Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP...

32
Steps to a New Security Operations Center The New Memphis International Airport Air Command Center Story September 10, 2019

Transcript of Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP...

Page 1: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Steps to a New Security Operations CenterThe New Memphis International Airport

Air Command Center Story

September 10, 2019

Page 2: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Speakers

JARRETT MORGAN, CISSP, PMPDirector of Information Technology/CIO

Memphis International Airport

[email protected] (p)901.674.0237 (m)

SEAN AHRENS, CPP, CSC, BSCP, FSYLSecurity Market LeaderAffiliated Engineers, Inc.

[email protected] (p)312.339.5019 (m)

Page 3: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

About Jarrett• My Role

• Responsibilities

Page 4: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

About Memphis International Airport

• Background on airport• Flights

• Large Hub

https://www.flickr.com/photos/mjscanlonphotography/39829867084/in/photostream/

Page 5: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

• Why

• Technology

• Best PracticesBackground on Project

Page 6: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

• Why

• Technology

• Best PracticesBackground on Project

Page 7: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Approaching the Design of a

Operations Center

Page 8: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Use

• Stand alone

• Integrated

• Situational awareness• Active monitoring• Passive monitoring

• Crisis management

• Hours of operations

• Number of operators

• Systems/sources• Controlled• Partitioned• Law Enforcement Sensitive

Page 9: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 10: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Elements

• Space• Architecture

• Adjacencies• Isolation

• Raised floor• Ceiling• Columns - Not• Acoustics• Lighting• Ergonomics• Flooring• Furniture

• Desks• Chairs

Page 11: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 12: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 13: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 14: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

MEP• HVAC

• Plumbing

• Electrical• UPS• Generator

• Sewer

• Telecommunications

Page 15: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 16: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Elements

• Situational Awareness

• Radio

• Telephone

• Surveillance

• Intercom

• FIDS

• PIDS

• TSA

• Dispatch

Page 17: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 18: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Elements

• Other elements

• Future Situational Awareness

• HTTPS interfaces

• Public address

• White noise generators

• Accessibility

Page 19: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Affiliated Engineers, Inc.

Page 20: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Memphis’ Story

• Needs Analysis• Inventory

• Analysis

• Key Technology

• Peer Review

Page 21: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Needs Analysis

• Interviews• Operators

• Staff

• Executives• Needs

• Wants

• Wishes

Page 22: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Inventory

• Equipment• Audio/Visual

• Computers

• Storage

• Printers

• Surveillance

Page 23: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Analysis • Space

• Sources• Future sources

• Adjacencies

• Ergonomics

• Sick Building Syndrome Vs. Building-Related Illness

• Technology

• Interdependencies

• HVAC• Comfort

• Cyber Security

• USB connectivity – Power onlyThis Photo by Unknown Author is licensed under CC BY

Page 25: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Key Technology

• Monitoring approach• CAD

• KVM

• Video wall processors

• Video wall

Page 26: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

CAD

https://www.google.com/url?sa=i&source=images&cd=&ved=2ahUKEwj52az7xo_kAhUdHjQIHdjqAwYQjRx6BAgBEAQ&url=https%3A%2F%2Fwww.hexagonsafetyinfrastructure.com%2Fproducts%2Fcommand-control-and-communications%2Fintergraph-computer-aided-dispatch&psig=AOvVaw2DqITREj53JVD-iK3Y52EY&ust=1566325397629504

• Heart of Situational Awareness• GIS

• IPS• GPS• Automatic routing

• AVL

• Integrations• Multi-agency• Reporting• PIDS• Public Address• Access• Phone • Radio

Page 27: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

KVM• On Steroids

• Matrix multiple sources

• Secured/encrypted• Law Enforcement Sensitive

• Macro outputs• Operator driven approaches

• Remote PC’s• No USB drop vulnerabilities

• Controlled workstations

• Hot desks• No confirmed seating

https://www.thinklogical.com/wp-content/uploads/2019/02/MC-screenshot_3.jpg

Page 28: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Video Wall Processor• Elements

• Size location and number of inputs• Layout (canvas) flexibility; • Operator driven displays• Time driven displays

• Determining the number of inputs and outputs;

• How many rooms a single processor will access;

• Image size and resolution requirements ;

• Aspect ratio• Pixel density• Latency;• Refresh• How the system handles HDCP (from

broadcast sources or Apple computers, for example);

• Cable distance

Page 29: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Video Wall• Technology

• LCD

• DLP

• Rear-screen

• Projection

• Direct view LED

• Cubes

• Bezels

• This is where the money goes• Resolution

• Pixel density

• Latency

https://www.extron.com/article/videowallshapesize

Page 30: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Peer Review• What's existing

• Identifying gaps

Page 31: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Peer Review

• Electronics

• Telecommunications

• HVAC

• Plumbing

• Flooring

• Acoustics

• Lighting

Page 32: Steps to a New Security Operations Center · 2019-09-10 · Speakers JARRETT MORGAN, CISSP, PMP Director of Information Technology/CIO Memphis International Airport JMorgan@flymemphis.com

Questions

SEAN A. AHRENS, CPP, FSyl,

CSC

SECURITY MARKET GROUP LEADER

AEI | AFFILIATED ENGINEERS, INC. 10 S. La Salle Street, Suite 2700 | Chicago, IL 60603

P: 312.977.2857 | F: 312.977.2801M: [email protected] | www.aeieng.com