STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th...

17
STRENGTHENING COOPERATION ON STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE CYBER SECURITY WITHIN THE ASEAN REGION ASEAN REGION The ASEAN Secretariat The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19 October 2007

Transcript of STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th...

Page 1: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

STRENGTHENING STRENGTHENING COOPERATION ON CYBER COOPERATION ON CYBER

SECURITY WITHIN THE ASEAN SECURITY WITHIN THE ASEAN REGIONREGION

The ASEAN SecretariatThe ASEAN Secretariat

The 4th ARF Seminar on Cyber TerrorismBusan, Korea, 16 – 19 October 2007

Page 2: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

ARF Cooperation on Cyber ARF Cooperation on Cyber SecuritySecurity

First ARF Seminar on Cyber First ARF Seminar on Cyber Terrorism, Jeju Island, October 2004Terrorism, Jeju Island, October 2004

Second ARF Seminar on Cyber Second ARF Seminar on Cyber Terrorism, Cebu City, the Philippines, Terrorism, Cebu City, the Philippines, October 2005October 2005

Third ARF Workshop on Cyber Security, New Delhi, September 2006

Fourth ARF Seminar on Cyber Terrorism, Busan, October 2007

Page 3: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Previous recommendationsPrevious recommendations Promote International and Inter-agency’s Promote International and Inter-agency’s

information sharing and cross-sectoral information sharing and cross-sectoral measures/activities measures/activities

Networking and dialogue (contact person, Networking and dialogue (contact person, web based, mailing list, phone/fax, etc.)web based, mailing list, phone/fax, etc.)

Working on and sharing guiding Working on and sharing guiding principles/ reference paper, best principles/ reference paper, best practices, case studies, technologies and practices, case studies, technologies and solutions, etc.solutions, etc.

Public-Private Partnership, e.g. the Social Public-Private Partnership, e.g. the Social Corporate Responsibility, especially for Corporate Responsibility, especially for the cross-border mattersthe cross-border matters

Page 4: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

ARF Statement on ARF Statement on Cooperation in Fighting Cooperation in Fighting

Cyber Attack and Terrorist Cyber Attack and Terrorist Misuse of Misuse of

Cyber Space Cyber Space

Page 5: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

ProgressProgress

ASEAN Convention on Counter-terrorismASEAN Convention on Counter-terrorism Adopted by ASEAN Leaders in January 2007 Adopted by ASEAN Leaders in January 2007

in Cebu, the Philippinesin Cebu, the Philippines The Convention includes Cyber-Terrorism in The Convention includes Cyber-Terrorism in

the areas of cooperation the areas of cooperation ASEAN Focal Points for CERTs ASEAN Focal Points for CERTs

ARF is working on the List of Contact PointsARF is working on the List of Contact Points Network of Technical (Expert) GroupNetwork of Technical (Expert) Group

ASEAN WG on Information Infrastructure ASEAN WG on Information Infrastructure Working on technical cooperation on N-Working on technical cooperation on N-

SOC, Network Monitoring CentreSOC, Network Monitoring Centre Capacity and confidence building activitiesCapacity and confidence building activities

Page 6: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Work in ProgressWork in Progress

Compilation of the national legislation on Compilation of the national legislation on cyber terrorism (cyber security issues)cyber terrorism (cyber security issues)

Mechanism for regional cooperation to Mechanism for regional cooperation to combat cyber terrorism combat cyber terrorism

ARF Centre on Counter Cyber-terrorismARF Centre on Counter Cyber-terrorism

Page 7: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

ASEAN Cooperation in ASEAN Cooperation in Policy and Regulation on Policy and Regulation on Network and Information Network and Information

SecuritySecurity

Page 8: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Cooperation in PolicyCooperation in Policy ASEAN Telecommunications and IT ASEAN Telecommunications and IT

Ministers and Senior Officials Meetings Ministers and Senior Officials Meetings (TELMIN/ TELSOM)(TELMIN/ TELSOM)

Platform for cooperation initiatives amongst ASEAN Platform for cooperation initiatives amongst ASEAN Member Countries, Dialogue Partners/industries to Member Countries, Dialogue Partners/industries to further enhance the progress, readiness, and further enhance the progress, readiness, and awareness of, amongst others, network and awareness of, amongst others, network and information security information security

TELSOM Working Group on Information TELSOM Working Group on Information Infrastructure Infrastructure

Technical knowledge and current challenges Technical knowledge and current challenges relating to the network and information security relating to the network and information security and available solutionsand available solutions

Operational activities and policy implementation Operational activities and policy implementation

Page 9: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

AchievementAchievement

Adoption of suitable international standards Adoption of suitable international standards (e.g., telecommunications and cyber-(e.g., telecommunications and cyber-security standards) security standards)

Put in place minimum performance Put in place minimum performance guidelines for setting up National CERTguidelines for setting up National CERT

Put in place guidelines for implementation Put in place guidelines for implementation of CERT cooperation in ASEANof CERT cooperation in ASEAN

Cooperation on Cyber-security skills Cooperation on Cyber-security skills Encourage the development of National Encourage the development of National

Security Operation Centre (N-SOC) and/or Security Operation Centre (N-SOC) and/or cooperation of the Network Monitoring cooperation of the Network Monitoring Centre to proactively manage, monitor and Centre to proactively manage, monitor and facilitate cross border information sharing facilitate cross border information sharing

