A. Information and Critical Infrastructure Protection in Greece
In Greece, there is a set of public services, independent authorities, organizations and bodies that include among their responsibilities issues related to the security and protection of information and critical infrastructures within the framework of Cyber Defense. These include (1):
Supervisory/Regulatory/Administrative Security Bodies:
(a). The Cyber Defense Directorate of the General Staff of National Defense (DIKYB/GHNDA) which has a command role at the national level. The GHNDA is responsible for issuing the National Security Regulation (ESR) (P.D. 17/1974), in collaboration with the National Intelligence Service (NIS). The ESR applies throughout the national territory and the public administration.
(b). EYP, which is an Information Security Authority (INFOSEC) (Law 39/2008), is responsible for the national Computer Emergency and Response Team (CERT) (P.D. 325/2003) and is the National Authority for Countering Electronic Attacks (P.D. 325/2003).
(c). The Directorate of Political Emergency Planning (PSEA) and the Information Technology Development Service (YAP) of the Ministry of Interior (YPES), which have certain responsibilities directly or indirectly related to the protection of critical national infrastructures. Indicatively, it is stated that the PSEA Directorate is responsible for the preparation, maintenance and review of service plans for the services of the General Secretariat for Public Administration and e-Government, while the YAP has been designated as the Certification Authority of the Greek State (APED), i.e. as the Primary Authority (PAP) (Law 3448/2006).
(d). The Hellenic Police (ELAS), as a subordinate to the Ministry of Internal Affairs, which is involved mainly through the Crisis Management Directorate, the Forensic Services Directorate, the Cybercrime Prosecution Service, the Digital Evidence Examination Sector, etc. The examination and analysis of digital evidence is carried out using special tools and procedures (computer forensics).
(e). The Ministry of Transport and Communications (MTC), which is responsible for formulating policy for the security of public networks and electronic communications services (Law 3431/2006), jointly with co-responsible Ministries.
(f). The Bank of Greece (BoG), which is involved in preventing the use of the financial system for the laundering of proceeds from criminal activities and the financing of specific violent crimes (Law 3601/2007, Supervisory Framework – Basel II, etc.).
(g). The Security Incident Response Team of the National Research and Technology Network (GRNET-CERT, GRNET-CERT), which is responsible for responding to security incidents in the Greek network (.gr), providing information, training and technical assistance and representing Greece in the relevant European and international councils.
Security Regulatory Bodies
(h). Independent authorities, such as the Personal Data Protection Authority (APPD), the Communications Privacy Assurance Authority (ADAE) and the National Telecommunications and Post Commission (EETT), which intervene in matters within their competence. Indicatively, the APPD is responsible for personal data protection issues and for the control of all involved bodies (Law 2472/1997, Law 2774/1999). ADAE is responsible for maintaining the confidentiality of free communication, for the certification of security products and for the control of all involved bodies (Law 3115/2003). Meanwhile, EETT is responsible, among other things, for the control of electronic signature service providers (P.D.150/2001), as well as for the integrity and availability of public communication networks - even in times of emergency.
Private Bodies - Information Websites
(i). Bodies and services, such as the Hellenic Agency for the Prevention of Electronic Fraud (EFTA), the Association of Information and Communications Enterprises of Greece (SEPE), the Greek safe internet hub SafeNetHomePlus, the SafeLine service and – in particular, due to the particular potential it can demonstrate – the Digital Awareness and Response to Threats (DART) Action Group, which operates within the framework of the “Digital Greece” Operational Program.
B. National CERT
By Law 3649/2008 article 4 paragraph 8, EYP is defined as the National Authority for Countering Electronic Attacks. The mission of the National Authority for Countering Electronic Attacks (EAAHE), as the meaning of CERT is translated, is to ensure the prevention and statistical and active response to electronic attacks against communications networks, information storage facilities and IT systems. In addition, the National CERT is responsible for the collection, processing of electronic data and the information of the competent bodies. Furthermore, by Law 3649/2008 article 6 paragraph 1, public services, legal entities under public law and public enterprises are obliged to provide specially authorized employees of EYP with any information, data or assistance for the fulfillment of its mission.
