SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Next Generation Networks Security

Size: px
Start display at page:

Download "SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Next Generation Networks Security"

Transcription

1 International Telecommunication Union ITU-T Y.2740 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (01/2011) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Next Generation Networks Security Security requirements for mobile remote financial transactions in next generation networks Recommendation ITU-T Y.2740

2 ITU-T Y-SERIES RECOMMENDATIONS GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT- GENERATION NETWORKS GLOBAL INFORMATION INFRASTRUCTURE General Services, applications and middleware Network aspects Interfaces and protocols Numbering, addressing and naming Operation, administration and maintenance Security Performances INTERNET PROTOCOL ASPECTS General Services and applications Architecture, access, network capabilities and resource management Transport Interworking Quality of service and network performance Signalling Operation, administration and maintenance Charging IPTV over NGN NEXT GENERATION NETWORKS Frameworks and functional architecture models Quality of Service and performance Service aspects: Service capabilities and service architecture Service aspects: Interoperability of services and networks in NGN Numbering, naming and addressing Network management Network control architectures and protocols Smart ubiquitous networks Security Generalized mobility Carrier grade open environment Future networks Y.100 Y.199 Y.200 Y.299 Y.300 Y.399 Y.400 Y.499 Y.500 Y.599 Y.600 Y.699 Y.700 Y.799 Y.800 Y.899 Y.1000 Y.1099 Y.1100 Y.1199 Y.1200 Y.1299 Y.1300 Y.1399 Y.1400 Y.1499 Y.1500 Y.1599 Y.1600 Y.1699 Y.1700 Y.1799 Y.1800 Y.1899 Y.1900 Y.1999 Y.2000 Y.2099 Y.2100 Y.2199 Y.2200 Y.2249 Y.2250 Y.2299 Y.2300 Y.2399 Y.2400 Y.2499 Y.2500 Y.2599 Y.2600 Y.2699 Y.2700 Y.2799 Y.2800 Y.2899 Y.2900 Y.2999 Y.3000 Y.3099 For further details, please refer to the list of ITU-T Recommendations.

3 Recommendation ITU-T Y.2740 Security requirements for mobile remote financial transactions in next generation networks Summary Within the last few years, a great variety of remote payment networks using mobile networks have been established. While implementing different approaches, quite often they lack of security. At the same time communication networks, including mobile networks, yield substantial changes undergoing transition to the next generation networks (NGN). Recommendation ITU-T Y.2740 elaborates approaches to develop system security for mobile commerce and mobile banking in the next generation networks (NGN). It describes security requirements for the mobile commerce and the mobile banking systems, based on four specified security levels. It outlines probable risks in mobile commerce and mobile banking systems, and specifies means for risk reduction. History Edition Recommendation Approval Study Group 1.0 ITU-T Y Keywords Mobile banking, mobile commerce, mobile payments, remote payments, security. Rec. ITU-T Y.2740 (01/2011) i

4 FOREWORD The International Telecommunication Union (ITU) is the United Nations specialized agency in the field of telecommunications, information and communication technologies (ICTs). The ITU Telecommunication Standardization Sector (ITU-T) is a permanent organ of ITU. ITU-T is responsible for studying technical, operating and tariff questions and issuing Recommendations on them with a view to standardizing telecommunications on a worldwide basis. The World Telecommunication Standardization Assembly (WTSA), which meets every four years, establishes the topics for study by the ITU-T study groups which, in turn, produce Recommendations on these topics. The approval of ITU-T Recommendations is covered by the procedure laid down in WTSA Resolution 1. In some areas of information technology which fall within ITU-T's purview, the necessary standards are prepared on a collaborative basis with ISO and IEC. NOTE In this Recommendation, the expression "Administration" is used for conciseness to indicate both a telecommunication administration and a recognized operating agency. Compliance with this Recommendation is voluntary. However, the Recommendation may contain certain mandatory provisions (to ensure, e.g., interoperability or applicability) and compliance with the Recommendation is achieved when all of these mandatory provisions are met. The words "shall" or some other obligatory language such as "must" and the negative equivalents are used to express requirements. The use of such words does not suggest that compliance with the Recommendation is required of any party. INTELLECTUAL PROPERTY RIGHTS ITU draws attention to the possibility that the practice or implementation of this Recommendation may involve the use of a claimed Intellectual Property Right. ITU takes no position concerning the evidence, validity or applicability of claimed Intellectual Property Rights, whether asserted by ITU members or others outside of the Recommendation development process. As of the date of approval of this Recommendation, ITU had not received notice of intellectual property, protected by patents, which may be required to implement this Recommendation. However, implementers are cautioned that this may not represent the latest information and are therefore strongly urged to consult the TSB patent database at ITU 2011 All rights reserved. No part of this publication may be reproduced, by any means whatsoever, without the prior written permission of ITU. ii Rec. ITU-T Y.2740 (01/2011)

5 CONTENTS Page 1 Scope References Definitions Terms defined elsewhere Terms defined in this Recommendation Abbreviations and acronyms Conventions Security considerations for mobile banking and mobile commerce systems in the next generation network Basic risks in mobile remote financial transactions Security goals Security levels and means to support them... 3 Bibliography... 8 Rec. ITU-T Y.2740 (01/2011) iii

6

7 Recommendation ITU-T Y.2740 Security requirements for mobile remote financial transactions in next generation networks 1 Scope This Recommendation describes security risks associated with remote mobile financial transactions supported by the next generation network (NGN) application services and the risk mitigation and counter measures based on four security levels. This Recommendation also specifies the minimum requirements for protecting the privacy of an individual's personal data regarding remote mobile financial transactions. 2 References The following ITU-T Recommendations and other references contain provisions which, through reference in this text, constitute provisions of this Recommendation. At the time of publication, the editions indicated were valid. All Recommendations and other references are subject to revision; users of this Recommendation are therefore encouraged to investigate the possibility of applying the most recent edition of the Recommendations and other references listed below. A list of the currently valid ITU-T Recommendations is regularly published. The reference to a document within this Recommendation does not give it, as a stand-alone document, the status of a Recommendation. [ITU-T X.800] Recommendation ITU-T X.800 (1991), Security architecture for Open Systems Interconnection for CCITT applications. [ITU-T X.805] Recommendation ITU-T X.805 (2003), Security architecture for systems providing end-to-end communications. [ITU-T Y.2720] Recommendation ITU-T Y.2720 (2009), NGN identity management framework. [ITU-T Y.2741] Recommendation ITU-T Y.2741 (2011), Architecture of secure mobile financial transactions in next generation networks. 3 Definitions 3.1 Terms defined elsewhere This Recommendation uses the following terms defined elsewhere: access control [ITU-T X.800]: The prevention of unauthorized use of a resource, including the prevention of use of a resource in an unauthorized manner application [ITU-T Y.2741]: A special mobile banking or mobile commerce application uploaded to Client's (user's) mobile device authentication [ITU-T X.800]: See data origin authentication, and peer entity authentication. NOTE In this Recommendation, the term "authentication" is not used in connection with data integrity, the term "data integrity" is used instead availability [ITU-T X.800]: The property of being accessible and useable upon demand by an authorized entity client [ITU-T Y.2741]: Private individual or corporate entity that has signed a contractual agreement on the use of telecommunication services and the system of mobile commerce. Rec. ITU-T Y.2740 (01/2011) 1

