SlideShare a Scribd company logo
Allignment of CIIP Structures Bernhard M. Hämmerli President Swiss Informatics Society  & Acris GmbH May 31 Davos
Overall Conclusions and Recommendations Content: Parsifal Project  Attack and Defence Structure Centre for European Policy Studies CEPS Taskforce Preparedness and Reaction Structure Conclusions are taken for each part separately
Overall Conclusions and Recommendations Before Parsifal: Thematic Workshop September 2007 About Parsifal:  P rotection  a nd T r u s t  i n  F inanci al  Infrastructure Type Co-ordination Action, Duration 18 Month, Start September 1, 2008 Related Projects:  Comifin (Strep), Think Trust  Advisory Board,  RISEPTIS .  5  Partner:  Atos Origin SAE (Spain), Avoco Secure LTD (UK), @bc (Germany) EDGE International BV (The Netherlands), Waterford Institute of Technology  (Ireland), Acris GmbH (Switzerland) Parsifal Project objectives Bringing together CFI and TSD research stakeholders in order to establish and nurture relationships between the financial sector stakeholders and the ICT TSD RTD communities Contributing to the understanding of CFI challenges Developing longer term visions, research roadmaps, CFI scenarios and best practice guides Co-ordinating the relevant research work, knowledge and experiences.
Initial Workshop: Background Workshop March 16/17 in Frankfurt, Germany Many Topics: Payment, Settlement, Stocks, BCM/DRP, Identity, Rating … Participants: ca. 70% executives and experts from CFI, ca. 30% academic and research Stakeholder Group Parsifal  100 experts from very senior to topic experts Market specific challenges: Identified by Parsifal / Break out group topics: Group 1:   Controlling Instant On Demand Business in CFI:  Authentication, Identity Management, Resilience and Denial of Service  Group 2:   Entitlement Management and Securing Content in the Perimeterless Financial  Environment: Identity, Policy, Privacy and Audit [ 1,2 ]   Identity is a s a new currency, it is absolutely essential Group 3:   Business Continuity and Control in an Interconnected and Interdependent Service  Landscape: Compliance, Protecting Critical Processes  Description of status on international FI - Operational:  Strong activities on BCM, Dependability, (Inter-)Dependencies probably not sufficient ready for new and upcoming issues - Regulation:  T o o o o  strong activities on regulation: Risk of conformity in risk evaluation - Strategic & Research: ????????  (not sufficiently provided)
Conclusions on Structures Attack and Defence Structure (Mapping Scenarios and Challenges) Need to align the structure, known means   Public Private Partnership integrated in a global context
5. Business Continuity and Control in an Interconnected and Interdependent Service Landscape.  Recommendation 7/8 Design and implementation of secure platforms and applications Secure platforms and backup platforms,  including new levels of virtualized worlds Secure applications (including legacy): design, implementation and operation Application performance auditing: Application foot-printing Alternate secure communication channel  (vs. virtualization) Data centre dependencies analysis Establishment of adequate and well networked coordination response  teams
5. Business Continuity and Control in an Interconnected and Interdependent Service Landscape.  Recommendation 8/8 Model Definition Testing, design and implementation of secure platform, applications and infrastructure (including simulation) through trustworthy exercises between CIP Sector and government s Extensions of BCM and DRP Models including regular tests and evaluations and simulation The extensions are amongst others: - risk sharing models - end-to-end communication models; end point security - modelling complexity and volume of transaction in a reasonable way
Overall Conclusions and Recommendations Conclusions Parsifal Project  Attack and Defence Structure must be aligned through Public Private Partnership, global cooperation and regulation as well inter corporation collaboration (main business competition, security is in spite of this a collaboration domain) Common metrics and method to assess risks and common exercises on supra national, i.e. Regional continental and global scale are required Global agreement on standards and process to face a global challenges (Airtraffic, Climate Change)  are urgently needed
CEPS I Goals Defining policy options on CIP Shaping a public-private partnership: opportunities and challenges.  CI and CII: a Transatlantic perspective Risk assessment and CIP and CIIP-related issues in EU policy making    Increase Preparedness and Reaction Structure
CEPS II About the taskforce Selected early outcome Preparedness: 27 EU member states need attention of supplier Reaction: 27 EU member states need attention of supplier Not possible to finance for suppliers: An organized preparedness and reaction structure must be developed Define CIIP exposure metrics and risk assessment which are internationally agreed on Incidents are not national or regional,  but global.  Global entities (as e.g. In air traffic IATA ) are needed to counter fight the global challenge