EYP, as the National CERT authority, has the necessary scientific personnel and the required equipment for handling, developing a strategy and dealing with attack threats. It is responsible for collecting, processing and distributing relevant information. In order to more effectively fulfill its mission, it cooperates with other National and non-National CERTs, with the corresponding services of other countries and International Organizations on relevant issues, as well as with foreign Intelligence Services. Examples of such cooperation are other national CERTs (ForthCERT, AuthCERT, etc.), ENISA (European Network and Information Security Agency), the Prosecution of Electronic Crime (ELAS), the Cyber Defense Directorate (DIKYB) of the Hellenic National Defense General Staff and Internet Providers.
The Hellenic Cybersecurity Agency, within the framework of its responsibilities as the competent body responsible for National-CERT, provides all services related to Information Systems (IS) of the broader public sector, and these are the following [4], [6]:
- It is the competent National Authority for addressing and protecting against electronic threats and attacks, mainly against the Public Sector and the country's Critical Infrastructures.
- It collects data on electronic attacks-threats from public and private bodies.
- Analyzes, records, evaluates and categorizes the type of attacks, threats and security incidents and handles them according to their type.
- Provides information and advice on the protection of Public and Private entity computer systems for security incidents and attacks-threats, upon request from interested parties.
- It makes announcements regarding imminent threats or ongoing electronic attacks and proposes preventive or repressive protection measures.
- It distributes information and suggestions regarding protection, results, impacts and conclusions from threats-attacks.
- It collaborates with other National and non-National CERTs, as well as Public Agency Services on relevant issues.
- Provides advice and assistance to the facilities of the organization that was attacked, for the restoration-limitation of the effects of the attacks upon request of the organization.
- It issues general instructions for securing public sector information systems.
- Coordinates response actions between those involved in attacks and security incidents.
- Conducts security audits on public sector information systems (penetration tests).
- It proposes protective measures required to eliminate the effects of security incidents.
EYP, through National-CERT, has also participated in the following exercises: [4]:
- PANOPTIS 2010 (18-20/5/2010): 1st National Cyber Defense Exercise of the Hellenic National Defense General Staff.
- SEESIM 10 (18-24/10/2010): South Eastern Europe Simulation 2010.
- Cyber Europe 2010 (3-5/11/2010): 1st Pan-European Cyber Exercise of ENISA.
- NCDEX 10 (16-18/11/2010): Cyber Coalition-NATO Cyber Defense Exercise 2010.
C. National Communications and Information Security Authority (INFOSEC)
With PD 360/92, EYP is responsible for the security of National Communications. It provides technical support on communications security issues, evaluates/certifies cryptographic systems and produces National keys. In 2003, with PD 325, EYP becomes the accredited Communications and Information Security Authority (INFOSEC) in the EU. It cooperates with the corresponding EU authorities and National users for the certification of hardware and software and the security accreditation of EU systems. With the National Security Regulation (GHND/2004) EYP is the National Communications and Information Security Authority (INFOSEC) and the National Electromagnetic Radiation Protection Authority (TEMPEST).
EYP is our National Representative in the international agreement CCRA (Common Criteria Recognition Arrangement) forthe mutual application and recognition of certificates for information technology security systems. These certificates are granted by accredited laboratories and Organizations, following assessments that they conduct in accordance with the criteria and methodology of the international standard ISO 15408 (Common Criteria). The assessment concerns all types of information technology security products or systems (such as operating systems, databases, firewalls, intrusion detection systems, smart cards, biometrics, etc.) and the classification is made at one of seven levels (EAL1 to EAL7), depending on the degree of security provided by the system under consideration. [6]. This certification includes the evaluation of the material by an accredited testing and calibration laboratory (according to ISO/IEC 17025) or by an approved Certification Body (Compliant Certification Body), equivalent to ISO/IEC [6, 10]. Finally, an important criterion for selecting secure information systems is the trustworthiness of the manufacturer, which includes the origin of the designer, the origin of the manufacturer, official certification and national approval.
D. Directorate of Cyber Defense, Hellenic National Defense General Staff (DIKYB)
The history of the Cyber Defense Department for the Cyber Defense case began essentially at the Ministry of Defense in 1999, as a department of the General Staff of the Navy.