8 3.1.6 confidentiality [ITU-T X.800]: The property that information is not made available or disclosed to unauthorized individuals, entities, or processes data integrity [ITU-T X.800]: The property that data has not been altered or destroyed in an unauthorized manner data origin authentication [ITU-T X.800]: The corroboration that the source of data received is as claimed mobile payment system [ITU-T Y.2741]: Mobile banking and/or mobile commerce System next generation network (NGN) [b-itu-t Y.2001]: A packet-based network able to provide telecommunication services and able to make use of multiple broadband, QoS-enabled transport technologies and in which service-related functions are independent from underlying transport-related technologies. It enables unfettered access for users to networks and to competing service providers and for services of their choice. It supports generalized mobility which will allow consistent and ubiquitous provision of services to users privacy [ITU-T X.800]: The right of individuals to control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed. NOTE Because this term relates to the right of individuals, it cannot be very precise and its use should be avoided except as a motivation for requiring security repudiation [ITU-T X.800]: Denial by one of the entities involved in a communication of having participated in all or part of the communication security dimension [ITU-T X.805]: A set of security measures designed to address a particular aspect of the network security security layer [ITU-T X.805]: A hierarchy of network equipment and facility groupings security planes [ITU-T X.805]: A certain type of network activity protected by security dimensions. 3.2 Terms defined in this Recommendation This Recommendation uses the following term: security level: Security specification of the system which defines effectiveness of risk protection. 4 Abbreviations and acronyms This Recommendation uses the following abbreviations and acronyms: GSM Global System for Mobile Communications MPS Mobile Payment System MSISDN Mobile Station International ISDN Number NGN Next Generation Network PA-DSS Payment Application Data Security Standard PCI DSS Payment Card Industry Data Security Standard 5 Conventions None. 2 Rec. ITU-T Y.2740 (01/2011)

9 6 Security considerations for mobile banking and mobile commerce systems in the next generation network Mobile payment system (MPS) security in the next generation network (NGN) is based on the MPS architecture and the MPS participants roles specified in [ITU-T Y.2741], Architecture of secure mobile financial transactions in next generation networks as well as on the MPS participants risk analysis, described below. 6.1 Basic risks in mobile remote financial transactions This clause does not consider factors that condition new global and industrial risks run by the participants when implementing the MPS system, strategic, country and sovereign, market, interest, liquidity, legal, reputation risks, etc. The clause touches upon the information risks that may arise directly at time of remote mobile payments and require deciding security issues to minimize the risks: The risk of confidentiality loss which implies unauthorized access to confidential information; The risk of data integrity violation which is the distortion of information when transferring or processing data; The risk of electronic documents forgery (the risk to authenticity) which is when electronic documents are generated by unauthorized participants; The risk of repudiation which involves the denial of authorship of an electronic document; The risk of information destruction, either intended or due to negligence; Transactional risk which involves failure to finish or complete a transaction (e.g., owing to bad transmission quality). 6.2 Security goals To improve the mobile payment security and minimize the risks of the participants, the solution must ensure the realization of the following goals: to reduce the possibility of interception of personal or financial information at time of a transaction; to reduce the possibility of retrieving personal or financial information from databases; to reduce the possibility of substitution or distortion of personal or financial information at time of a transaction; to reduce the possibility to use the solution by unauthorized persons and persons attempting a masquerade by implementation of a unique authentication; to reduce the possibility of using "stolen" information in the solution; to provide the grounds to make it impossible for a transaction initiator or participant to deny his actions after they have been performed; to ensure the compliance with legal rights and duties of all interoperation participants; to ensure the completion of transaction. 6.3 Security levels and means to support them This Recommendation describes four MPS security levels based on MPS participants risk analysis. The System security level is defined by the set of security dimensions implementations (see Table 1). Thus, the fourth (the highest) security level must have the strongest implementations of security dimensions. Nevertheless, requirements for some security dimensions are unified for all security levels. Rec. ITU-T Y.2740 (01/2011) 3

10 Parties using MPS should be aware of the System security level and the System's risks. The acceptable security level for a certain risk of any System component is determined by the party taking this risk. The parties can additionally mitigate the risks of using MPS by operational measures which may include limiting the frequency or monetary value of individual transactions, the availability of the service to users with high loyalty level, etc. The client is identified to the System by using an NGN network public identifier (e.g., MSISDN for GSM networks) Implementation of security dimensions for all security levels The System security is entrusted upon every System participant and is achieved by the physical and the administrative facilities of security assurance at data transfer, processing and storage. The System participants shall ensure the implementation of information security assurance industry standards (e.g., [b-pci DSS], and [b-pa-dss], etc.). Eight security dimensions [ITU-T X.805] that define the MPS security levels are listed below. It is mandatory that all System participants should implement the security dimensions in relation to the information being involved in the data exchange. 1) Access control: the access to each MPS component must be granted only as provided by the System personnel or end-user access level. The requirement is valid for all security levels. 2) Authentication: the authenticity of the claimed identity of the entities participating must be ensured. This is one of the key factors in mitigating the risk of denial of authorship. Due to wide organizational and technical implementation possibilities, each security level defines minimal authentication mechanism requirements. The three factors of client (user) authentication are: the client uses some information which no one else can be aware of, e.g., access password (Something You Know); the client possesses something which is available only for him and performs certain actions uniquely, e.g., generates an electronic signature or a message authentication code (Something You Have); the client uses his biometric data (Something You Are). 3) Non-repudiation: provides means for preventing an individual or an entity from denying having performed a particular action (e.g., sending, transferring or receiving messages). For this purpose, all System personnel and end-user actions shall undergo mandatory registration. Event logs must be change-proof and contain all actions of all users. Compliance with the requirements is achieved by legally stated or reserved in mutual contracts means and accepted authentication mechanisms. The requirement is valid for all security levels. 4) Data confidentiality: data used in the System are protected from unauthorized disclosure and alteration. Requirements to confidentiality are defined by the System data criticality. Each security level specifies certain means of ensuring confidentiality and imposes restrictions on the System data criticality level. 5) Communication security: the guaranteed delivery of the sequence of messages in both directions (to and from the addressee) includes the completion of a transaction (using the protocols that ensure the completion of a transaction), and the protection of the information from an unauthorized disclosure at time of transfer over the communication channels. This requirement is valid for all security levels. 4 Rec. ITU-T Y.2740 (01/2011)