Page 10: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Cooperation in RegulationCooperation in Regulation ASEAN Telecommunication Regulators ASEAN Telecommunication Regulators

Council (ATRC)Council (ATRC) 2005 Framework on Cooperation of Network 2005 Framework on Cooperation of Network

Security Security ATRC Action Plan ATRC Action Plan

ATRC Working Group on Network SecurityATRC Working Group on Network Security Evaluation of preparedness and right to enforce Evaluation of preparedness and right to enforce

against any network abuseagainst any network abuse Establishment of an ASEAN liaison networkEstablishment of an ASEAN liaison network ASEAN-wide user education and awareness raising ASEAN-wide user education and awareness raising

programs, technical solutions, periodic assessment, programs, technical solutions, periodic assessment, and and

ATRC Internet Access Service Provider (IASP) Forum ATRC Internet Access Service Provider (IASP) Forum International and regional cooperationInternational and regional cooperation

Page 11: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Multiplatform CooperationMultiplatform Cooperation ASEAN+ Dialogue Partners: ASEAN+ Dialogue Partners:

CERT Incident Drills with Dialogue PartnersCERT Incident Drills with Dialogue Partners An expanded exercise from the ASEAN-wide CID in 2006An expanded exercise from the ASEAN-wide CID in 2006 The ASEAN + DPs CID on 16 July 2007 (ASEAN, China, The ASEAN + DPs CID on 16 July 2007 (ASEAN, China,

Japan, Korea, India and Norway)Japan, Korea, India and Norway) Capacity Building Capacity Building

Workshops, seminars and training courses and technical Workshops, seminars and training courses and technical visits (China, Korea, Japan, and India)visits (China, Korea, Japan, and India)

ASEAN helps ASEAN ASEAN helps ASEAN ASEAN+ other Organizations:ASEAN+ other Organizations:

ASEAN+ APEC Workshop on Network Security at ASEAN+ APEC Workshop on Network Security at TEL 35, Manila - The Philippines, 24 April 2007TEL 35, Manila - The Philippines, 24 April 2007

Cooperation with ITU/APTCooperation with ITU/APT ASEAN+ Industry (MS, IBM, etc)ASEAN+ Industry (MS, IBM, etc)

Page 12: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Multiplatform CooperationMultiplatform Cooperation ASEAN+ China:ASEAN+ China:

Emergency Response Contact Mechanism by end of Emergency Response Contact Mechanism by end of 20072007

11stst CERTS Incidents Drill in 2007 (or 2008) CERTS Incidents Drill in 2007 (or 2008) Coordination Framework for Network and Coordination Framework for Network and

Information Security Emergency ResponsesInformation Security Emergency Responses China to join the ATRC Network Security Liaison China to join the ATRC Network Security Liaison

Network (Point of Contacts)Network (Point of Contacts) ASEAN+ Japan:ASEAN+ Japan:

a high-level meeting on ICT security issues a high-level meeting on ICT security issues in 2008in 2008 ASEAN+ EU:ASEAN+ EU:

Propose a Workshop to discuss and exchange views Propose a Workshop to discuss and exchange views on the EU Cyber-crime Convention. on the EU Cyber-crime Convention.

Page 13: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Disaster Relief Disaster Relief CommunicationsCommunications

A regional proposal on common A regional proposal on common frequency for disaster relief frequency for disaster relief communications in ASEAN Regioncommunications in ASEAN Region

ATRC is working on common ATRC is working on common frequencies for disaster relief frequencies for disaster relief

ATRC will consider to propose and/or ATRC will consider to propose and/or submit the proposal on a common set submit the proposal on a common set of frequencies for ASEAN Telecoms and of frequencies for ASEAN Telecoms and IT Ministers (TELMIN) to further IT Ministers (TELMIN) to further consider and/or adopt consider and/or adopt

Page 14: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Future Work ProgramFuture Work Program

Page 15: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Course of ActionsCourse of Actions Conduct the Seminar on Cyber Terrorism on Conduct the Seminar on Cyber Terrorism on

regular basisregular basis Exchange of views and knowledge on Exchange of views and knowledge on

regulations, cyber laws, and ICT Security regulations, cyber laws, and ICT Security Masterplan (Roadmap) Masterplan (Roadmap)

Establishment of the National Cyber Security Establishment of the National Cyber Security Agency (NISA, KISA)Agency (NISA, KISA)

Complete the List of Focal Points of the ARF Complete the List of Focal Points of the ARF National Cyber Security Agencies National Cyber Security Agencies

Further collaborate/cooperate within ARF Further collaborate/cooperate within ARF Members and with other Int’l Organizations Members and with other Int’l Organizations

Conduct technical training on technology and Conduct technical training on technology and solutions for counter-measures solutions for counter-measures

Sharing experience, model and benefit of the Sharing experience, model and benefit of the Public-Private Partnership (Gov’t-Business Public-Private Partnership (Gov’t-Business Forum on Cyber Security)Forum on Cyber Security)

Page 16: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Contact PointsContact Points

ARF Unit:

Mr. Pratap Parameswaran: [email protected] Ms. Retno Astrini: [email protected]

ICT Unit:

Mr. Nguyen Ky Anh: [email protected]

Page 17: STRENGTHENING COOPERATION ON CYBER SECURITY WITHIN THE ASEAN REGION The ASEAN Secretariat The 4 th ARF Seminar on Cyber Terrorism Busan, Korea, 16 – 19.

Thank youThank you