14
Aims & Expectations of Gibraltar Cyber Security Forum 2010 By Joseph M Torres Gibraltar Regulatory Authority

CTO-CybersecurityForum-2010-Joe Torres

Embed Size (px)

Citation preview

Page 1: CTO-CybersecurityForum-2010-Joe Torres

Aims & Expectations of Gibraltar

Cyber Security Forum 2010

By Joseph M Torres

Gibraltar Regulatory Authority

Page 2: CTO-CybersecurityForum-2010-Joe Torres

Introduction

Page 3: CTO-CybersecurityForum-2010-Joe Torres

Putting Things into Perspective

• Gibraltar’s population <30k

• Economy– Tourism– Financial Services– Online Gambling

Page 4: CTO-CybersecurityForum-2010-Joe Torres

Small Jurisdiction but…

• World Class Online Gambling Operators

• Gambling attracts Cyber Crime– Fraud– Denial of Service– Personal Data / Identity theft

Page 5: CTO-CybersecurityForum-2010-Joe Torres

Importance of a CERT

• Government

• Organisations

• Community

• Need for robust mechanisms– Swift action– Fast response and management of threats– Minimize downtime & disruptions

Page 6: CTO-CybersecurityForum-2010-Joe Torres

Current legal Instruments

• Communications Act 2006– Protecting the infrastructure (GRA)

• Data Protection Act 2004– Protecting the privacy of the individual (GRA)

• Crimes (Computer Hacking) Act 2009– Criminalising illicit use of computers (Police)

Page 7: CTO-CybersecurityForum-2010-Joe Torres

Dealing with Cyber Threats

• Small– Home Users

• Medium– SME

• Large– Network / Service Providers

Page 8: CTO-CybersecurityForum-2010-Joe Torres

Key Players

• Network Operators• Service Providers• Law Enforcement• MoD• Government• GRA

Page 9: CTO-CybersecurityForum-2010-Joe Torres

Sharing of Information

• Between Operators– Network– Gambling

• Between Government Agencies– Ministries– Law enforcement

Page 10: CTO-CybersecurityForum-2010-Joe Torres

Need for CERT?

• Locally– Already established under other committees– Resource management – Legal framework– Self regulated

• International Coordination– No coordination with International Agencies– No central local point of contact

Page 11: CTO-CybersecurityForum-2010-Joe Torres

CERT Deliverables

• Coordination of resources– Local & International

• Monitoring of attacks

• Education i.e.– How to stop proliferation of virus

• Prevention

Page 12: CTO-CybersecurityForum-2010-Joe Torres

Who should be Responsible

• Government

• Operators

• Government Agency

Page 13: CTO-CybersecurityForum-2010-Joe Torres

Conclusions

• Need for formal resource coordination– Locally – Internationally

• Education

• Need for a CERT? – Clear cut guidelines– Committee or Independent body?

Page 14: CTO-CybersecurityForum-2010-Joe Torres

Thank you

Any Questions