More Related Content

PPTX
Financial instruments for climate change: the way forward in the next long-te...
PPT
MAKING GWP’S KNOWLEDGE CHAIN WORK presented by Mohamed AIT KADI at Stockholm...
PPT
Gabriel Rissola, Managing Director, Telecentre-Europe (ES)
PPTX
Horizon 2020 ICT and Advanced Materials & Manufacturing
PPT
Business Modles as Systemic Instruments?
PDF
Presentation-at-CHARME-Workshop-25-26Oct2016-ROME
PDF
Ippc conference14082014
PDF
Nanofutures and the European Pilot Production Network
Financial instruments for climate change: the way forward in the next long-te...
MAKING GWP’S KNOWLEDGE CHAIN WORK presented by Mohamed AIT KADI at Stockholm...
Gabriel Rissola, Managing Director, Telecentre-Europe (ES)
Horizon 2020 ICT and Advanced Materials & Manufacturing
Business Modles as Systemic Instruments?
Presentation-at-CHARME-Workshop-25-26Oct2016-ROME
Ippc conference14082014
Nanofutures and the European Pilot Production Network

Similar to Allignment of CIIP Structures (20)

DOCX
Img s position-paper_for_h2020
PDF
International Cooperation Experiences: Results Achieved, Lessons Learned, and...
PPTX
COVID-19 Strategic Response Lab | Deloitte
PDF
COVID-19 Strategic Response Lab | Deloitte
PDF
Tenia Chatzinikoli APM RISK MANAGEMENT SIG CONFERENCE
PDF
Foresight Methods and Practice: Lessons Learned from International Foresight ...
PPTX
Examining End-User Standardisation Needs for Disaster Resilience
PPTX
Carbon Market 2.1? Networks and the riddle of fair and ambitious climate coop...
PPT
10 Trends in Capability Planning for Defence and Security
PPTX
A stakeholder based approach to standardisation for disaster resilience
PDF
CEFI Roadmap for India workshop III
PDF
Building Climate Resilient Value Chains
PDF
A Major Revision of the CISRCP Program
PDF
Entrepreneurship (Project identification)
PDF
Secure Societies & Space in HORIZON 2020 - Khoen Liem - Israel 3.2.2014
PDF
Lecture on Innovation & Cost Saving Strategies in Facilities Management
PDF
NAMAs for Sustainable Refrigeration, Air-conditioning and Foam Production
PDF
Towards Quantification of Cyber Risk
PDF
_03 Experiences of Large Banks
PPT
ITS Toolkit
Img s position-paper_for_h2020
International Cooperation Experiences: Results Achieved, Lessons Learned, and...
COVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | Deloitte
Tenia Chatzinikoli APM RISK MANAGEMENT SIG CONFERENCE
Foresight Methods and Practice: Lessons Learned from International Foresight ...
Examining End-User Standardisation Needs for Disaster Resilience
Carbon Market 2.1? Networks and the riddle of fair and ambitious climate coop...
10 Trends in Capability Planning for Defence and Security
A stakeholder based approach to standardisation for disaster resilience
CEFI Roadmap for India workshop III
Building Climate Resilient Value Chains
A Major Revision of the CISRCP Program
Entrepreneurship (Project identification)
Secure Societies & Space in HORIZON 2020 - Khoen Liem - Israel 3.2.2014
Lecture on Innovation & Cost Saving Strategies in Facilities Management
NAMAs for Sustainable Refrigeration, Air-conditioning and Foam Production
Towards Quantification of Cyber Risk
_03 Experiences of Large Banks
ITS Toolkit
Ad

More from Global Risk Forum GRFDavos (20)

