《勒索软件如何教会大英图书馆遵循众所周知的最佳实践.pdf》由会员分享,可在线阅读,更多相关《勒索软件如何教会大英图书馆遵循众所周知的最佳实践.pdf(46页珍藏版)》请在三个皮匠报告上搜索。
1、Kidnapping a LibraryHow Ransomware Taught the British Library to Follow Well-Known Best Practices Brian Myers PhD,CISSP,CCSKExperience20 years in software development9 years in information securityPast PositionsDirector of InfoSec,WebMD Health ServicesSenior AppSec Architect,WorkBoardSenior Risk Adv
2、isor,Leviathan SecurityCurrent WorkIndependent Information Security ConsultantCo-organizer,OWASP AppSec Days PNWSafetyLight LLCGoalsUnderstand what happens in a ransomware attackImprove our own disaster recovery planningAgendaThe British LibraryThe AttackThe ConsequencesLessons LearnedAgendaThe Brit
3、ish LibraryThe British LibraryThe AttackThe ConsequencesLessons LearnedThe British LibraryManuscripts and BooksHistoryregularly acquiring disparate collections1972British Museum books 1970sNewspaper LibraryPatent Office Library1982India Office Library1983National Sound Archive2004UK Web ArchiveEndan
4、gered Archives2000sDigitization partnerships2013Non-print Legal Deposit LibraryMany objectsManuscriptsBooksMapsImagesThesesJournalsNewspapersStampsPatent RecordsSound ArchivesArchived UK WebsitesWax Seals from the Magna CartaTibetan Prayer WheelsChinese Oracle BonesAnglo-Saxon SwordHebrew Astrolabe,
5、14th c.Ancient Roman Wax TabletsHow Big is the British Library?Printed items170 millionBookshelves466 miles+6 per yearWeb pages1.56 petabytesStaff1700 peoplelibrarians,researchers,IT,administrative staffAnnual Budget142 million$200m2023 What Information Systems Does the Library Have?POS systems on s
6、ite Cafe,gift shopCollectionsDigital archivesOnline catalog(s)Public-facing websiteOnline learning materialsReader registrationDigital archive accessInternal networkFirewalls,terminal serversOffice systems:HR,Payroll,Email,file sharesWhats the Librarys Infosec Program Like?Firewalls(Sophos XG)MFAInc