11 6) Data integrity: the correctness, accuracy and integrity of data are ensured by means of protection against unauthorized modification, deletion, creation and replication, as well as the indication of these unauthorized activities. Logical completion of a transaction is guaranteed when certain conditions are satisfied, which is implemented on the application level. Each security level defines certain mechanisms of integrity assurance. Integrity assurance can be achieved by means of data confidentiality and access control. 7) Availability: ensures the preservation of authorized access to MPS data and services. The requirement is valid for all security levels and is to be met by the service provider in a best effort manner. 8) Privacy: ensures the security of the information involved in the data exchange and stored by the system participants. The minimum number of data necessary for the System to operate shall be used in the solution. The System participants shall mitigate against unauthorized data acquisition and transfer. The System shall assure compliance with the financial industry standards. The security dimensions that are equally implemented at all security levels are: access control; non-repudiation; communication security; availability. The following security dimensions have different implementation at different security levels: authentication; data confidentiality; data integrity; privacy Security level 1 MPS can rely on the authentication of the client provided by the NGN operator. Data confidentiality and integrity are ensured by the data transfer environment (communications security), and at their storage and processing by the mechanism of data storage as well as the System access control facilities. The privacy is ensured by the absence of sensitive data in the messages being transferred, as well as by the implementation of the required mechanisms of data storage and the system access control facilities. The System components must not have latent possibilities of unauthorized data acquisition and transfer Security level 2 Authentication when using the System services can be executed by using only one authentication factor and thus can be implemented without the application of cryptographic protocols. One-time-password is used for authentication. One-time-password is generated by means of various tokens (single factor one-time-password device, single factor cryptographic device, etc.). Data confidentiality, integrity and privacy are ensured similarly to level Security level 3 Multifactor client authentication must be used for the access to the System services. The System shall use more than one authentication factor to authenticate the client. Rec. ITU-T Y.2740 (01/2011) 5

12 Data confidentiality, integrity and privacy at message transfer must be ensured by using additional message encryption, together with data transfer protocols that ensure the security of the data being transferred by the interoperation participants (including data integrity verification). During data storage and processing, their confidentiality, integrity and privacy are ensured by additional mechanisms of encryption and masking together with well-defined distribution of access in concordance with privileges and permissions. To meet security requirements at this level, the System shall use special software applications, uploaded to clients' mobile devices. These applications shall implement two-factor authentication and ensure both encryption and decryption of the transferred data. Each authentication shall require entry of the password or other activation data to activate the authentication key and the unencrypted copy of the authentication key shall be erased after each authentication (multifactor software cryptographic token). All MPS interoperation participants shall use security facilities that ensure the system against break-in. In the level 3 solutions, the security of data transferred over the communications channels shall be ensured by means of strong cryptography. The strength of a cryptographic method depends on the cryptographic key being used. The effective key size shall meet the recommendations of the minimal key size choice which ensures its relative strength Security level 4 This is the highest System security level. To meet the security requirements at this level, the System shall use hardware security modules installed in clients' mobile devices. These hardware security modules shall implement two-factor authentication and ensure both encryption and decryption of the transferred data. Each authentication shall require entry of the password or other activation data to activate the authentication key and the unencrypted copy of the authentication key shall be erased after each authentication (multifactor hardware cryptographic token). Both symmetric and asymmetric cryptographic algorithms are applied to message encryption. Implementation of other security dimensions shall fully correspond to level 3. 6 Rec. ITU-T Y.2740 (01/2011)

13 Table 1 Correlation of security levels and security dimensions implementation Security dimension Access control Authentication Nonrepudiation Data confidentiality Data integrity Privacy Communication security Availability Security Level Level 1 Level 2 Level 3 Level 4 The access to every system component shall be granted to authorized system personnel only. The activation of special applications uploaded to mobile terminals should be permitted to the authorized clients only. The authentication in the System is ensured by the NGN data transfer environment. Single-factor authentication at the System services usage. Multifactor authentication at the System services usage. In-person subscription to services where personal data with obligatory identification is used. Multifactor authentication at the System services usage. Obligatory usage of a hardware cryptographic module. The impossibility of a transaction initiator or participant denying his or her actions upon their completion is ensured by explicit and implicit legal contracts legally stated or reserved in mutual contracts means and accepted authentication mechanisms. All system personnel and end-user actions shall be logged. Event logs shall be change-proof and hold all actions of all users. During data transfer, data confidentiality is ensured by the data transfer environment (communications security), and by the mechanism of data storage together with the means of system access control at data storage and processing. Privacy is ensured by the absence of sensitive data in the messages being transferred, as well as by the implementation of the required mechanisms of data storage and the System access control facilities. The System components must not have latent possibilities of unauthorized data acquisition and transfer. During data transfer, data confidentiality is ensured by additional message encryption together with data transfer protocols that ensure the security of the data being transferred by the interoperation participants (including data integrity verification). During data storage and processing, their confidentiality, integrity and privacy are ensured by additional mechanisms of encryption and masking together with well-defined distribution of access in concordance with privileges and permissions. The implementation of the level 3 requirements with the obligatory usage of hardware cryptographic and data security facilities on the client's side (hardware cryptographic module). The delivery of a message to the addressee is ensured as well as the security against unauthorized disclosure at time of transfer over the communications channels. It is ensured by the NGN providers. It ensures that there is no denial of authorized access to the System data and services. Availability is assured by the NGN providers as well as by the MPS service providers. Rec. ITU-T Y.2740 (01/2011) 7

14 Bibliography [b-itu-t Y.2001] Recommendation ITU-T Y.2001 (2004), General overview of NGN. [b-pa-dss] Payment Card Industry (PCI), Payment Application Data Security Standard. Requirements and Security Assessment Procedures, Version 2.0, October [b-pci DSS] Payment Card Industry (PCI), Data Security Standard. Requirements and Security Assessment Procedures, Version 2.0, October Rec. ITU-T Y.2740 (01/2011)

15

16 SERIES OF ITU-T RECOMMENDATIONS Series A Series D Series E Series F Series G Series H Series I Series J Series K Series L Series M Series N Series O Series P Series Q Series R Series S Series T Series U Series V Series X Series Y Series Z Organization of the work of ITU-T General tariff principles Overall network operation, telephone service, service operation and human factors Non-telephone telecommunication services Transmission systems and media, digital systems and networks Audiovisual and multimedia systems Integrated services digital network Cable networks and transmission of television, sound programme and other multimedia signals Protection against interference Construction, installation and protection of cables and other elements of outside plant Telecommunication management, including TMN and network maintenance Maintenance: international sound programme and television transmission circuits Specifications of measuring equipment Terminals and subjective and objective assessment methods Switching and signalling Telegraph transmission Telegraph services terminal equipment Terminals for telematic services Telegraph switching Data communication over the telephone network Data networks, open system communications and security Global information infrastructure, Internet protocol aspects and next-generation networks Languages and general software aspects for telecommunication systems Printed in Switzerland Geneva, 2011

SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Next Generation Networks Security

SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Next Generation Networks Security International Telecommunication Union ITU-T Y.2723 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (11/2013) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS

More information

World Summit on Information Society (WSIS) Forum 2013. 16 May 2013

World Summit on Information Society (WSIS) Forum 2013. 16 May 2013 World Summit on Information Society (WSIS) Forum 2013 Toolkit for creating ICT-based services using mobile communications for e- government services 16 May 2013 Hani Eskandar ICT Applications coordinator

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION ITU-T Y.2902 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU Amendment 4 (11/2008) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION

More information

m Commerce Working Group

m Commerce Working Group m-powering Development Initiative Advisory Board second meeting Geneva, 23 rd of May 2014 m Commerce Working Group M-Commerce structure 2 Definitions Mobile Device m-commerce MFS m-marketing m-banking

More information

ITU-T. G.983.3 Amendment 2 (07/2005) A broadband optical access system with increased service capability by wavelength allocation Amendment 2

ITU-T. G.983.3 Amendment 2 (07/2005) A broadband optical access system with increased service capability by wavelength allocation Amendment 2 International Telecommunication Union ITU-T TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU G.983.3 Amendment 2 (07/2005) SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Digital

More information

ITU-T Y.2001. General overview of NGN

ITU-T Y.2001. General overview of NGN INTERNATIONAL TELECOMMUNICATION UNION ITU-T Y.2001 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (12/2004) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS

More information

ITU-T. G.994.1 Amendment 5 (04/2010)

ITU-T. G.994.1 Amendment 5 (04/2010) International Telecommunication Union ITU-T TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU G.994.1 Amendment 5 (04/2010) SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Digital

More information

ITU-T E.118. The international telecommunication charge card

ITU-T E.118. The international telecommunication charge card International Telecommunication Union ITU-T E.118 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (05/2006) SERIES E: OVERALL NETWORK OPERATION, TELEPHONE SERVICE, SERVICE OPERATION AND HUMAN FACTORS International

More information

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Secure applications and services Security protocols

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Secure applications and services Security protocols International Telecommunication Union ITU-T X.1154 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (04/2013) SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Secure applications and services

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION ITU-T X.680 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU Amendment 1 (06/99) SERIES X: DATA NETWORKS AND OPEN SYSTEM COMMUNICATIONS OSI networking and system aspects

More information

SERIES M: TELECOMMUNICATION MANAGEMENT, INCLUDING TMN AND NETWORK MAINTENANCE Integrated services digital networks

SERIES M: TELECOMMUNICATION MANAGEMENT, INCLUDING TMN AND NETWORK MAINTENANCE Integrated services digital networks International Telecommunication Union ITU-T M.3705 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (03/2013) SERIES M: TELECOMMUNICATION MANAGEMENT, INCLUDING TMN AND NETWORK MAINTENANCE Integrated services

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION ITU-T D.140 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (07/98) SERIES D: GENERAL TARIFF PRINCIPLES General tariff principles Charging and accounting in the international

More information

ITU-T E.123. Notation for national and international telephone numbers, e-mail addresses and Web addresses

ITU-T E.123. Notation for national and international telephone numbers, e-mail addresses and Web addresses INTERNATIONAL TELECOMMUNICATION UNION ITU-T E.123 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (02/2001) SERIES E: OVERALL NETWORK OPERATION, TELEPHONE SERVICE, SERVICE OPERATION AND HUMAN FACTORS International

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU J.141 (09/99) SERIES J: TRANSMISSION OF TELEVISION, SOUND PROGRAMME AND OTHER MULTIMEDIA SIGNALS Measurement of the

More information

By Authority Of THE UNITED STATES OF AMERICA Legally Binding Document

By Authority Of THE UNITED STATES OF AMERICA Legally Binding Document By Authority Of THE UNITED STATES OF AMERICA Legally Binding Document By the Authority Vested By Part 5 of the United States Code 552(a) and Part 1 of the Code of Regulations 51 the attached document has

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION CCITT E.113 THE INTERNATIONAL TELEGRAPH AND TELEPHONE CONSULTATIVE COMMITTEE (11/1988) SERIES E: OVERALL NETWORK OPERATION, TELEPHONE SERVICE, SERVICE OPERATION AND

More information

ITU-T Q.812. Amendment 3 (02/00) Protocol profile for electronic communications interactive agent Amendment 3:

ITU-T Q.812. Amendment 3 (02/00) Protocol profile for electronic communications interactive agent Amendment 3: INTERNATIONAL TELECOMMUNICATION UNION ITU-T Q.812 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU Amendment 3 (02/00) SERIES Q: SWITCHING AND SIGNALLING Specifications of signalling system no. 7 Q3 interface

More information

Draft ITU-T Recommendation X.805 (Formerly X.css), Security architecture for systems providing end-to-end communications

Draft ITU-T Recommendation X.805 (Formerly X.css), Security architecture for systems providing end-to-end communications Draft ITU-T Recommendation X.805 (Formerly X.css), architecture for systems providing end-to-end communications Summary This Recommendation defines the general security-related architectural elements that

More information

Advanced Topics in Distributed Systems. Dr. Ayman Abdel-Hamid Computer Science Department Virginia Tech

Advanced Topics in Distributed Systems. Dr. Ayman Abdel-Hamid Computer Science Department Virginia Tech Advanced Topics in Distributed Systems Dr. Ayman Abdel-Hamid Computer Science Department Virginia Tech Security Introduction Based on Ch1, Cryptography and Network Security 4 th Ed Security Dr. Ayman Abdel-Hamid,

More information

PRIVACY AND DATA SECURITY MODULE

PRIVACY AND DATA SECURITY MODULE "This project has been funded under the fourth AAL call, AAL-2011-4. This publication [communication] reflects the views only of the author, and the Commission cannot be held responsible for any use which

More information

ITU-T G.800. Amendment 2 (09/2010) Unified functional architecture of transport networks Amendment 2

ITU-T G.800. Amendment 2 (09/2010) Unified functional architecture of transport networks Amendment 2 International Telecommunication Union ITU-T G.800 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU Amendment 2 (09/2010) SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Digital networks

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO/IEC 29180 First edition 2012-12-01 Information technology Telecommunications and information exchange between systems Security framework for ubiquitous sensor networks Technologies

More information

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Telecommunication security. Framework of security technologies for home network

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Telecommunication security. Framework of security technologies for home network International Telecommunication Union ITU-T X.1111 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (02/2007) SERIES X: DATA NETWORKS, OPEN SSTEM COMMUNICATIONS AND SECURIT Telecommunication security Framework

More information

INTERNATIONAL TELECOMMUNICATION UNION DATA COMMUNICATION NETWORKS: OPEN SYSTEMS INTERCONNECTION (OSI); SECURITY, STRUCTURE AND APPLICATIONS

INTERNATIONAL TELECOMMUNICATION UNION DATA COMMUNICATION NETWORKS: OPEN SYSTEMS INTERCONNECTION (OSI); SECURITY, STRUCTURE AND APPLICATIONS INTERNATIONAL TELECOMMUNICATION UNION CCITT X.800 THE INTERNATIONAL TELEGRAPH AND TELEPHONE CONSULTATIVE COMMITTEE DATA COMMUNICATION NETWORKS: OPEN SYSTEMS INTERCONNECTION (OSI); SECURITY, STRUCTURE AND