This made Greece one of the first countries internationally with organized activity. In May 2003, the activity was activated as a department in the Hellenic Navy/National Defense General Staff where it was developed at an inter-branch level. In July 2004, it was decided to expand the department to a Directorate and place it under the Hellenic Navy General Staff. Since 2004, the Cyber Defense Directorate (DIKYB) of the National Defense General Staff has been established and is operating.
Since then, it was upgraded to the Cyber Defense Command in 2010, developing a complete operational action plan for the country's defense and security in Cyberspace. The Hellenic National Defense General Staff/Dikyb has regular cooperation with state agencies such as the Hellenic National Security Service and the Hellenic Police, thus contributing to addressing emerging threats in Cyberspace against National Security. As reported by the Ministry of National Defense, the details of the existing and implemented Cyber Defense and Cyber Attack operational planning are highly classified, but the level at which the ED operates is very high. What is also assured by the Ministry of National Defense is that the classified information of the ED operates outside of computers connected to the Internet, as a result of which there is no issue of leakage of classified national security information.
Continuous training, which is required to address Cyber threats, is achieved through the participation of the Hellenic National Defense Command/General Staff in NATO Cyber Defense exercises, as well as by organizing similar exercises at the national level.
In the PANOPTIS 2010 exercise, the Hellenic National Defense General Staff coordinated the action of the Public Sector and agencies (5 Ministries-Open Government Group-Office of the Prime Minister-HND-TEE) and the Academic Community (17 HEIs-TEIs), establishing a communication channel and enhancing the possibilities for cooperation between them. The exercise was free of charge, taking into account that the participants exercised from their headquarters.
The objective purposes of the exercise were the coordination and cooperation of the various agencies in addressing/neutralizing the threat of Cyberwar against our country, the training of personnel and the utilization of the know-how of the Academic Community.
In addition to the 1st National Cyber Defense Exercise PANOPTIS 2010, the Hellenic National Defense General Staff/Dikyb has participated in various NATO and European Union Cyber Defense exercises. In November 2009, our country participated in the 1st NATO Interstate Exercise called “Cyber Coalition” (NCDEx 09), in which, in addition to the Military, 4 ministries, the University of Athens and the Technical University of Athens participated.
Greece, together with Lithuania, were the only member states that took part in all 7 episodes, while its performance was particularly mentioned for 3 out of the 7 episodes.
E. Cyber Defense at the National University Level
At the university level, GRNET-CERT operates, which, within the framework of the National Research and Technology Network (GRNET), interconnects Greek Universities, Technical Educational Institutions and most Greek Research Centers, responding to security incidents in the Greek web space (.gr), providing the necessary technical assistance and information to resolve each situation. It connects more than 90 educational institutions (HEIs, TEIs) and research institutions, serving a total of approximately 500,000 users [8].
GRNET-CERT is located in the Network Operation Center (NOC) of the National Technical University of Athens (NTUA) and operates with its staff. The NOC provides technical management services to the GRNET-GRNET, as well as to the Panhellenic Network for Education (EDUnet). The GRNET is coordinated by the General Secretariat for Research and Technology (GSRT). The National Research and Technology Network (GRNET) was created with the aim of offering high-level network interconnection of Greek Academic and Research Institutions.
As can be seen, the three CERT authorities (National CERT, DIKYB and the university CERT) cooperating, constitute the country's defense in Cyberspace, that is, constituting a common team consisting of three pillars of cooperation, an intelligence service, a state authority and the most important CERT team (academic GRNET) in Greece. Each of the three pillars of cooperation is active in different sectors, as analyzed, nevertheless the cooperation of the triad and the overlap of sectors must be considered a given for a successful Cyber Defense at the national level.
F. Cyber defense in NATO and the European Union
Since 2006, NATO has been developing Cyber Defense systems in order to protect its networks and to contribute to addressing needs that arise in its member states.
In 2007, NATO responded to cyber attacks against Estonia. This event resulted in the establishment of the Cyber Defense Management Authority [9] (CDMA) in Brussels, for the timely and effective defense against such attacks on its critical facilities. At the same time, inMay 2008, in execution of this new NATO strategy, the Cooperative Cyber Defense Center of Excellence(CCDCoE) was established at a strategic level to further strengthen Cyber Defense. The CCDoE is NATO’s strategic planning for addressing Cyber Defense in the long term, within the framework of creating a comprehensive doctrine and strategy. In particular, the CCDCoE, which is the 10th of NATO's 19 Centers of Excellence, operates as a training and education center for addressing threats in Cyberspace.
