{"id":1647,"date":"2019-06-18T16:13:55","date_gmt":"2019-06-18T14:13:55","guid":{"rendered":"https:\/\/wpethzprd.ethz.ch\/its\/?p=1647"},"modified":"2019-06-18T16:13:57","modified_gmt":"2019-06-18T14:13:57","slug":"new-ciso-at-eth-zurich","status":"publish","type":"post","link":"https:\/\/blogs.ethz.ch\/its\/2019\/06\/18\/new-ciso-at-eth-zurich\/","title":{"rendered":"New CISO at ETH Zurich"},"content":{"rendered":"\n<p>Dr. Domenico Salvati is the new CISO at ETH Zurich.<\/p>\n\n\n\n<p>Domenico Salvati has been working as CISO (Chief Information Security Officer) at ETH Zurich since the beginning of April 2019. The role of the CISO has existed at ETH for some time now, and was hitherto carried out by the Head of IT Services, Dr. Rui Brandao. With the entry into force of the directive &#171;Information Security at ETH Zurich&#187; (around April 2018) it became clear that the tasks, rights and duties of the CISO as specified would exceed the time budget of the Head of IT Services<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">Domenico Salvati: Career Path<\/h2>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2019\/06\/Domenico_Salvati-838x1024.jpg\" alt=\"Domenico Salvati: new CISO at ETH Zurich\" class=\"wp-image-1648\" width=\"210\" height=\"256\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2019\/06\/Domenico_Salvati-838x1024.jpg 838w, https:\/\/blogs.ethz.ch\/its\/files\/2019\/06\/Domenico_Salvati-245x300.jpg 245w, https:\/\/blogs.ethz.ch\/its\/files\/2019\/06\/Domenico_Salvati-768x939.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2019\/06\/Domenico_Salvati-600x734.jpg 600w\" sizes=\"auto, (max-width: 210px) 100vw, 210px\" \/><figcaption><em>Domenico Salvati: new CISO at ETH Zurich<\/em><\/figcaption><\/figure>\n\n\n\n<p>For Domenico Salvati, Information Security has played a central role in his professional career. His interest in information security began towards the end of his studies in information systems at the University of Zurich, where he wrote his degree dissertation on &#171;Organisational Aspects of Information Security&#187;. The final year paper opened the way to his first employment with a large audit firm, where he gained initial experience in the Computer Risk Management Group. He gained further experience on the staff of the CIO at a medium-sized Swiss bank, and this led to him being hired by a major Swiss bank, where he held various roles in the field of information security. The bank later offered him the opportunity to work part-time with its support in order to write a dissertation entitled &#171;Management of Information System Risks&#187;.\u00a0 Domenico Salvati then went from the banking world to a job with a major Swiss health insurer, where he served as Corporate Risk Manager.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is information security and what does a CISO do?<\/h2>\n\n\n\n<p>Information security &#171;wants&#187; to\nensure that confidential information remains confidential, that information is\nnot unintentionally and erroneously altered (information and integrity), and\nthat information is available when needed. In many cases, the above-mentioned\nrequirements for the protection of information also stipulate verification\nand\/or traceability, which are particularly important when someone wants to\nmake a payment via e-banking, and prove retrospectively that the payment was\nactually triggered. The &#171;information&#187; part of the term\n&#171;information security&#187; should also indicate that this protection\nshould not be limited to the IT resources of ETH Zurich, but also applies, for\nexample, to information written on paper, and even to the spoken word.<\/p>\n\n\n\n<p>The ETH Zurich CISO now essentially implements the above-mentioned directive, &#171;Information Security at ETH Zurich&#187; and is the central point of contact for all units (central bodies, departments, and their institutes, as well as teaching and research institutions outside the departments) for all information security issues. It is also important in this context to adhere to the rules of conduct specified in the &#171;ETH Zurich Acceptable Use Policy for Information and Communications Technology (BOT)&#187;. In view of the size and complexity of ETH Zurich and the great variety of tasks involved in the role of CISO (see article 5 of the &#171;Information Security Directive&#187;), for each department and for the central bodies and staff, so-called Information Security Officers (ISO) are being appointed, who are on the front line, as the first points of contact.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Information Security Directive URL <\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/rechtssammlung.sp.ethz.ch\/Dokumente\/203.25.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">https:\/\/rechtssammlung.sp.ethz.ch\/Dokumente\/203.25.pdf<\/a> <\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Organizational affiliation<\/h2>\n\n\n\n<p>As its area of responsibility extends across the entire ETH, the CISO is part of the Secretary General under the helm of the ETH President. The organizational placement in the General Secretariat is intended to underpin the ETH-wide acceptance of the CISO by contacts outside the IT Servives.<\/p>\n\n\n\n<p>IT Services are an important contact, in\nparticular for the implementation of technical measures for information\nsecurity. The central role played by IT Services in information security issues\nis also reflected in the fact that the CISO does not belong to IT Services\norganizationally, but still works within IT Services<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What are the next projects?<\/h2>\n\n\n\n<p>For the next few months, Domenico Salvati\nwill be busy getting acquainted with ETH Zurich, and planning the next steps.\nSo far, many efforts have been made in the area of information security to\ncollect sensitive information (including databases) and determine their\nprotection requirements. The results obtained are now being intensified in\norder to achieve ETH-wide coverage.<\/p>\n\n\n\n<p>As a next step, the collection and\nreassessment of the current state of information security should prove interesting.\nDomenico Salvati has also been requested to provide the ISOs &#171;at the front\nline&#187; with the necessary tools and support to carry out their duties in\nthe field of information security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dr. Domenico Salvati is the new CISO at ETH Zurich.<\/p>\n","protected":false},"author":838,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[257891,25],"tags":[257943,261280],"class_list":["post-1647","post","type-post","status-publish","format-standard","hentry","category-it-sec","category-news","tag-chief-information-security-officer","tag-ciso-at-eth-zurich"],"_links":{"self":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/1647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/users\/838"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/comments?post=1647"}],"version-history":[{"count":0,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/1647\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/media?parent=1647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/categories?post=1647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/tags?post=1647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}