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION ITU-T X.690 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (07/2002) SERIES X: DATA NETWORKS AND OPEN SYSTEM COMMUNICATIONS OSI networking and system aspects Abstract

More information

INTERNATIONAL TELECOMMUNICATION UNION SERIES L: CONSTRUCTION, INSTALLATION AND PROTECTION OF CABLES AND OTHER ELEMENTS OF OUTSIDE PLANT

INTERNATIONAL TELECOMMUNICATION UNION SERIES L: CONSTRUCTION, INSTALLATION AND PROTECTION OF CABLES AND OTHER ELEMENTS OF OUTSIDE PLANT INTERNATIONAL TELECOMMUNICATION UNION ITU-T L.52 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (05/2003) SERIES L: CONSTRUCTION, INSTALLATION AND PROTECTION OF CABLES AND OTHER ELEMENTS OF OUTSIDE PLANT

More information

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Cyberspace security Identity management

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Cyberspace security Identity management International Telecommunication Union ITU-T X.1252 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (04/2010) SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Cyberspace security Identity

More information

INTERNATIONAL TELECOMMUNICATION UNION $!4! #/--5.)#!4)/..%47/2+3 /0%. 3934%-3 ).4%2#/..%#4)/. /3) 3%#52)49 3425#452%!.$!00,)#!4)/.

INTERNATIONAL TELECOMMUNICATION UNION $!4! #/--5.)#!4)/..%47/2+3 /0%. 3934%-3 ).4%2#/..%#4)/. /3) 3%#52)49 3425#452%!.$!00,)#!4)/. INTERNATIONAL TELECOMMUNICATION UNION ##)44 8 THE INTERNATIONAL TELEGRAPH AND TELEPHONE CONSULTATIVE COMMITTEE $!4! #/--5.)#!4)/..%47/2+3 /0%. 3934%-3 ).4%2#/..%#4)/. /3) 3%#52)49 3425#452%!.$!00,)#!4)/.3

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION ITU-T G.825 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (03/2000) SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Digital networks Quality

More information

Cryptography and Network Security Overview & Chapter 1. Network Security. Chapter 0 Reader s s Guide. Standards Organizations.

Cryptography and Network Security Overview & Chapter 1. Network Security. Chapter 0 Reader s s Guide. Standards Organizations. Cryptography and Network Security Overview & Chapter 1 Fifth Edition by William Stallings Lecture slides by Lawrie Brown (with edits by RHB) Chapter 0 Reader s s Guide The art of war teaches us to rely

More information

Chap. 1: Introduction

Chap. 1: Introduction Chap. 1: Introduction Introduction Services, Mechanisms, and Attacks The OSI Security Architecture Cryptography 1 1 Introduction Computer Security the generic name for the collection of tools designed

More information

Part I. Universität Klagenfurt - IWAS Multimedia Kommunikation (VK) M. Euchner; Mai 2001. Siemens AG 2001, ICN M NT

Part I. Universität Klagenfurt - IWAS Multimedia Kommunikation (VK) M. Euchner; Mai 2001. Siemens AG 2001, ICN M NT Part I Contents Part I Introduction to Information Security Definition of Crypto Cryptographic Objectives Security Threats and Attacks The process Security Security Services Cryptography Cryptography (code

More information

SERIES T: TERMINALS FOR TELEMATIC SERVICES Still-image compression JPEG-1 extensions

SERIES T: TERMINALS FOR TELEMATIC SERVICES Still-image compression JPEG-1 extensions International Telecommunication Union ITU-T T.871 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (05/2011) SERIES T: TERMINALS FOR TELEMATIC SERVICES Still-image compression JPEG-1 extensions Information

More information

Cryptography and Network Security

Cryptography and Network Security Cryptography and Network Security Third Edition by William Stallings Lecture slides by Shinu Mathew John http://shinu.info/ Chapter 1 Introduction http://shinu.info/ 2 Background Information Security requirements

More information

Content Teaching Academy at James Madison University

Content Teaching Academy at James Madison University Content Teaching Academy at James Madison University 1 2 The Battle Field: Computers, LANs & Internetworks 3 Definitions Computer Security - generic name for the collection of tools designed to protect

More information

Plain English Guide To Common Criteria Requirements In The. Field Device Protection Profile Version 0.75

Plain English Guide To Common Criteria Requirements In The. Field Device Protection Profile Version 0.75 Plain English Guide To Common Criteria Requirements In The Field Device Protection Profile Version 0.75 Prepared For: Process Control Security Requirements Forum (PCSRF) Prepared By: Digital Bond, Inc.

More information

)454 6. SERIES V: DATA COMMUNICATION OVER THE TELEPHONE NETWORK Interfaces and voiceband modems. ITU-T Recommendation V.25

)454 6. SERIES V: DATA COMMUNICATION OVER THE TELEPHONE NETWORK Interfaces and voiceband modems. ITU-T Recommendation V.25 INTERNATIONAL TELECOMMUNICATION UNION )454 6 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (10/96) SERIES V: DATA COMMUNICATION OVER THE TELEPHONE NETWORK Interfaces and voiceband modems!utomatic ANSWERING

More information

Information Security Basic Concepts

Information Security Basic Concepts Information Security Basic Concepts 1 What is security in general Security is about protecting assets from damage or harm Focuses on all types of assets Example: your body, possessions, the environment,

More information

INTERNATIONAL TELECOMMUNICATION UNION. WORLD TELECOMMUNICATION STANDARDIZATION ASSEMBLY Dubai, 20-29 November 2012

INTERNATIONAL TELECOMMUNICATION UNION. WORLD TELECOMMUNICATION STANDARDIZATION ASSEMBLY Dubai, 20-29 November 2012 INTERNATIONAL TELECOMMUNICATION UNION ITU-T TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU WORLD TELECOMMUNICATION STANDARDIZATION ASSEMBLY Dubai, 20-29 November 2012 Resolution 76 Studies related to

More information

SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Cloud Computing

SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Cloud Computing I n t e r n a t i o n a l T e l e c o m m u n i c a t i o n U n i o n ITU-T Y.3600 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (11/2015) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL

More information

ETSI TR 102 071 V1.2.1 (2002-10)

ETSI TR 102 071 V1.2.1 (2002-10) TR 102 071 V1.2.1 (2002-10) Technical Report Mobile Commerce (M-COMM); Requirements for Payment Methods for Mobile Commerce 2 TR 102 071 V1.2.1 (2002-10) Reference RTR/M-COMM-007 Keywords commerce, mobile,

More information

ITU-T X.805 based Vulnerability Analysis Method for Security Framework of End-to-End Network Services

ITU-T X.805 based Vulnerability Analysis Method for Security Framework of End-to-End Network Services ITU-T X.805 based Vulnerability Method for Security Framework of End-to-End Network Services YOUNGDUK CHO YOOJAE WON BYONGJIN CHO Information Security Technology Division Korea Information Security Agency

