Security and business continuity in ICT : a case study by Orange - PowerPoint PPT Presentation

About This Presentation
Title:

Security and business continuity in ICT : a case study by Orange

Description:

ITU Workshop on ICT Security Standardization for Developing Countries ... Management systems for records SCADA security Geneva, Switzerland, ... – PowerPoint PPT presentation

Number of Views:86
Avg rating:3.0/5.0
Slides: 14
Provided by: PRos156
Category:

less

Transcript and Presenter's Notes

Title: Security and business continuity in ICT : a case study by Orange


1
Security and business continuity in ICT a case
study by Orange
ITU Workshop on ICT Security Standardizationfor
Developing Countries (Geneva, Switzerland,
15-16 September 2014)
  • Francois Zamora,
  • Global security management system
  • Corporate Security Department, Orange Group
  • francois.zamora_at_orange.com

2
Purpose of this presentation
  • To exchange on how normative references are used
    for security and business continuity
  • To detect opportunities in the context of
    developing countries
  • Orange
  • Trends observed
  • Selected approach and methodology in Orange
    security function

3
Oranges footprint
4
Some trends observed
  • Regulatory
  • European Critical Infrastructures, started with
    energy, transports and interlinks ICT.
  • France reformulates Europes vision
  • Influences on developing countries
  • Standardization
  • Information security
  • BCM
  • Privacy
  • Cloud security (provider and consumer)
  • Management systems for records
  • SCADA security
  • ICT
  • mutates
  • concentrates
  • outsources
  • is exposed
  • enables new fields

5
A vision shared in France
courtesy HCFDC, Feb 2013 (Laurent Ducamin,
SGDSN)
6
Case study
  • All these sectors are interlinked with strong
    interdependencies leading to complex
    representations and challenging requirements
  • Orange selected an approach and methodologies to
    clarify and address ICT security and resilience
    in a context of strong technological mutations

7
Approach
  • Orange Global security standard
  • Global security management system
  • Use and map external references
  • Clarify requirements and maintain watch
  • Manage risks and comply
  • Continuously improve
  • Certify for business, re-use for compliance

8
Methodology
  • Identifying critical scopes of services,
    activities and processes Risk identification
    and management with ISO/IEC 27005
  • Continuous improvements with ISO/IEC 27001, and
    22301
  • Use and map other normative references
  • Maintain watch to assess effects
  • from and on Cloud-computing-based infras
  • from the virtualization trends of network
    equipments
  • from and upon key providers
  • from the conquest of new fields of services

9
Conclusions and Recommendations
  • Thanks to a risk approach effort is focused on
    critical functions and only relevant references
    are selected
  • Maintaining watch enables adequacy to local
    requirements and proportionality of effort with
    real-life threats

10
Thank you
  • backup slides follow

11
disctinctive features and strength
12
Oranges weight
13
Oranges networks overviewfor the enterprise
market
Write a Comment
User Comments (0)
About PowerShow.com