12. 犖犖迦牽犢犖犖犖朽権犖÷犖迦牽犖犖迦犢犖犖犖犖巌 23 犖犖巌犖犖迦犖 2551 Deadline!!! Must Have (Common) Entries 1. Log 犖犖犖 web proxy 犖犖伍犖犖園硯犖犖犖 5 犖犖犖巌県犖園 犖犢犖犖÷顕犖犖朽 SOC 2. Log 犖犖犖 web proxy 犖犖園犖犖ム犖迦硯犖÷元犖犢犖犖÷弦犖 credential 犖犖犖劇賢犖犖犖犢犖犢犖о犖迦犖犢犖ム鍵 session 犢犖犢犖犖犖犖 user 犖犖犢犖 3. Log 犖犖犖 email server 犖犖犖犖犖園犖 5 犖犖犖巌県犖園 犖犢犖犖÷顕犖犖朽 SOC 4. Log 犖犖犖 Corporate Internet web server 犖犖伍犖犖園硯 犖犢犖犖÷顕犖犖朽 SOC [OS <security+system event> +IIS] 5. Access log 犖犖犖 VPN 犢犖ム鍵 RADIUS 犖犖犖犖犖園犖 5 犖犖犖巌県犖園
13. 犖犖犖園犖犖犖伍犖÷顕犖犖犖犖迦牽犢犖ム鍵犖犖犖迦犖園犖∇犖犖犖÷犖犖犢犖犖犖劇賢犖犢犖迦権犖犖迦犖犖橿犖犢犖 User 犖犢犖犖 login 犖犢犖犖犢犖犢犖迦犖犢犖犖迦犖犖萎犖 User 犖犢犖犖 login 犖犢犖犖犖犖犖 Internet DHCP, NAT, Proxy and etc. 犖犖園犖犖橿検犖迦犖犖犖迦牽犖犢犖迦犖犖о顕犖÷犖ム賢犖犖犖園権犢犖犖犖迦牽犢犖犢犖犖犖園犖犖迦犢犖犖÷弦犖 Log Integrity Identification and Authentication Confidentiality with access control (authorization) 犖犖迦牽犢犖犖犖朽権犖÷犖迦牽犖犖迦犢犖犖犖犖巌
20. Time [Since 1967] Astronomical Definition Atomic Definition 1 Second (SI Unit) = ? Resolution No. 1of The 13th CGPM: The second is the duration of 9 192 631 770 periods of the radiation corresponding to the transition between the two hyperfine levels of the ground state of the caesium-133atom . http://www.bipm.org 1 犖о険犖 = 24x60x60 = 86400 犖о鹸犖犖迦犖 WRONG!! =86400+[Leap Seconds] Correct!! 犖犖朽犖÷顕犖犖犖 Atomic Clock 犖犖犖劇賢 Caesium Atomic Clock
21. 犢犖犖劇犖犖犖犖犖犢犖о献犖迦犖犖犖萎犖犖犖犖÷犖巌硯犢犖犖犖犢 犢犖犖犖犖迦牽犖犢犖迦犖犖巌 : http :// www . bipm . org / en / scientific / tai / tai . html 犖犖迦牽犖犖橿犖о犖犖迦犢犖 International Atomic Time (TAI) >250 Caesium Atomic Clock 犖犖迦犖犖犖迦犖園犖÷顕犖犖犖犖迦犢犖犢犖犖犖迦犖巌検犖迦犖犖о犖 50 犖犖犖萎犖犖犖犖園犖о犖ム 犖犢犖犖犢犖迦犖犖犢犖о検犖犖橿犖о TAI 犖犖朽 BIPM 犢犖 Paris NIMT yes NECTEC no Navy no (until 2007) NIST NIMT
22. Caesiums TAI UTC TAI = International Atomic Time UTC=TAI 賊 Leap Second (since 1972) UTC TAI = -33 sec. (since 1 Jan. 2006)
28. 犖犖迦牽犖犖巌犖迦牽犖犖迦犖園犖犖園犖犢犖ム鍵犖犖橿犖犖巌犖犖迦牽 Computer Crime Coordination Organization 犖犖犖萎犖犢犖犢犖犖犖迦牽犖犖巌犖迦牽犖犖 Speed Pre-defined Org + Adequate Competency Pre-defined Process Competency To close the gap between technical and legal issue To mind human right and employee right and discipline Impact 犢犖犢犖 / 犖犖迦犖 / 犖ム鹸犖犖犖巌犖犖巌 / 犢犖犖犖犖犖犖巌 / 犢犖∇顕犖о犖 / 犖犖巌犖犖巌検犖犖伍県犖∇犖 / 犖犖萎見犖о犖迦犖犖犖萎犖犖 Group/Company LG Image/Reputation PR Management Executives Employees HR
29. 犖犖犖萎犖∇犖犢犢犖犖犖迦牽犖犖園犖犖園犖犖犖犖萎犖犖犖÷犖迦牽犖 Clear Role & Responsibility 犖÷元犖犖迦牽犖÷賢犖犖犖÷顕犖∇犖迦牽犖萎見犖犢犖迦犖朽犖犖園犖犖巌犖犖犖犖犖朽犖犖園犢犖犖 Clear Direction & Methodology 犖÷元犢犖犖о犖迦犢犖ム鍵犖о鹸犖犖朽犖橿犖犖巌犖犖迦牽犖犖朽犖犖園犢犖犖 犢犖ム鍵犢犖犢犖犖犖巌絹犖犖迦犢犖犖朽権犖о犖園犖犖園犖 Group Structured Collaboration 犖÷元犢犖犖о犖迦犢犖犖犖迦牽犖犖犖萎肩犖迦犖犖迦犖犖朽犖犖園犢犖犖 Maintain Competency and Readiness to Respond 犖÷元犖犖迦牽犖犖犖巌見犖迦牽犖犖園犖犖迦牽犖犖犖犢犖犖о顕犖÷牽犖項犖犖朽犖犖橿犖犢犖犢犖犢 犖犖犖犖犢犖о 犢犖犖劇犖犖犖о顕犖÷犖犢犖犖÷犖犖犖迦牽犖犖橿犖犖巌犖犖迦牽犖犖∇犖迦犖犖園犖犢犖о犖犖
30. Baseline of Competency PTT Group Computer Crime Handling Policy & Direction Related Legislations Type of Computer Crimes Law Enforcement Decision Matrix Evidence Chain of Custody Computer Crime Response Procedure
31. PTT Group Computer Crime Bureau of Advisory Legal Security Expert/CSO PR HR OICO+ICT PTT PTTEP PTTCH PTTAR TOP Committee 犖犖犖 . RMC
33. Accessing to Security Log Computer-Crime Coordinator Authorized Access ICT Security Log Manager ICT Security Log Analyst Security Log Subsidiary Company PTT Group Risk Management Committee SOC S ecurity O peration C enter CSIRT C omputer S ecurity I ncident R esponse T eam Required by Computer Crime Act 2007
34. Security Log Access Chain of Authority Company Assign Senior Officer by - Company order or - Job description Security Operators or MSSP Assign/ Transfer by - Memo/MOU or - Service Agreement (attachment) Request for authority Access Access MSSP= M anaged S ecurity S ervice P rovider Access Required for Analysis Security Monitoring Back up/Archiving Security Log
35. Security Log Access Chain of Authority Company X Assign IT Dept. Manager or Internal Audit and etc. by - Company order or - Job description by - Memo/MOU or - Service Agreement (attachment) Access Access Required for Analysis Security Monitoring Back up/Archiving MSSP Assign SOC Access Security Log