More information

INFORMATION TECHNOLOGY SECURITY STANDARDS

INFORMATION TECHNOLOGY SECURITY STANDARDS INFORMATION TECHNOLOGY SECURITY STANDARDS Version 2.0 December 2013 Table of Contents 1 OVERVIEW 3 2 SCOPE 4 3 STRUCTURE 5 4 ASSET MANAGEMENT 6 5 HUMAN RESOURCES SECURITY 7 6 PHYSICAL AND ENVIRONMENTAL

More information

Credit Card Security

Credit Card Security Credit Card Security Created 16 Apr 2014 Revised 16 Apr 2014 Reviewed 16 Apr 2014 Purpose This policy is intended to ensure customer personal information, particularly credit card information and primary

More information

Cryptography and Network Security Chapter 1

Cryptography and Network Security Chapter 1 Cryptography and Network Security Chapter 1 Acknowledgments Lecture slides are based on the slides created by Lawrie Brown Chapter 1 Introduction The art of war teaches us to rely not on the likelihood

More information

COSC 472 Network Security

COSC 472 Network Security COSC 472 Network Security Instructor: Dr. Enyue (Annie) Lu Office hours: http://faculty.salisbury.edu/~ealu/schedule.htm Office room: HS114 Email: ealu@salisbury.edu Course information: http://faculty.salisbury.edu/~ealu/cosc472/cosc472.html

More information

INTERNATIONAL TELECOMMUNICATION UNION. SERIES V: DATA COMMUNICATION OVER THE TELEPHONE NETWORK Interfaces and voiceband modems

INTERNATIONAL TELECOMMUNICATION UNION. SERIES V: DATA COMMUNICATION OVER THE TELEPHONE NETWORK Interfaces and voiceband modems INTERNATIONAL TELECOMMUNICATION UNION ITU-T V.24 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (02/2000) SERIES V: DATA COMMUNICATION OVER THE TELEPHONE NETWORK Interfaces and voiceband modems List of

More information

ISO/IEC 27002:2013 WHITEPAPER. When Recognition Matters

ISO/IEC 27002:2013 WHITEPAPER. When Recognition Matters When Recognition Matters WHITEPAPER ISO/IEC 27002:2013 INFORMATION TECHNOLOGY - SECURITY TECHNIQUES CODE OF PRACTICE FOR INFORMATION SECURITY CONTROLS www.pecb.com CONTENT 3 4 5 6 6 7 7 7 7 8 8 8 9 9 9

More information

Toward global Interoperable Identity Management

Toward global Interoperable Identity Management ITU-T Joint Meeting on the IdM Focus Group Reports Toward global Interoperable Identity Management Anthony-Michael Rutkowski Vice-President, VeriSign Chair, ITU-T IdM FG Requirements WG Geneva, 10-11 September

More information

Next Generation Networks architecture by ITU-T

Next Generation Networks architecture by ITU-T Next Generation Networks architecture by ITU-T Robert Wójcik Department of Telecommunications 21st January 2009, Kraków, Poland Outline 1 The beginnings 2 The definition 3 Fundamental characteristics of

More information

EESTI STANDARD EVS-ISO/IEC 18028-2:2007

EESTI STANDARD EVS-ISO/IEC 18028-2:2007 EESTI STANDARD EVS-ISO/IEC 18028-2:2007 INFOTEHNOLOOGIA Turbemeetodid Infotehnoloogiavõrkude turve Osa 2: Võrguturbe arhitektuur Information technology Security techniques IT network security Part 2: Network

More information

Smart Card- An Alternative to Password Authentication By Ahmad Ismadi Yazid B. Sukaimi

Smart Card- An Alternative to Password Authentication By Ahmad Ismadi Yazid B. Sukaimi Smart Card- An Alternative to Password Authentication By Ahmad Ismadi Yazid B. Sukaimi Purpose This paper is intended to describe the benefits of smart card implementation and it combination with Public

More information

ISO 27001 Controls and Objectives

ISO 27001 Controls and Objectives ISO 27001 s and Objectives A.5 Security policy A.5.1 Information security policy Objective: To provide management direction and support for information security in accordance with business requirements

More information

Information System Security

Information System Security Information System Security Chapter 1:Introduction Dr. Lo ai Tawalbeh Faculty of Information system and Technology, The Arab Academy for Banking and Financial Sciences. Jordan Chapter 1 Introduction The

More information

Electronic Data Interchange (EDI) Messaging Security

Electronic Data Interchange (EDI) Messaging Security Essay 18 Electronic Data Interchange (EDI) Messaging Security Ted Humphreys The modern economy and the future wealth and prosperity of industry and commerce rely increasingly on the exchange of data and

More information

Network Security 網 路 安 全. Lecture 1 February 20, 2012 洪 國 寶

Network Security 網 路 安 全. Lecture 1 February 20, 2012 洪 國 寶 Network Security 網 路 安 全 Lecture 1 February 20, 2012 洪 國 寶 1 Outline Course information Motivation Introduction to security Basic network concepts Network security models Outline of the course 2 Course

More information

Neutralus Certification Practices Statement

Neutralus Certification Practices Statement Neutralus Certification Practices Statement Version 2.8 April, 2013 INDEX INDEX...1 1.0 INTRODUCTION...3 1.1 Overview...3 1.2 Policy Identification...3 1.3 Community & Applicability...3 1.4 Contact Details...3

More information

Cryptographic Modules, Security Level Enhanced. Endorsed by the Bundesamt für Sicherheit in der Informationstechnik

Cryptographic Modules, Security Level Enhanced. Endorsed by the Bundesamt für Sicherheit in der Informationstechnik Common Criteria Protection Profile Cryptographic Modules, Security Level Enhanced BSI-CC-PP-0045 Endorsed by the Foreword This Protection Profile - Cryptographic Modules, Security Level Enhanced - is issued

More information

7. Public Key Cryptosystems and Digital Signatures, 8. Firewalls, 9. Intrusion detection systems, 10. Biometric Security Systems, 11.

