OSCT-2

Europe/Zurich
513/1-027 (CERN)

513/1-027

CERN

19
Show room on map
Ian Neilson (CERN), Romain Wartel
Description
Operational Security Coordination Team meeting. To dial in to the conference: a. Dial +41227676000 (Main) b. Enter access code 0142490 Or, to be called by the system, you can click here: https://audioconf/call/0142490
Slides
Participants
  • Alessandra Forti
  • Alexander Verkooijen
  • Carlos Fuentes Bermejo
  • David Jackson
  • David Kelsey
  • Denise Heagerty
  • Eddie Aronovich
  • Eddie Aronovich
  • Emanouil Atanassov
  • Ian Neilson
  • Pawel Wolniewicz
  • Pål ANDERSSEN
  • Riccardo Brunetti
  • Rolf Rumler
  • Romain Wartel
  • Ryabinkin Eygene
  • Serge Droz
  • Stanislav Spasov
  • Ursula Epting
  • Åke Sandgren
    • 09:00 09:30
      Introduction

      Introduction, agenda of the day, and progress made since OSCT-1

    • 09:30 10:30
      Round-table: EGEE-wide OSCT activities

      Different tasks for OSCT have been identified.
      How do the ROCs propose we achieve them?
      How can we collaborate and share the load?

      While this list is by no mean exhaustive or authoritative,
      the proposed tasks so far cover:
      - OSCT communications with other groups and the sites
      - Incident Response improvement
      - Security tools (monitoring, detection, prevention)

      During this session, all ROCs are welcome to comment on
      proposed tasks and their priority, and according to their
      preferences and availability, offer some contribution on one
      or more area.

      slides
    • 10:30 11:00
      Coffee break 30m
    • 11:00 12:00
      Round-table: Sensitive information reporting and disclosure

      OSCT needs to deal with sensitive information, but must also
      be able to communicate with all the sites and other external
      projects.

      Specific issues have recently been reported, for which
      feedback and recommendations from the ROCs would be necessary:

      • What is the best way to handle the information flow for
        unpatched software or operational vulnerabilities? (GSVG ->
        OSCT -> all sites)

      • How can we resolve or mitigate SPAM problems on the
        incident reporting channels, while enabling external
        communities to contact our CSIRTs?

      • Do we need a both a CSIRT and a CONTACTS list?

    • 12:00 13:30
      Lunch break 1h 30m
    • 13:30 14:00
      Security Service Challenges

      SSC2 debriefing and future plans.

      slides
    • 14:00 14:20
      Regional security: IT ROC

      Presentations from the ROC representative as to how security
      operations are organised in his region.

    • 14:20 14:50
      Regional security: SEE ROC

      Presentations from the ROC representative as to how security
      operations are organised in his region.

    • 14:50 15:05
      ISSeG update

      Update on the EGEE related projected, ISSeG
      (http://www.isseg.eu) and collaboration with OSCT.

      slides
    • 15:05 15:35
      Coffee break 30m
    • 15:35 15:50
      Collaboration with other monitoring groups

      Introduction about the monitoring groups currently being
      setup, in particular the System Management:

      https://uimon.cern.ch/twiki/bin/view/LCG/SystemManagementWGMandate

      and discuss about the security part of the mandate.

      slides
    • 15:50 16:30
      Round-table: Security Monitoring

      There are several monitoring tools/frameworks that could be
      used for security purpose, such as (but not limited to) SAM,
      Pakiti, or lcg-fw.

      • How could be use these tools?
      • Do we want to provide/maintain them?
      • How could we promote their use among the sites?
    • 16:30 17:00
      OSCT Duty Contact

      The OSCT-DC role has been implemented since OSCT-1.

      • Is there any good/bad feedback from the ROCs about this?
      • How can we improve the role?
    • 17:00 17:15
      AOB and next meeting