PPTX
Disaster Risk Management Knowledge Centre, Brian Doherty
PPTX
Disaster risk reduction and nursing - human science research the view of surv...
PPTX
Global alliance of disaster research institutes (GADRI) discussion session, A...
PPTX
Towards a safe, secure and sustainable energy supply the role of resilience i...
PDF
Making Hard Choices An Analysis of Settlement Choices and Willingness to Retu...
PPTX
The Relocation Challenges in Coastal Urban Centers Options and Limitations, A...
PPT
C&A Save the Children Urban DRR Project, Ray KANCHARLA
PPT
Involving the Mining Sector in Achieving Land Degradation Neutrality, Simone ...
PPTX
Disaster Risk Reduction and Nursing - Human Science research the view of surv...
PPTX
Training and awareness raising in Critical Infrastructure Protection & Resili...
PPTX
IDRC Davos 2016 - Workshop Awareness Raising, Education and Training - Capaci...
PPTX
Global Alliance of Disaster Research Institutes - Hirokazu TATANO
PPTX
Capacity Development for DRR, Beatrice PROGIDA
PPTX
Dynamic factors influencing the post-disaster resettlement success Lessons fr...
PPTX
Consequences of the Armed Conflict as a Stressor of Climate Change in Colombi...
PPTX
Disaster Risk Perception in Cameroon and its Implications for the Rehabilitat...
PPTX
Systematic Knowledge Sharing of Natural Hazard Damages in Public-private Part...
PPTX
Exploring the Effectiveness of Humanitarian NGO-Private Sector Collaborations...
PPTX
Can UK Water Service Providers Manage Risk and Resilience as Part of a Multi-...
PPTX
A Holistic Approach Towards International Disaster Resilient Architecture by ...
Disaster Risk Management Knowledge Centre, Brian Doherty
Disaster risk reduction and nursing - human science research the view of surv...
Global alliance of disaster research institutes (GADRI) discussion session, A...
Towards a safe, secure and sustainable energy supply the role of resilience i...
Making Hard Choices An Analysis of Settlement Choices and Willingness to Retu...
The Relocation Challenges in Coastal Urban Centers Options and Limitations, A...
C&A Save the Children Urban DRR Project, Ray KANCHARLA
Involving the Mining Sector in Achieving Land Degradation Neutrality, Simone ...
Disaster Risk Reduction and Nursing - Human Science research the view of surv...
Training and awareness raising in Critical Infrastructure Protection & Resili...
IDRC Davos 2016 - Workshop Awareness Raising, Education and Training - Capaci...
Global Alliance of Disaster Research Institutes - Hirokazu TATANO
Capacity Development for DRR, Beatrice PROGIDA
Dynamic factors influencing the post-disaster resettlement success Lessons fr...
Consequences of the Armed Conflict as a Stressor of Climate Change in Colombi...
Disaster Risk Perception in Cameroon and its Implications for the Rehabilitat...
Systematic Knowledge Sharing of Natural Hazard Damages in Public-private Part...
Exploring the Effectiveness of Humanitarian NGO-Private Sector Collaborations...
Can UK Water Service Providers Manage Risk and Resilience as Part of a Multi-...
A Holistic Approach Towards International Disaster Resilient Architecture by ...
Ad

Recently uploaded (20)

PDF
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
PDF
How to Get Approval for Business Funding
PDF
NewBase 12 August 2025 Energy News issue - 1812 by Khaled Al Awadi_compresse...
PDF
Booking.com The Global AI Sentiment Report 2025
PDF
Digital Marketing & E-commerce Certificate Glossary.pdf.................
PDF
Comments on Crystal Cloud and Energy Star.pdf
PDF
Deliverable file - Regulatory guideline analysis.pdf
PDF
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
PDF
Solaris Resources Presentation - Corporate August 2025.pdf
PPTX
2025 Product Deck V1.0.pptxCATALOGTCLCIA
PDF
Technical Architecture - Chainsys dataZap
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
Module 2 - Modern Supervison Challenges - Student Resource.pdf
PDF
NEW - FEES STRUCTURES (01-july-2024).pdf
PDF
How to Get Funding for Your Trucking Business
PDF
1911 Gold Corporate Presentation Aug 2025.pdf
PDF
ANALYZING THE OPPORTUNITIES OF DIGITAL MARKETING IN BANGLADESH TO PROVIDE AN ...
PPTX
Astra-Investor- business Presentation (1).pptx
PPT
Lecture 3344;;,,(,(((((((((((((((((((((((
PPTX
operations management : demand supply ch
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
How to Get Approval for Business Funding
NewBase 12 August 2025 Energy News issue - 1812 by Khaled Al Awadi_compresse...
Booking.com The Global AI Sentiment Report 2025
Digital Marketing & E-commerce Certificate Glossary.pdf.................
Comments on Crystal Cloud and Energy Star.pdf
Deliverable file - Regulatory guideline analysis.pdf
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
Solaris Resources Presentation - Corporate August 2025.pdf
2025 Product Deck V1.0.pptxCATALOGTCLCIA
Technical Architecture - Chainsys dataZap
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
Module 2 - Modern Supervison Challenges - Student Resource.pdf
NEW - FEES STRUCTURES (01-july-2024).pdf
How to Get Funding for Your Trucking Business
1911 Gold Corporate Presentation Aug 2025.pdf
ANALYZING THE OPPORTUNITIES OF DIGITAL MARKETING IN BANGLADESH TO PROVIDE AN ...
Astra-Investor- business Presentation (1).pptx
Lecture 3344;;,,(,(((((((((((((((((((((((
operations management : demand supply ch

