Central Information Point for Telecom Investigation CIOT René Bladder
|
|
|
- Garey Blake
- 10 years ago
- Views:
Transcription
1 Central Information Point for Telecom Investigation CIOT René Bladder RIPE 58 Meeting 4 th may 2009
2 Content of this presentation Why CIOT? Goal CIOT CIOT Information System Informatiebijeenkomst aanbieders 26 februari 2009
3 Why CIOT? ( ) Increase of interest for Telecom data/users (LEA) Liberalisation of Telecom market; Existing communications: Not quick (days/weeks) Not cost efficient (manual fax procedure) Not complete (not all providers) No track records No standards
4 LEA's 25 Police regions 6 Units National Recherche 4 Special cid s from four ministries: FIOD, AID, IOD, SIOD 2 Intelligence (secret) Services: AIVD en MIVD Internal Affaires Police, KMAR, KLPD 112, Central Authority (LP-OM) 42 organisations with regulated, legal access.
5 Providers All Telecom Providers for fixed lines, mobile telephony (MVNE & MVNO), carrier (pre-) select services,... All Internet Service Providers for internet access and services Telco's started in 2004 ISP's started in 2006 Total number of connected providers: ± 110
6 Central organisations OPTA for pricing, number distribution, etc... Telecom Agency of the Ministry of Economic affairs for the Telecom Law and Besluit-CIOT COIN (Telecom companies) for central storage of data for portering of telephone numbers Central Bureau for Privacy concerning Personal Data (privacy in general)
7 Goal CIOT Collect current customer data from providers on a daily basis; Deliver specific information to: (Special) Investigation Services Intelligence & Security Services Manage the CIOT Information system guarding careful storage and rightful use of the system; Be an intermediary between LEA and providers. CIOT is part of the Ministry of Justice.
8 Type of Data Customer data ==> CIOT Traffic data ==> Data retention act (soon...) Content data ==> Legal Interception
9 Service developed ( ) Investigators BOIDs Public Prosecutors CIOT Providers
10 Legal embedding/agreements Telecom Act WIV Privacy Act Provider Decree CIOT BOID WvS Privacy agreement Audit agreement SLA with Provider SLA with BOID CIOT
11 CIOT model Automated request for information to providers Automated comparison of questions with data of providers Automated delivering of answers Request + question + answer is only visible by authorities Management of system is performed by CIOT Monitoring is clear and precise Use of the system is based on the law
12 Generic Question / Answer process Client Blackbox Applicant Submitting a request for data Question Question Daily update of data Provider Warrant Answer Answer Competent Authority Server Authorisation for using the system Central Authority Reports on the use of the CIOT-system Ministry of Justice Development, IT management and Security CIOT
13 Request Identification warrant Legal base for request Function competent authority Name investigation
14 Type of Question Telephone number address IP-address v4 IP-address v6 Account ID Hardware ID Postal code + house number
15 Answer Name + Address + City foreign address Type of address Type of Service Type of Network service Name Service provider Name Network provider Date creation database
16
17
18 Key results Increased efficiency Volume and location independent Generic application with standard equipment System is 24 hours / 7 days available Standard format for telecom and internet data Security of system approved by intelligence services and audited by KPMG and FOX-IT
19 Production highlights Hit-rate is 88% - 94% questions per month 42 BOIDs send in requests for information 110 Providers give answers Roughly 50 million telephone numbers and 31 million internet identifying items are accessible using the CIOT-system
20 Questions Do not hesitate and ask questions now!...or contact CIOT via ask me later at the bar ;-) Informatiebijeenkomst aanbieders 26 februari 2009
Lawful Interception in practise in the Netherlands
SvSnet Stichting Nationale Beheersorganisatie Internet Providers Lawful Interception in practise in the Netherlands Cyprus 30 June 2010 Pim van Stam SvSnet 1 SvSnet Stichting Nationale Beheersorganisatie
Privacy in the cloud. DNB has indicated that it considers cloud computing a form of outsourcing.
