OIC-CERT 2020 ANNUAL REPORT Organization of the Islamic Cooperation Computer Emergency Response Team
Total Page:16
File Type:pdf, Size:1020Kb
OIC-CERT 2020 ANNUAL REPORT Organization of the Islamic Cooperation Computer Emergency Response Team OIC-CERT 2020 ANNUAL REPORT 3 ABOUT THE OIC-CERT OBJECTIVES he Organization of the Islamic Strengthening the relationship of CERTs Cooperation – Computer among the OIC Member countries, OIC- T Emergency Response Team (OIC- CERT partners, and other stakeholders in CERT) was established through the the OIC community Organization of the Islamic Cooperation Encouraging the sharing of cybersecurity (OIC) Resolution No 3/35-INF experience and information. Collaboration of Computer Emergency Response Team (CERT) Among the OIC Preventing and reducing cyber-crimes by Member Countries. It was passed during harmonizing cybersecurity policies, laws, the 35th Session of the Council of Foreign and regulations Ministers of the OIC in Kampala Uganda on Building cybersecurity capabilities and 18-20 June 2008. awareness amongst the OIC-CERT member countries In 2009 through the Resolution No 2/36- INF Granting the Organization of the Promoting collaborative research, Islamic Cooperation – Computer development, and innovation in Emergency Response Team an Affiliated cybersecurity Institution Status, the OIC-CERT became Promoting international cooperation with an affiliate institution of the OIC during the international cybersecurity organizations. 36th Session of the Council of Foreign Ministers of the OIC Meeting in Damascus, Assisting the OIC-CERT member countries Syrian Arab Republic on 23-25 May 2009. in establishing and developing their national CERTs VISION Envisioning the OIC-CERT to be a leading cybersecurity platform to make the global cyber space safe. MISSION A platform to develop cybersecurity capabilities to mitigate cyber threats by leveraging on global collaboration OIC-CERT 2020 ANNUAL REPORT 4 MEMBERSHIPS BOARD MEMBERS 2020 Egypt Egypt Computer Emergency Response Team Oman (Chair) (EG-CERT) Oman National Computer Emergency Indonesia Response Team (OCERT) National Cyber and Crypto Agency (Badan Malaysia (Permanent Secretariat) Siber dan Sandi Negara - BSSN) CyberSecurity Malaysia Iran • Iran Computer Emergency Response Team Azerbaijan (IRCERT) Azerbaijan Government CERT • Isfahan University of Technology Computer (CERT.GOV.AZ) Emergency Response Team (IUTcert) Egypt • Amirkabir University of Technology Egypt Computer Emergency Response Team Computer Emergency Response Team (EG-CERT) (AUTcert) • Sharif University of Technology Computer Indonesia Emergency Response Team (SharifCert) National Cyber and Crypto Agency (Badan • Shiraz University ICT Center (SUcert) Siber dan Sandi Negara - BSSN) • Maher Center Iran • APA Ferdowsi University of Mashhad Iran Computer Emergency Response Team CERT (APA-FUMcert) • (IRCERT) APA University Bojnord CERT (APA- UBCERT) United Arab Emirates UAE Computer Emergency Response Team Jordan (aeCERT) Jordan Computer Emergency Response Team (JO-CERT) FULL & GENERAL MEMBERS Kazakhstan • Kazakhstan Computer Emergency Azerbaijan Response Team (KZ-CERT) • Center for Analysis and Investigation of Azerbaijan Government CERT Cyber-Attacks (CA ICA) (CERT.GOV.AZ) Bangladesh Kuwait Kuwait National Cyber Security Centre • Bangladesh e-Government Computer (NCSC-KW) Incident Response Team (BGD e-GOV CIRT) Kyrgyzstan • BangladeshCERT Computer Emergency Response Team of • Bangladesh Computer Emergency Kyrgyz Republic (CERT-KG) Response Team (bdCERT) Libya Brunei Darussalam Libyan Computer Emergency Response Team Brunei Computer Emergency Response Team (Libya-CERT) (BruCERT) Malaysia Cote D’Ivoire • CyberSecurity Malaysia Cote D’Ivoire Computer Emergency Response • Universiti Teknikal Malaysia Melaka Team (CI-CERT) (UTeM) OIC-CERT 2020 ANNUAL REPORT 5 Morocco AFFILIATE MEMBER Moroccan Computer Emergency Response Team (maCERT) Team Cymru, USA Nigeria COMMERCIAL MEMBERS Consultancy Support Service Limited (CS2) Oman CERT-GIB, Singapore Oman National Computer Emergency Duzon, South Korea Response Team (OCERT) Huawei, UAE Pakistan • Pakistan Information Security Association Insight Security Operation Centre, Oman (PISA-CERT Serba Dinamik Group Berhad, Malaysia • National Response Centre for Cyber Crimes (NR3C) Turkcell Cyber Defence Centre, Turkey Qatar PROFESSIONAL MEMBERS Qatar Computer Emergency Response Team (Q-CERT) Abdul Fattah Mohamed Yatim - Teknimuda (M) Sdn Bhd, Malaysia Saudi Arabia Saudi Arabia Computer Emergency Response Dr. Abdulrahman Ahmad Abdul Muthana - Team (CERT-SA) Smart Security Solutions, Yemen Somalia Hatim Mohammad Tahir – Islamic Institute of Somalia Computer Emergency Response Higher Education Perlis Team (SomCERT) Prof. Dr. Rabiah Ahmad - Universiti Teknikal Sudan Malaysia Melaka, Malaysia Sudan Computer Emergency