7. Public Key Cryptosystems and Digital Signatures, 8. Firewalls, 9. Intrusion detection systems, 10. Biometric Security Systems, 11. Content 1.Introduction to Data and Network Security. 2. Why secure your Network 3. How Much security do you need, 4. Communication of network systems, 5. Topology security, 6. Cryptosystems and Symmetric

More information

A SECURITY ARCHITECTURE FOR AGENT-BASED MOBILE SYSTEMS. N. Borselius 1, N. Hur 1, M. Kaprynski 2 and C.J. Mitchell 1

A SECURITY ARCHITECTURE FOR AGENT-BASED MOBILE SYSTEMS. N. Borselius 1, N. Hur 1, M. Kaprynski 2 and C.J. Mitchell 1 A SECURITY ARCHITECTURE FOR AGENT-BASED MOBILE SYSTEMS N. Borselius 1, N. Hur 1, M. Kaprynski 2 and C.J. Mitchell 1 1 Royal Holloway, University of London 2 University of Strathclyde ABSTRACT Future mobile

More information

COMMISSION OF THE EUROPEAN COMMUNITIES

COMMISSION OF THE EUROPEAN COMMUNITIES EN EN EN COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 11/XII/2006 C (2006) 6364 final COMMISSION DECISION of 11/XII/2006 List of standards and/or specifications for electronic communications networks,

More information

LAW FOR THE ELECTRONIC DOCUMENT AND ELECTRONIC SIGNATURE. Chapter two. ELECTRONIC DOCUMENT AND ELECTRONIC SIGNATURE

LAW FOR THE ELECTRONIC DOCUMENT AND ELECTRONIC SIGNATURE. Chapter two. ELECTRONIC DOCUMENT AND ELECTRONIC SIGNATURE LAW FOR THE ELECTRONIC DOCUMENT AND ELECTRONIC SIGNATURE Prom. SG. 34/6 Apr 2001, amend. SG. 112/29 Dec 2001, amend. SG. 30/11 Apr 2006, amend. SG. 34/25 Apr 2006, amend. SG. 38/11 May 2007 Chapter one.

More information

IY2760/CS3760: Part 6. IY2760: Part 6

IY2760/CS3760: Part 6. IY2760: Part 6 IY2760/CS3760: Part 6 In this part of the course we give a general introduction to network security. We introduce widely used security-specific concepts and terminology. This discussion is based primarily

More information

ELECTRONIC SIGNATURES AND ASSOCIATED LEGISLATION

ELECTRONIC SIGNATURES AND ASSOCIATED LEGISLATION ELECTRONIC SIGNATURES AND ASSOCIATED LEGISLATION This can be a complex subject and the following text offers a brief introduction to Electronic Signatures, followed by more background on the Register of

More information

SECURITY INFRASTRUCTURE Standards and implementation practices for protecting the privacy and security of shared genomic and clinical data

SECURITY INFRASTRUCTURE Standards and implementation practices for protecting the privacy and security of shared genomic and clinical data Global Alliance for Genomics and Health SECURITY INFRASTRUCTURE Standards and implementation practices for protecting the privacy and security of shared genomic and clinical data VERSION 1.1 March 12,

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Imprint Machines or Stand-alone Dial-out Terminals Only, no Electronic Cardholder Data Storage

More information

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows: What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers

More information

The Impact of 21 CFR Part 11 on Product Development

The Impact of 21 CFR Part 11 on Product Development The Impact of 21 CFR Part 11 on Product Development Product development has become an increasingly critical factor in highly-regulated life sciences industries. Biotechnology, medical device, and pharmaceutical

More information

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst. 2010. Page 1 of 7 www.ecfirst.com

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst. 2010. Page 1 of 7 www.ecfirst.com Policy/Procedure Description PCI DSS Policies Install and Maintain a Firewall Configuration to Protect Cardholder Data Establish Firewall and Router Configuration Standards Build a Firewall Configuration

More information

COM 17 LS 05 E. English only Original: English TELECOMMUNICATION STANDARDIZATION SECTOR. Question(s): 9/17

COM 17 LS 05 E. English only Original: English TELECOMMUNICATION STANDARDIZATION SECTOR. Question(s): 9/17 Question(s): 9/17 INTERNATIONAL TELECOMMUNICATION UNION TELECOMMUNICATION STANDARDIZATION SECTOR STUDY PERIOD 2005-2008 LIAISON STATEMENT Source: Q.9/17 Rapporteur Group (Tokyo, 15-17 November 2004) Title:

More information

Requirements & Reference Models for ADSL Access Networks: The SNAG Document

Requirements & Reference Models for ADSL Access Networks: The SNAG Document Technical Report TR-010 Requirements & Reference Models for ADSL Access Networks: The SNAG Document June 1998 Abstract: This document outlines architectural requirements and reference models for ADSL services

More information

Department of Veterans Affairs VA DIRECTIVE 6510 VA IDENTITY AND ACCESS MANAGEMENT

Department of Veterans Affairs VA DIRECTIVE 6510 VA IDENTITY AND ACCESS MANAGEMENT Department of Veterans Affairs VA DIRECTIVE 6510 Washington, DC 20420 Transmittal Sheet VA IDENTITY AND ACCESS MANAGEMENT 1. REASON FOR ISSUE: This Directive defines the policy and responsibilities to

More information

SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Transmission media and optical systems characteristics Optical fibre cables

SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Transmission media and optical systems characteristics Optical fibre cables International Telecommunication Union ITU-T G.657 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (11/2009) SERIES G: TRANSMISSION SYSTEMS AND MEDIA, DIGITAL SYSTEMS AND NETWORKS Transmission media and

More information

SHORT MESSAGE SERVICE SECURITY

SHORT MESSAGE SERVICE SECURITY SHORT MESSAGE SERVICE SECURITY February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in

More information

##)44 ) #!,, &/27!2$).' 5.#/.$)4)/.!, ).4%'2!4%$ 3%26)#%3 $)')4!,.%47/2+ )3$. '%.%2!, 3425#452%!.$ 3%26)#% #!0!"),)4)%3 2ECOMMENDATION )

##)44 ) #!,, &/27!2$).' 5.#/.$)4)/.!, ).4%'2!4%$ 3%26)#%3 $)')4!,.%47/2+ )3$. '%.%2!, 3425#452%!.$ 3%26)#% #!0!),)4)%3 2ECOMMENDATION ) INTERNATIONAL TELECOMMUNICATION UNION ##)44 ) THE INTERNATIONAL (08/92) TELEGRAPH AND TELEPHONE CONSULTATIVE COMMITTEE ).4%'2!4%$ 3%26)#%3 $)')4!,.%47/2+ )3$. '%.%2!, 3425#452%!.$ 3%26)#% #!0!"),)4)%3

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU M.2140 (02/2000) SERIES M: TMN AND NETWORK MAINTENANCE: INTERNATIONAL TRANSMISSION SYSTEMS, TELEPHONE CIRCUITS, TELEGRAPHY,

More information

Information Security

Information Security Information Security Dr. Vedat Coşkun Malardalen September 15th, 2009 08:00 10:00 vedatcoskun@isikun.edu.tr www.isikun.edu.tr/~vedatcoskun What needs to be secured? With the rapid advances in networked

More information

3. Designed for installation by the user without further substantial support by the supplier; and

3. Designed for installation by the user without further substantial support by the supplier; and Commerce Control List Supplement No. 1 to Part 774 Category 5 - Info. Security page 1 CATEGORY 5 TELECOMMUNICATIONS AND INFORMATION SECURITY Part 2 INFORMATION SECURITY Note 1: The control status of information

More information

Certified Information Systems Auditor (CISA)

Certified Information Systems Auditor (CISA) Certified Information Systems Auditor (CISA) Course Introduction Course Introduction Module 01 - The Process of Auditing Information Systems Lesson 1: Management of the Audit Function Organization of the

