welcome to tomorrow ... today

20
Copyright © 2016 Splunk Inc. Tim Lee CISO, City of LA Ernie Welch Sales Engineer, Splunk Welcome to Tomorrow ... Today The need and benefit of merging of IT and Security in today's ever connected world of security and IT

Upload: lytram

Post on 14-Feb-2017

232 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Welcome to Tomorrow ... Today

Copyright©2016Splunk Inc.

TimLeeCISO,CityofLA

ErnieWelchSalesEngineer,Splunk

WelcometoTomorrow...TodayTheneedandbenefitofmergingofITandSecurityintoday'severconnectedworldofsecurityandIT

Page 2: Welcome to Tomorrow ... Today

Disclaimer

2

Duringthecourseofthispresentation,wemaymakeforwardlookingstatementsregardingfutureeventsortheexpectedperformanceofthecompany.Wecautionyouthatsuchstatementsreflectourcurrentexpectationsandestimatesbasedonfactorscurrentlyknowntousandthatactualeventsorresultscoulddiffermaterially.Forimportantfactorsthatmaycauseactualresultstodifferfromthose

containedinourforward-lookingstatements,pleasereviewourfilingswiththeSEC.Theforward-lookingstatementsmadeinthethispresentationarebeingmadeasofthetimeanddateofitslivepresentation.Ifreviewedafteritslivepresentation,thispresentationmaynotcontaincurrentoraccurateinformation.Wedonotassumeanyobligationtoupdateanyforwardlookingstatementswemaymake.Inaddition,anyinformationaboutourroadmapoutlinesourgeneralproductdirectionandissubjecttochangeatanytimewithoutnotice.Itisforinformationalpurposesonlyandshallnot,beincorporatedintoanycontractorothercommitment.Splunkundertakesnoobligationeithertodevelopthefeaturesor

functionalitydescribedortoincludeanysuchfeatureorfunctionalityinafuturerelease.

Page 3: Welcome to Tomorrow ... Today

CityofLosAngeles

2nd largestcityinU.SPopulation:4MillionAnnualvisitors:43Million43departments,35,000FTECriticalInfrastructureSectors

3

Page 4: Welcome to Tomorrow ... Today

Mayor’sExecutiveDirectiveonCybersecurity

“I’mcreatingthisCyberIntrusionCommandCenter(CICC)sothatwehavea single,focusedteamresponsibleforimplementingenhancedsecurity standardsacrosscitydepartmentsandservingasarapidreaction forcetocyber-attacks,”MayorEricGarcetti

4

Page 5: Welcome to Tomorrow ... Today

Challenges

“Siloed”SOCs/NOCsDispersedandmassivelogcapturingLackofcentralizedIncidentManagementcapabilitiesNothreatintelligenceanalysisandsharingplatformLimitedSituationAwareness(SA)andsecuritymetricscity-wide

5

Page 6: Welcome to Tomorrow ... Today

Solution

6

IntegratedSOCCriticalAssetProtection(CAP)

Page 7: Welcome to Tomorrow ... Today

7

Page 8: Welcome to Tomorrow ... Today

CriticalAsset

8

A“CriticalAsset”isdefinedasanysystem,whetherphysicalorvirtual,sovitaltotheCityofLosAngelesanditscitizens,thattheincapacityordestructionofsuchsystems,ortheunauthorizedaccessand/ordisseminationoftheinformationcontainedtherein,wouldhaveadebilitatingimpactontheCity'ssecurity,economicsecurity,publichealthorsafety,oranycombinationofthosematters.

Page 9: Welcome to Tomorrow ... Today

9

IDENTIFY

• Critical Asset Inventory• Data sources & security controls• Security goals & use cases

DETECT

• Data collection / Logging• SIEM/ISOC integration• Alert correlation, notification and dashboards

PROTECT

• KPI monitoring . Policy, Standard and Guidelines• Threat Intelligence service . Awareness and Training• Vulnerability assessment . Penetration testing and Tabletop exercise• Data Security / Compliance

RESPOND • Incident Response Plan and Notification Procedure (Department, City-wide)

RECOVER• Critical System Recovery Plan (Service Continuity Plan)Cr

iticalA

ssetProtection

Page 10: Welcome to Tomorrow ... Today

EnterpriseSecurity

10

ESandabifurcatedISOCdashboard

Page 11: Welcome to Tomorrow ... Today

ITServiceIntelligence

11

We’vedeployed5ofthe43departmentswithinCityofLAWe’remodeled38ServicesWe’vecreated30individualglasstablesWe’remonitoring160KPI’sWe’veenabledMLforanomalydetection/adaptivethresholdsWe’reusingMulti-KPIAlertingforadvancednotifications

CurrentDeployment

Page 12: Welcome to Tomorrow ... Today

ITServiceIntelligence

12

RoleBasedAccessControl

Page 13: Welcome to Tomorrow ... Today

ITServiceIntelligence

13

Usingmultiglasstables

Page 14: Welcome to Tomorrow ... Today

ITServiceIntelligence

14

LeveragingcoredashboardsfromITSI

Page 15: Welcome to Tomorrow ... Today

ITServiceIntelligence

15

DeepDivesandOSHostDetails

Page 16: Welcome to Tomorrow ... Today

Tomorrow…Today

16

ITSImulti-KPIAlertsandNotableEvents

Page 17: Welcome to Tomorrow ... Today

ITSI&Security

17

Startingtotieitalltogether

Page 18: Welcome to Tomorrow ... Today

LessonsLearned

StartgettingeventsintoSplunkASAPEngageBusinessServiceSME’searly– DBServers– WebServers– AppServers

LeverageKPIBaseSearches– muchmoreefficientLeverageThresholdtemplates– Savestime,buildsstandards

18

Page 19: Welcome to Tomorrow ... Today

WhatNow?

19

Relatedbreakoutsessionsandactivities…

Page 20: Welcome to Tomorrow ... Today

THANKYOU