Security Communications in EOSC

Europe/Zurich
600/R-001 (CERN)

600/R-001

CERN

15
Show room on map
Sven Gabriel (Nikhef/EGI)
  • Tuesday 24 April
    • 09:30 17:30
      Day 1 8h 600/R-001

      600/R-001

      CERN

      15
      Show room on map
      1. Scoping, aims and context of the workshop. Agreement on the agenda
      2. Target Audience Analysis
        2.1 Identify communication endpoints, for example: Management, Peer Infras, Site/NGI Security Endpoints
        2.2 for these endpoints define
        • Why are we sending the notification.
        • Who should get an advisory, incident notification
        • What should be the content of this communication
      3. Definition of Performance Indicators, for ex.
        • Time from issue (Incident, Vulnerability, etc) report till final assessment
        • Time from issue (Incident, Vulnerability, etc.) report till report to clients
        • Number of mails used in this process (noise)
      4. Current Vulnerability Handling Process
      5. Vulnerability Handling Process in the EOSC era
  • Wednesday 25 April
    • 09:30 15:30
      Day 2 6h 513/R-068

      513/R-068

      CERN

      19
      Show room on map
      1. How to get a transparent Risk Assessment? Adapted CVSS-3?
      2. Discussion Risk Levels
      3. Communication Templates (As needed for the Updated Handling Process)
        3.1 Vulnerabilities (Recipients as defined at day-1)
        3.2 Incidents (Recipients as defined at day-1)
      4. Inventory of tools needed (goc-db, ipmt, rt(-ir) etc etc)