26
Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect April 16th, 2019

Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Identity and Access ManagementCase Study: How to play with 70 billion dollars?

Julien Bois

IAM Solution Architect

April 16th, 2019

Page 2: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

What did you hear about this fraud?

Page 3: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Société Générale: Bigger than any Canadian Bank

French commercial bank with, in 2007:

- 150 000 employees

- 30 million clients

- 34 billion $ of income

End of 2007, Société Générale had:

- 35 billion of capital stock

- 7 billion of profit- 1.3 billion of profit

All amounts are in Canadian dollars

Page 4: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

SG CIB : 3 jobs of an Investment Banker

Trader: Buy or sell shares

for bank’s corporate clients

Commissions

No risk

Own trading: Profit thanks

to knowledge of market

Market change

Risk limit: 175 millions

Arbitrageur: Use market

inefficiencies

Value differencies

No risk

Page 5: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Example of Arbitrage Operations

Successful arbitrage operation: TD Share between TMX and NYSE

Unauthorized directional position

CAD 62

1 share

USD 48CAD 64+ CAD 2

Instantly

January 2008

From 2 to 18

70,000,000,000 $ 61,000,000,000 $

From 21 to 23Futures

DAX 30

- 9,000,000,000 $

Page 6: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

What would be IAM weaknesses that would let him fraud?

Page 7: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

947 fictive operations to hide the risk taken by the bank

Intra-monthly provisions

Cancelled or updated transactions

Inexistent counterparts

Differed transactions

Page 8: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Indulgence and access to trading control

Internal move of Jérôme Kerviel :

- From: Control (Middle Office)

- To: Trading (Front Office)

Understanding deficiencies of

control teams

Indulgence from his

previous friends

Access conservation

to systems to follow controls

Page 9: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Proximity control failures

Trading assistant complicity

Lack of managerial oversight

Ignored warnings

- Volume increase

- Unusually high results

- EUREX Warnings

- Unusual cash needs

- Incoherent explanations

- Limit overtaking

- Refusal to take holidays

Page 10: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

How IAM could have prevented this event to happen?

Page 11: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Focus 2010 Initiative , incorporated with Fighting Back

From 2007 to 2010

CAD 15 million

26 applications

Paris

2011 180

World100

Page 12: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 1: POPS (Personal Organisation Provisioning Services)

Trustable source for identities

Business role management

Appropriate approval for new accesses

Access deactivation for leavers

Page 13: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 1: Movers management

Segregation of duties

Access copy prohibited

Formalized exception procedure

Deactivation after moves

Page 14: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 1: Business role implementation

Permissions and applicative profiles dictionary

Organizational business roles

Access sensibility evaluation

Stake holder accountability

Page 15: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 1: UAR (User Account Review)

Real Time Access Data

Access Certification

Account Ownership

Access Deactivation Checks

Page 16: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 2: TALC (Technical Account Life Cycle)

Access Approval

Privileged Account Management (BreakGlass)

Segregation between Account and Access

: Planned or Incident

Page 17: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 2: Privileged access management

Ownership identification

Environment segregation

Accounts and privileges review

Access management delegation

Page 18: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream 4: Advanced Authentication Solutions

Sésame RTFE : Authentication, Authorization

Non-interactive password management

Strong authentication

Page 19: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Stream Ressources humaines

Position rotation

Mandatory holidays

Limits formalization

Control Team independence

Page 20: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Which of those initiatives look new ?

Page 21: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Conclusion about event caused by Jérome Kerviel

Very small personal gain

Fortuitous discovery

Luckless calendar

Dramatic consequences

Page 22: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Additional

readings

Green Report (in French):

www.lefigaro.fr/assets/pdf/GREEN.pdf

Initiative Fighting Back (in French):

www.societegenerale.com/sites/default/files/documents/Co

ntrol_messages_updated_final_2905.pdf

Page 23: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Cybersecurity – What is it?

Protect data on 3 aspects:

- Confidentiality

- Integrity

- Availability

Page 24: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Cybersecurity – Which certifications?

Certifications in cybersecurity:

- ISACA (CISA, CISM, …)

- ISC2 (CISSP, ISSAP, …)

- CompTIA (Security+, CASP, …)

- GIAC – SANS

- EC-Council (CEH, …)

- Vendors: Microsoft, Cisco,

Symantec, HP, Juniper, McAfee,

Red Hat, CA, AWS

Page 25: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

15 Top-Paying IT Certifications for 2019 (Global Knowledge)

1. Google Certified Professional Cloud Architect - $139,529

2. PMP® - Project Management Professional - $135,798

3. Certified ScrumMaster® - $135,441

4. AWS Certified Solutions Architect - Associate - $132,840

5. AWS Certified Developer – Associate - $130,369

6. Microsoft Certified Solutions Expert (MCSE): Server Infrastructure - $121,288

7. ITIL® Foundation - $120,566

8. CISM - Certified Information Security Manager - $118,412

9. CRISC - Certified in Risk and Information Systems Control - $117,395

10.CISSP - Certified Information Systems Security Professional - $116,900

11.CEH - Certified Ethical Hacker - $116,306

12. Citrix Certified Associate - Virtualization (CCA-V) - $113,442

13.CompTIA Security+ - $110,321

Page 26: Identity and Access Management - ottawa-outaouais.iiba.org€¦ · Identity and Access Management Case Study: How to play with 70 billion dollars? Julien Bois IAM Solution Architect

Cybersecurity – How to learn ?

Training is available easily:

- Certifiers: SANS, EC-Council, CompTIA, …

- Books: Amazon, Ottawa Library, …

- Online: Udemy, Cybrary.it, Lynda, Pluralsight, …

- MOOC: edX, Coursera, FutureLearn, …

- Ottawa: Carleton, La Cité Collégiale, Algonquin, …

- Vendors: Microsoft, Symantec, CA Technologies, …

More info: www.cybersecuritymastersdegree.org