Transcript
Page 1: Welcome to Tomorrow ... Today

Copyright©2016Splunk Inc.

TimLeeCISO,CityofLA

ErnieWelchSalesEngineer,Splunk

WelcometoTomorrow...TodayTheneedandbenefitofmergingofITandSecurityintoday'severconnectedworldofsecurityandIT

Page 2: Welcome to Tomorrow ... Today

Disclaimer

2

Duringthecourseofthispresentation,wemaymakeforwardlookingstatementsregardingfutureeventsortheexpectedperformanceofthecompany.Wecautionyouthatsuchstatementsreflectourcurrentexpectationsandestimatesbasedonfactorscurrentlyknowntousandthatactualeventsorresultscoulddiffermaterially.Forimportantfactorsthatmaycauseactualresultstodifferfromthose

containedinourforward-lookingstatements,pleasereviewourfilingswiththeSEC.Theforward-lookingstatementsmadeinthethispresentationarebeingmadeasofthetimeanddateofitslivepresentation.Ifreviewedafteritslivepresentation,thispresentationmaynotcontaincurrentoraccurateinformation.Wedonotassumeanyobligationtoupdateanyforwardlookingstatementswemaymake.Inaddition,anyinformationaboutourroadmapoutlinesourgeneralproductdirectionandissubjecttochangeatanytimewithoutnotice.Itisforinformationalpurposesonlyandshallnot,beincorporatedintoanycontractorothercommitment.Splunkundertakesnoobligationeithertodevelopthefeaturesor

functionalitydescribedortoincludeanysuchfeatureorfunctionalityinafuturerelease.

Page 3: Welcome to Tomorrow ... Today

CityofLosAngeles

2nd largestcityinU.SPopulation:4MillionAnnualvisitors:43Million43departments,35,000FTECriticalInfrastructureSectors

3

Page 4: Welcome to Tomorrow ... Today

Mayor’sExecutiveDirectiveonCybersecurity

“I’mcreatingthisCyberIntrusionCommandCenter(CICC)sothatwehavea single,focusedteamresponsibleforimplementingenhancedsecurity standardsacrosscitydepartmentsandservingasarapidreaction forcetocyber-attacks,”MayorEricGarcetti

4

Page 5: Welcome to Tomorrow ... Today

Challenges

“Siloed”SOCs/NOCsDispersedandmassivelogcapturingLackofcentralizedIncidentManagementcapabilitiesNothreatintelligenceanalysisandsharingplatformLimitedSituationAwareness(SA)andsecuritymetricscity-wide

5

Page 6: Welcome to Tomorrow ... Today

Solution

6

IntegratedSOCCriticalAssetProtection(CAP)

Page 7: Welcome to Tomorrow ... Today

7

Page 8: Welcome to Tomorrow ... Today

CriticalAsset

8

A“CriticalAsset”isdefinedasanysystem,whetherphysicalorvirtual,sovitaltotheCityofLosAngelesanditscitizens,thattheincapacityordestructionofsuchsystems,ortheunauthorizedaccessand/ordisseminationoftheinformationcontainedtherein,wouldhaveadebilitatingimpactontheCity'ssecurity,economicsecurity,publichealthorsafety,oranycombinationofthosematters.

Page 9: Welcome to Tomorrow ... Today

9

IDENTIFY

• Critical Asset Inventory• Data sources & security controls• Security goals & use cases

DETECT

• Data collection / Logging• SIEM/ISOC integration• Alert correlation, notification and dashboards

PROTECT

• KPI monitoring . Policy, Standard and Guidelines• Threat Intelligence service . Awareness and Training• Vulnerability assessment . Penetration testing and Tabletop exercise• Data Security / Compliance

RESPOND • Incident Response Plan and Notification Procedure (Department, City-wide)

RECOVER• Critical System Recovery Plan (Service Continuity Plan)Cr

iticalA

ssetProtection

Page 10: Welcome to Tomorrow ... Today

EnterpriseSecurity

10

ESandabifurcatedISOCdashboard

Page 11: Welcome to Tomorrow ... Today

ITServiceIntelligence

11

We’vedeployed5ofthe43departmentswithinCityofLAWe’remodeled38ServicesWe’vecreated30individualglasstablesWe’remonitoring160KPI’sWe’veenabledMLforanomalydetection/adaptivethresholdsWe’reusingMulti-KPIAlertingforadvancednotifications

CurrentDeployment

Page 12: Welcome to Tomorrow ... Today

ITServiceIntelligence

12

RoleBasedAccessControl

Page 13: Welcome to Tomorrow ... Today

ITServiceIntelligence

13

Usingmultiglasstables

Page 14: Welcome to Tomorrow ... Today

ITServiceIntelligence

14

LeveragingcoredashboardsfromITSI

Page 15: Welcome to Tomorrow ... Today

ITServiceIntelligence

15

DeepDivesandOSHostDetails

Page 16: Welcome to Tomorrow ... Today

Tomorrow…Today

16

ITSImulti-KPIAlertsandNotableEvents

Page 17: Welcome to Tomorrow ... Today

ITSI&Security

17

Startingtotieitalltogether

Page 18: Welcome to Tomorrow ... Today

LessonsLearned

StartgettingeventsintoSplunkASAPEngageBusinessServiceSME’searly– DBServers– WebServers– AppServers

LeverageKPIBaseSearches– muchmoreefficientLeverageThresholdtemplates– Savestime,buildsstandards

18

Page 19: Welcome to Tomorrow ... Today

WhatNow?

19

Relatedbreakoutsessionsandactivities…

Page 20: Welcome to Tomorrow ... Today

THANKYOU


Top Related