Allignment of CIIP Structures

  • 1. Allignment of CIIP Structures Bernhard M. Hämmerli President Swiss Informatics Society & Acris GmbH May 31 Davos
  • 2. Overall Conclusions and Recommendations Content: Parsifal Project Attack and Defence Structure Centre for European Policy Studies CEPS Taskforce Preparedness and Reaction Structure Conclusions are taken for each part separately
  • 3. Overall Conclusions and Recommendations Before Parsifal: Thematic Workshop September 2007 About Parsifal: P rotection a nd T r u s t i n F inanci al Infrastructure Type Co-ordination Action, Duration 18 Month, Start September 1, 2008 Related Projects: Comifin (Strep), Think Trust Advisory Board, RISEPTIS . 5 Partner: Atos Origin SAE (Spain), Avoco Secure LTD (UK), @bc (Germany) EDGE International BV (The Netherlands), Waterford Institute of Technology (Ireland), Acris GmbH (Switzerland) Parsifal Project objectives Bringing together CFI and TSD research stakeholders in order to establish and nurture relationships between the financial sector stakeholders and the ICT TSD RTD communities Contributing to the understanding of CFI challenges Developing longer term visions, research roadmaps, CFI scenarios and best practice guides Co-ordinating the relevant research work, knowledge and experiences.
  • 4. Initial Workshop: Background Workshop March 16/17 in Frankfurt, Germany Many Topics: Payment, Settlement, Stocks, BCM/DRP, Identity, Rating … Participants: ca. 70% executives and experts from CFI, ca. 30% academic and research Stakeholder Group Parsifal 100 experts from very senior to topic experts Market specific challenges: Identified by Parsifal / Break out group topics: Group 1: Controlling Instant On Demand Business in CFI: Authentication, Identity Management, Resilience and Denial of Service Group 2: Entitlement Management and Securing Content in the Perimeterless Financial Environment: Identity, Policy, Privacy and Audit [ 1,2 ]  Identity is a s a new currency, it is absolutely essential Group 3: Business Continuity and Control in an Interconnected and Interdependent Service Landscape: Compliance, Protecting Critical Processes Description of status on international FI - Operational: Strong activities on BCM, Dependability, (Inter-)Dependencies probably not sufficient ready for new and upcoming issues - Regulation: T o o o o strong activities on regulation: Risk of conformity in risk evaluation - Strategic & Research: ???????? (not sufficiently provided)
  • 5. Conclusions on Structures Attack and Defence Structure (Mapping Scenarios and Challenges) Need to align the structure, known means  Public Private Partnership integrated in a global context
  • 6. 5. Business Continuity and Control in an Interconnected and Interdependent Service Landscape. Recommendation 7/8 Design and implementation of secure platforms and applications Secure platforms and backup platforms, including new levels of virtualized worlds Secure applications (including legacy): design, implementation and operation Application performance auditing: Application foot-printing Alternate secure communication channel (vs. virtualization) Data centre dependencies analysis Establishment of adequate and well networked coordination response teams
  • 7. 5. Business Continuity and Control in an Interconnected and Interdependent Service Landscape. Recommendation 8/8 Model Definition Testing, design and implementation of secure platform, applications and infrastructure (including simulation) through trustworthy exercises between CIP Sector and government s Extensions of BCM and DRP Models including regular tests and evaluations and simulation The extensions are amongst others: - risk sharing models - end-to-end communication models; end point security - modelling complexity and volume of transaction in a reasonable way
  • 8. Overall Conclusions and Recommendations Conclusions Parsifal Project Attack and Defence Structure must be aligned through Public Private Partnership, global cooperation and regulation as well inter corporation collaboration (main business competition, security is in spite of this a collaboration domain) Common metrics and method to assess risks and common exercises on supra national, i.e. Regional continental and global scale are required Global agreement on standards and process to face a global challenges (Airtraffic, Climate Change) are urgently needed
  • 9. CEPS I Goals Defining policy options on CIP Shaping a public-private partnership: opportunities and challenges. CI and CII: a Transatlantic perspective Risk assessment and CIP and CIIP-related issues in EU policy making  Increase Preparedness and Reaction Structure
  • 10. CEPS II About the taskforce Selected early outcome Preparedness: 27 EU member states need attention of supplier Reaction: 27 EU member states need attention of supplier Not possible to finance for suppliers: An organized preparedness and reaction structure must be developed Define CIIP exposure metrics and risk assessment which are internationally agreed on Incidents are not national or regional, but global. Global entities (as e.g. In air traffic IATA ) are needed to counter fight the global challenge