Challenges of Security Assurance Standardization in ICT
DOI:
https://doi.org/10.13052/jicts2245-800X.226Keywords:
Security Assurance, 3GPP, standardsAbstract
The explosion of mobile broadband growth has created a greater demand on the operators and vendors working together to place more and more telecom gears into wireless networks at a record pace to satisfy the users' insatiable appetite for mobile data. The desire for undiminished security coupled with more sophisticated attacks in an ICT world where the traditionally closed telecom networks are going through a change of open architecture, open platform, and virtualization, the entire telecommunication community has taken a proactive approach to re-evaluate the security assurance process to ensure that the products are as secure as ever. The operators and the vendors have come together under the roof of 3GPP to create such a security assurance standards to be applied, recognized, and accepted in all areas for which 3GPP network products are sold and marketed. This paper will examine the many issues, hurdles, and challenges of the standardization of security assurance.
Downloads
References
3GPP TR 33.805, Study on Security Assurance Methodology for 3GPP Network Products
3GPP TR 33.806, Pilot development of Security Assurance Specification (SCAS) for MME network product class
3GPP TR 33.916, Security Assurance Methodology for 3GPP network products
Canada's Privacy Act, http://www.priv.gc.ca/leg_c/leg_c_a_e.asp
Common Criteria for Information Technology Security Evaluation, Version 3.1 Release 4, September 2012
The CC and CEM documents: http://www.commoncriteriaportal.org/cc/
The CCRA introduction: http://www.commoncriteriaportal.org/ccra
CCRA Licensed Laboratories: http://www.commoncriteriaportal.org/ labs/
EU Directive 95/46/EC, The Data Protection Directive
CESG Commercial Product Assurance (CPA) Scheme: http://www.cesg. gov.uk/servicecatalogue/Product-Assurance/CPA/Pages/CPA.aspx
IETF Internet Draft: “Endpoint Security Posture Assessment – Enterprise Use Cases”
Cloud Computing Information Assurance Framework: http://www.enisa. europa.eu
ITU-T X.1254: Entity Authentication Assurance Framework