the GN3-4 Security White Paper, we will address some of the cybersecurity challenges of the NREN community, focussing on six main areas:

Main themes
Security Baselining for products, services and organisations Agreed frameworks and guidelines, their applications, what they mean for the organisation, frameworks as a means to prove and improve mutual trust between organisations thru benchmarking and sharing, both organisational and technical
(Managed) Security products and servicesServices delivered by NRENs or joint services delivered by GÉANT, for example Certificate Services (TCS, other), DDoS mitigation, (virtualised) Firewalling, and others. Research into the use of emerging technologies such as quantum cryptology and blockchain technologies. 
Legal compliance (including privacy compliance)EU and other regulations on security, privacy and data sharing, measures that need to be taken and implemented (GDPR[i], NIS Guideline, EIDAS, to mention a few), representing NRENs in influencing what the regulations will be about in the future
Management of risks 

Identifying risks, risk management methods, risk registers, (cyber) threat assessments, threat intelligence sharing, sharing best practices 

Training and awarenessCreating cyber security awareness culture, communicating risks, threats and their mitigation internally; specific training needs of the security officers, applying the newest training methods (online trainings, serious gaming, simulation)
Incident response, business continuity and crisis managementAddressing and managing security breaches and attacks not only on networks, but also on internal services, ways of dealing with unexpected threats, managing crises, preparing for the unexpected

[i] In this paper, we will not discuss implementing GDPR compliance as the new GÉANT Task Force will be working on it.

Community Consultations

Community consultations are organised to:

  1. Collect feedback on the 6 main themes identified 
  2. Collect specific ideas that could be included in the paper 
  3. Rate the ideas suggested from the most to least urgent 

The results of the community consultations:

ConsultationDate, placeResults
SIG-ISM Security white paper consultation5 October, BrusselsSLIDES
Public Security white paper consultation (1)16 October, OnlineSLIDES
Public Security white paper consultation (2)25 October, OnlineSLIDES & additional proposals
Public Security white paper consultation (3)31 October, Online
Joint results (ratings)-

Security white paper brainstorm sessions results.xlsx

(including 25 October)

Authors

Alf Moens (SURFnet)

Sigita Jurkynaitė (GÉANT)


 

  • No labels