It has a staff of 30 people, with the participation of experts from the participating countries, which are Estonia, Lithuania, Latvia, Germany, Hungary, Italy, Slovakia and Spain as regular members and the USA as an observer.
NATO also has the Consultation, Command and Control Agency (NC3A) in the Netherlands, which was established in 1996 and is the support service for design, system integration, technical support for NATO systems and facilities. In addition to strategic planning and the provision of training to Alliance members, the CCDoE deals with the creation of international rules and legislation for security in Cyberspace, in consultation with all international organizations (EU, UN, G8, etc.).
In the European Union (EU), a large number of CERTs have been created by universities, national agencies and large Information Technologies (IT) organizations. Most countries do not have a national central coordinating body. The existing teams cooperate on the pan-European Task Force-Collaboration Security Incident Teams (TF-CSIRT). The central control of the European CERTs is gradually being transferred to the European Network and Information Security Agency (ENISA) as the European Network and Information Security Agency.
ENISA was established in 2004 and is located in Heraklion, Crete. Its term of office is five years according to its statute. ENISA's purpose is to improve network and information security in the EU. It contributes to the development of the logic of computer networks and information security, for the benefit of citizens, consumers, depositors and national organizations in the EU.
It assists the EU, its Member States and the Organizations in meeting the criteria relating to their network connectivity and information security, contributing to the development and continuous updating of the existing and future legislative framework. In addition, ENISA mainly functions as a Centre of Expertise on network and information security issues, providing advisory services on issues such as cybercrime and risk assessment methodologies, and preparing relevant studies.12]
At the international military level, the US Pentagon has designated the US Cyber Command (USCYBERCOM) under the command of the National Security Agency (NSA), responsible exclusively for the protection of military forces. The Department of Homeland Security has been designated as the responsible authority for government centers and facilities. Corresponding to our national DIKYB/GHEETHA, it plans, coordinates, synchronizes all necessary actions for the defense of the electronic information network of the Department of Defense (Ministry of Defense). It is prepared whenever required to conduct military Cyberwar operations, ensuring the electronic availability (freedom) of information and communication systems and respectively hinders enemy systems.
G. Conclusions – Epilogue
It is almost absurd that while the Internet was originally created with the aim of being bullet-proof to enemy attacks, today it is extremely vulnerable.Securing a system that is constantly expanding and evolving, from all possible attacks, is something particularly difficult. The increasing rates of integration of new users and new technologies into the Internet, the explosion in data traffic via the Internet, the growing demand for information, are some of the points that demonstrate the rapid development of the Internet and the penetration of Cyberspace into all areas of our lives. The defensive aspect of this process, when the user tries to protect his own systems, is defined as Cyber Defense.
While the offensive aspect is not acknowledged by anyone, the defensive is a basic purpose of national services, state organizations, academic institutions and armed forces of every modern country.
Cyberwar constitutes a modern major asymmetric threat to the national security and prosperity of advanced states and therefore it is necessary to design and continuously renew a strategy (Cyber Security Strategy) in Cyberspace, which will ensure to the greatest extent possible the secure flow of information, its storage and the ability to deal with all forms of cyberattacks.
Internationally, there is currently no official definition of Cyberwar within the UN framework, since the threat it represents has not been included in the law of “armed” conflicts. Important processes are underway in NATO and the EU to upgrade the threat posed by Cyberwar – and especially for NATO, the inclusion of the threat in the mechanisms that activate collective defense, in accordance with Article 5 of the Alliance Charter, is being considered.
The right balance between international universal cooperation on Cybersecurity and cooperation on the distribution of electronic information with other Organizations or states is the key to success in developing Cybersecurity and safeguarding, on the other hand, national information. In our country, optimal coordination of public agencies, the institutionalization of the roles of the various agencies, the definition of criteria for the occurrence of Cyberwar and the in-depth training of users are critical factors in the development of Cyber Defense.
Source: synpeka.gr