More information

INTERNATIONAL TELECOMMUNICATION UNION

INTERNATIONAL TELECOMMUNICATION UNION INTERNATIONAL TELECOMMUNICATION UNION TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU M.3400 (02/2000) SERIES M: TMN AND NETWORK MAINTENANCE: INTERNATIONAL TRANSMISSION SYSTEMS, TELEPHONE CIRCUITS, TELEGRAPHY,

More information

HIPAA Security. 4 Security Standards: Technical Safeguards. Security Topics

HIPAA Security. 4 Security Standards: Technical Safeguards. Security Topics HIPAA Security S E R I E S Security Topics 1. Security 101 for Covered Entities 2. Security Standards - Administrative Safeguards 3. Security Standards - Physical Safeguards 4. Security Standards - Technical

More information

ORDINANCE ON THE ELECTRONIC SIGNATURE CERTIFICATES IN THE. Chapter One GENERAL PROVISIONS

ORDINANCE ON THE ELECTRONIC SIGNATURE CERTIFICATES IN THE. Chapter One GENERAL PROVISIONS ADMINISTRATIONS Effective as of 13 June 2008 Adopted by Decree of the Council of Ministers No 97 of 16 May 2008 Promulgated SG, No. 48 of 23 May 2008 Chapter One GENERAL PROVISIONS Article 1. This Ordinance

More information

Technical Safeguards is the third area of safeguard defined by the HIPAA Security Rule. The technical safeguards are intended to create policies and

Technical Safeguards is the third area of safeguard defined by the HIPAA Security Rule. The technical safeguards are intended to create policies and Technical Safeguards is the third area of safeguard defined by the HIPAA Security Rule. The technical safeguards are intended to create policies and procedures to govern who has access to electronic protected

More information

159.334 Computer Networks. Network Security 1. Professor Richard Harris School of Engineering and Advanced Technology

159.334 Computer Networks. Network Security 1. Professor Richard Harris School of Engineering and Advanced Technology Network Security 1 Professor Richard Harris School of Engineering and Advanced Technology Presentation Outline Overview of Identification and Authentication The importance of identification and Authentication

More information

Hang Seng HSBCnet Security. May 2016

Hang Seng HSBCnet Security. May 2016 Hang Seng HSBCnet Security May 2016 1 Security The Bank aims to provide you with a robust, reliable and secure online environment in which to do business. We seek to achieve this through the adoption of

More information

ICT USER ACCOUNT MANAGEMENT POLICY

ICT USER ACCOUNT MANAGEMENT POLICY ICT USER ACCOUNT MANAGEMENT POLICY Version Control Version Date Author(s) Details 1.1 23/03/2015 Yaw New Policy ICT User Account Management Policy 2 Contents 1. Preamble... 4 2. Terms and definitions...

More information

Introduction to Security

Introduction to Security 2 Introduction to Security : IT Security Sirindhorn International Institute of Technology Thammasat University Prepared by Steven Gordon on 25 October 2013 its335y13s2l01, Steve/Courses/2013/s2/its335/lectures/intro.tex,

More information

Electronic Payment Schemes Guidelines

Electronic Payment Schemes Guidelines BANK OF TANZANIA Electronic Payment Schemes Guidelines Bank of Tanzania May 2007 Bank of Tanzania- Electronic Payment Schemes and Products Guidleness page 1 Bank of Tanzania, 10 Mirambo Street, Dar es

More information

ETSI TR 101 303 V1.1.2 (2001-12)

ETSI TR 101 303 V1.1.2 (2001-12) TR 101 303 V1.1.2 (2001-12) Technical Report Telecommunications and Internet Protocol Harmonization Over Networks (TIPHON) Release 3; Requirements definition study; Introduction to service and network

More information

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Secure applications and services IPTV security

SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Secure applications and services IPTV security International Telecommunication Union ITU-T X.1198 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (06/2013) SERIES X: DATA NETWORKS, OPEN SYSTEM COMMUNICATIONS AND SECURITY Secure applications and services

More information

Policy for the Acceptable Use of Information Technology Resources

Policy for the Acceptable Use of Information Technology Resources Policy for the Acceptable Use of Information Technology Resources Purpose... 1 Scope... 1 Definitions... 1 Compliance... 2 Limitations... 2 User Accounts... 3 Ownership... 3 Privacy... 3 Data Security...

More information

Network Security. Introduction. Security services. Players. Conclusions. Distributed information Distributed processing Remote smart systems access

Network Security. Introduction. Security services. Players. Conclusions. Distributed information Distributed processing Remote smart systems access Roadmap Introduction Network services X.800 RFC 2828 Players Marco Carli Conclusions 2 Once.. now: Centralized information Centralized processing Remote terminal access Distributed information Distributed

More information

Alternative authentication what does it really provide?

Alternative authentication what does it really provide? Alternative authentication what does it really provide? Steve Pannifer Consult Hyperion Tweed House 12 The Mount Guildford GU2 4HN UK steve.pannifer@chyp.com Abstract In recent years many new technologies

More information

CS 203 / NetSys 240. Network Security

CS 203 / NetSys 240. Network Security CS 203 / NetSys 240 Network Security Winter 2015 http://sconce.ics.uci.edu/203-w15/ 1 Contact Information Instructor: Gene Tsudik Email: gene.tsudik *AT* uci.edu Phone: (949) 824-43410 use only as the

More information

Draft Information Technology Policy

Draft Information Technology Policy Draft Information Technology Policy Version 3.0 Draft Date June 2014 Status Draft Approved By: Table of Contents 1.0 Introduction... 6 Background... 6 Purpose... 6 Scope... 6 Legal Framework... 6 2.0 Software

More information

Excerpt of Cyber Security Policy/Standard S05-001. Information Security Standards

Excerpt of Cyber Security Policy/Standard S05-001. Information Security Standards Excerpt of Cyber Security Policy/Standard S05-001 Information Security Standards Issue Date: April 4, 2005 Publication Date: April 4, 2005 Revision Date: March 30, 2007 William F. Pelgrin Director New

More information

ETSI TS 102 778 V1.1.1 (2009-04) Technical Specification

ETSI TS 102 778 V1.1.1 (2009-04) Technical Specification TS 102 778 V1.1.1 (2009-04) Technical Specification Electronic Signatures and Infrastructures (ESI); PDF Advanced Electronic Signature Profiles; CMS Profile based on ISO 32000-1 2 TS 102 778 V1.1.1 (2009-04)

More information

Cyber-Ark Software and the PCI Data Security Standard

Cyber-Ark Software and the PCI Data Security Standard Cyber-Ark Software and the PCI Data Security Standard INTER-BUSINESS VAULT (IBV) The PCI DSS Cyber-Ark s View The Payment Card Industry Data Security Standard (PCI DSS) defines security measures to protect

More information

Certification Report

Certification Report Certification Report EAL 4 Evaluation of SecureDoc Disk Encryption Version 4.3C Issued by: Communications Security Establishment Certification Body Canadian Common Criteria Evaluation and Certification

More information