Response Team Dr. Sofia Najwa Ramli - Universiti Tun Hussein (SudanCERT) Onn (UTHM), Malaysia Syria National Agency for Network Services FELLOW MEMBERS Tunisia Assoc. Prof. Colonel (R) Dato’ Ts. Dr. Husin National Agency for Computer Security Jazri, Serba Dinamik Group Berhad (tunCERT) Prof. Nabil Sahli, National Agency for Computer Turkey Security National Cyber Security Incident Response Team (TR-CERT) HONORARY MEMBER Uganda The Organization of the Islamic Cooperation Uganda Computer Emergency Response (OIC) Team (UG-CERT) United Arab Emirates UAE Computer Emergency Response Team (aeCERT) Uzbekistan Uzbekistan Computer Emergency Response Team (UzCERT) OIC-CERT 2020 ANNUAL REPORT 6 ACRONYMS A I APCERT Asia Pacific Computer Emergency ICTA Information and Communication Response Team Technologies Authority AUCSEG AU – African Union Cybersecurity IEEE Institute of Electrical and Expert Group Electronics Engineers ISPAB Internet Service Provider B Association of Bangladesh IT Information Technology BSSN National Cyber Crypto Agency ITU International Telecommunication Union C ITU-ARCC ITU Arab Regional Cybersecurity Centre CAMP Cybersecurity Alliance for Mutual Progress J CERT Computer Emergency Response Team JSC “STS” JSC ‘State Technical Services’ CII Critical Information Infrastructure CNCERT China Computer Emergency K Response Team CPrN Computer Professionals KSA Kingdom of Saudi Arabia Registration Council of Nigeria CSB Cyber Security Brunei L D LSN Lembaga Sandi Negara / National Crypto Agency DSA Defence Space Administration LEA Law Enforcement Agency F M FIRST Forum of Incident Response & MCPD Mandatory Continuing Security Team Professionals Development FUT Federal University of Technology MDR Managed Detection and Response G MDPI Multidisciplinary Digital Publishing Institute GBBL Galaxy Backbone Limited MISP Malware Information Sharing GCSCC Global Cyber Security Capacity Platform Centre MoU Memorandum of Understanding GFCE Global Forum on Cyber Expertise MoCT Ministry of Communications and GlobalACE Global Accredited Cybersecurity Technology Education MSSP Managed Security Service Provider H N HD Humanitarian Dialogue N-CERT National CERT NACS National Agency for Computer Security NAICOM National Insurance Commission OIC-CERT 2020 ANNUAL REPORT 7 NATO North Atlantic Treaty Organization NCA National Communication Authority (Somalia) NCS Nigeria Computer Society NCSC National Cyber Security Centre NITDA National Information Technology Development Agency O OIC-CERT Organization of the Islamic Cooperation – Computer Emergency Response Team OSCE Organization for Security and Co- operation in Europe P PSIRT Product Security Incident Response Team S SaaS Software as a Service SOC Security Operation Centre SUE State Unitary Enterprise OIC-CERT 2020 ANNUAL REPORT 8 OIC-CERT 2020 - In the nutshell by CyberSecurity Malaysia The Permanent Secretariat of the OIC-CERT IC-CERT Annual Report 2020 consists of members activities O done in that year. For this report, 68% of the Full Members participated to share their activities which is the highest so far. Thank you to those who have submitted their reports. strategic pillars to support OIC-CERT 2020 was a challenging year to the OIC- business plan which are: CERT because of the Covid-19 pandemic that pose various challenges for Computer • Organisation Structure lead by Oman Emergency Response Teams (CERTs) and the Secretariat around the world. A lot of security incidents • International Cooperation and happened because cyber criminals use the Promotion lead by Oman pandemic issues to create scams and • Standards and Regulations lead by Iran frauds, taking advantage of the public and Egypt scare towards COVID19 and also due to • Technical and Technology lead by Iran the increase of online presence because and Azerbaijan activities that were usually conducted face- • Capacity Building lead by Malaysia and to-face were held online instead – the Indonesia annual conference, general meeting, • Awareness lead by UAE hands on trainings, and Board face-to-face meetings. The OIC-CERT 12th Annual Conference 2020 is the pinnacle event of the year. In The OIC-CERT now has 53 teams and 2020, the event was held for the first time members from 27 OIC member countries, online since the inception of the OIC-CERT which is 47% of the OIC member countries. in 2009. More than 200 participants An encouraging number compared to the attended the conference worldwide through modest 7 founding members in 2006. In live broadcast. This is a considerable 2020, three new commercial members achievement considering it is the first and joined the collaboration - INSIGHT from having to deal with different logistic and Oman, TurkCELL from Turkey, and Huawei technical challenges. The Secretariat was from UAE. It is a major challenge to get all taken to task in organising this