Challenges of Security Assurance Standardization in ICT

Authors

  • Marcus Wong Huawei Technologies (USA), Bridgewater, New Jersey, USA

DOI:

https://doi.org/10.13052/jicts2245-800X.226

Keywords:

Security Assurance, 3GPP, standards

Abstract

The explosion of mobile broadband growth has created a greater demand on the operators and vendors working together to place more and more telecom gears into wireless networks at a record pace to satisfy the users' insatiable appetite for mobile data. The desire for undiminished security coupled with more sophisticated attacks in an ICT world where the traditionally closed telecom networks are going through a change of open architecture, open platform, and virtualization, the entire telecommunication community has taken a proactive approach to re-evaluate the security assurance process to ensure that the products are as secure as ever. The operators and the vendors have come together under the roof of 3GPP to create such a security assurance standards to be applied, recognized, and accepted in all areas for which 3GPP network products are sold and marketed. This paper will examine the many issues, hurdles, and challenges of the standardization of security assurance.

Downloads

Download data is not yet available.

Author Biography

Marcus Wong, Huawei Technologies (USA), Bridgewater, New Jersey, USA

Marcus Wong Wireless Security Research and Standardization, Huawei Technologies (USA).

Marcus received his Master of Arts Degree in Computer Science from Queens College of City University of New York (USA). He has over 20 years of experience in the wireless network security field with AT&T Bell Laboratories, AT&T Laboratories, Lucent Technologies, and Samsung's Advanced Institute of Technology. He holds Certification of Information System Security Professional (CISSP) from the prestigious International Information Systems Security Certification Consortium (ISC2).

Marcus has concentrated his research and work in many aspects of security in wireless communication systems, including 2G/3G/4G mobile networks, Personal Area Networks, and satellite communication systems. Marcus joined Huawei Technologies (USA) in 2007 and continued his focus on research and standardization in 3GPP, WiMAX Forum, IEEE, and IETF security areas. As an active contributor in the Wireless World Research Forum (WWRF), he has shared his security research on a variety of projects contributing toward whitepapers, book chapters, and speaking engagements.

In the past, Marcus has held elected official positions in both WWRF and 3GPP, serving as the vice-Chairman of WWRF Working Group 7 (Security and Trust working group) from 2007 to 2012 and as the vice-Chairman of 3GPP SA3 (Service & System Aspect, Security Group) from 2009 to 2011 respectively. He also served as guest editor in the IEEE Vehicular Technology magazine. He also has published a number of journal papers and whitepapers in leading publications, including that of the Journal of Cyber Security and Mobility. In addition, he has numerous patents granted and/or pending.

References

3GPP TR 33.805, Study on Security Assurance Methodology for 3GPP Network Products

3GPP TR 33.806, Pilot development of Security Assurance Specification (SCAS) for MME network product class

3GPP TR 33.916, Security Assurance Methodology for 3GPP network products

Canada's Privacy Act, http://www.priv.gc.ca/leg_c/leg_c_a_e.asp

Common Criteria for Information Technology Security Evaluation, Version 3.1 Release 4, September 2012

The CC and CEM documents: http://www.commoncriteriaportal.org/cc/

The CCRA introduction: http://www.commoncriteriaportal.org/ccra

CCRA Licensed Laboratories: http://www.commoncriteriaportal.org/ labs/

EU Directive 95/46/EC, The Data Protection Directive

CESG Commercial Product Assurance (CPA) Scheme: http://www.cesg. gov.uk/servicecatalogue/Product-Assurance/CPA/Pages/CPA.aspx

IETF Internet Draft: “Endpoint Security Posture Assessment – Enterprise Use Cases”

Cloud Computing Information Assurance Framework: http://www.enisa. europa.eu

ITU-T X.1254: Entity Authentication Assurance Framework

Downloads

Published

2014-12-11

How to Cite

Wong, M. . (2014). Challenges of Security Assurance Standardization in ICT. Journal of ICT Standardization, 2(2), 187–200. https://doi.org/10.13052/jicts2245-800X.226

Issue

Section

Articles