IT Security Human Resources

10
ICT Security Human Resources Budi Rahardjo Institut Teknologi Bandung [email protected]

description

T

Transcript of IT Security Human Resources

Page 1: IT Security Human Resources

ICT Security Human ResourcesBudi Rahardjo

Institut Teknologi [email protected]

Page 2: IT Security Human Resources

Current Situation

• The need for IT Security Professionals• But, not enough human resources available

locally

Need initiatives, strategies, to solve this challenge

Page 3: IT Security Human Resources

Stakeholders / Positions To Be Filled• Industry

– Banking, Telecommunication, e-Commerce, companies in general

• Government– Policy makers

• Academics– Researchers, inventors,

Lecturers, Teachers

• Military– Cybertroops

To Do:Must map current and projected need

Page 4: IT Security Human Resources

Level of Competence (Dreyfus & Dreyfus)

1. NoviceRule-based behaviour, strongly limited and inflexible

2. Experienced BeginnerIncorporates aspects of the situation

3. PractitionerActing consciously from long-term goals and plans

4. Knowledgeable practitionerSees the situation as a whole and acts from personal conviction

5. ExpertHas intuitive understanding of situation and zooms in on central aspects

Page 5: IT Security Human Resources

America’s National Initiative for Cybersecurity Education (NICE) Strategic Plan,August 11, 2011

Page 6: IT Security Human Resources

Certification vs. Formal Educationsimilar to software engineering

Certification• Too many certifications• Widely diverse• Not standard (yet)• Expensive

Formal Education• Has just started• Still a new field• Not available in most places• Not recognized (yet) by the

industry

Page 7: IT Security Human Resources
Page 8: IT Security Human Resources

Suggested Initiatives

• More security courses at universities• Security training at different level (from

awareness to advanced skill)• Security forum / sharing / conferences• Incentives for certification• Inexpensive certification• Regulation to make sure security is considered

Page 9: IT Security Human Resources

Info Security Grad Programme at ITB

• Two paths– InfoSec Engineering– InfoSec Governance

• Facilities (Cybersecurity Center)– Malware lab (virus, botnet, honeypot)– Forensic lab

• Opening Agustus 2013

Page 10: IT Security Human Resources

Concluding Remarks

• We have become too dependent on IT• Security is a major concern• IT security is still a new field• Professionals are in demand• Must fill the gap quickly