Privacy in the cloud computing, and the company concerned is required to submit a risk analysis to DNB. 3 Cloud computing entails the saving, processing and using of company data on the servers of a cloud
Liability of Network Service Providers
Liability of Network Service Providers This document is an extract from the book Cyber Crime & Digital Evidence Indian Perspective authored by Rohas Nagpal. This book is available as courseware for the
Statistics on Requests for data under the Data Retention Directive
Statistics on Requests for data under the Data Retention Directive Introduction 1. Directive 2006/24/EC on data retention ('the DRD') 1 requires Member States to provide the Commission on a yearly basis
Lex Mundi Telecommunications Regulation Multi-Jurisdictional Survey
Lex Mundi Telecommunications Regulation Multi-Jurisdictional Survey CONTACT INFORMATION Mr. J.F.A. Doeleman Houthoff Buruma N.V. P.O. Box 75505 1070 AM AMSTERDAM +31206056315 [email protected] NETHERLANDS
Basics of VoIP Termination
Basics of VoIP Termination Version 1.1 July 26, 2006 AdvancedVoIP.com [email protected] [email protected] Phone: +1 213 341 1431 Copyright AdvancedVoIP.com, 1999-2006. All Rights Reserved.
Thanks to SECNOLOGY s wide range and easy to use technology, it doesn t take long for clients to benefit from the vast range of functionality.
The Big Data Mining Company BETTER VISILITY FOR BETTER CONTROL AND BETTER MANAGEMENT 100 Examples on customer use cases Thanks to SECNOLOGY s wide range and easy to use technology, it doesn t take long
Global Information Society Watch 2014
Global Information Society Watch 2014 Communications surveillance in the digital age This report was originally published as part of a larger compilation, which can be downloaded from GISWatch.org Association
Concept. Central Monitoring and IP Address Administration
Concept Central Monitoring and IP Address Administration Concept of Central Monitoring and IP Address Administration Novicom Company together with its partner Invea-tech offer a unique concept of Centralized
The National Cyber Security Strategy (NCSS) Success through cooperation
The National Cyber Security Strategy (NCSS) Success through cooperation 1. Introduction The Netherlands stands for safe and reliable ICT 1 and the protection of the openness and freedom of the Internet.
Patrick Fair Partner, ITC and Data Security Specialist Baker & McKenzie. Developments in Security Regulation
Patrick Fair Partner, ITC and Data Security Specialist Baker & McKenzie Developments in Security Regulation Agenda Introduction PM & C Cybersecurity Review Mandatory Data Retention Legislation Overview
Number 3 of 2011 COMMUNICATIONS (RETENTION OF DATA) ACT 2011 ARRANGEMENT OF SECTIONS
Number 3 of 2011 COMMUNICATIONS (RETENTION OF DATA) ACT 2011 ARRANGEMENT OF SECTIONS Section 1. Interpretation. 2. Non-application of Act. 3. Obligation to retain data. 4. Data security. 5. Access to data.
Lawrence Police Department Administrative Policy. August 2013. A. Access to CJIS sensitive data is only available to authorized users.
Lawrence Police Department Administrative Policy SUBJECT Criminal Justice Information System (CJIS) APPLIES TO All Personnel EFFECTIVE DATE REVISED DATE August 2013 APPROVED BY Chief of Police TOTAL PAGES
Ulster University Standard Cover Sheet
Ulster University Standard Cover Sheet Document Title IT Monitoring Policy 1.5 Custodian Approving Committee Deputy Director of Finance and Information Services (Information Services) Information Services
Protecting Saskatchewan data the USA Patriot Act
Protecting Saskatchewan data the USA Patriot Act Main points... 404 Introduction... 405 Standing Committee on Public Accounts motion... 405 Our response to the motion... 405 ITO, its service provider,
XDR. Big Data solution.
XDR Big Data solution. MAIN GOAL Xdr is a solution that uses a simple low-cost architecture integrated to the business infrastructure of Telecom companies. Both Telcos and Internet businesses have often
Taking VoIP Innovation to the Next Level
Taking VoIP Innovation to the Next Level Introduction Voxvalley Voxvalley offers ICT Solutions to global clients empowering them with real-time modern communication capabilities and next-gen software solutions
Managed Services Billing Platform For MVNOs
Managed Platform For MVNOs Search for local partners (MVNEs) One Business Avenue / One Address for Business Development About One Business Avenue One Address for Business Development A business consulting
INFORMATION SECURITY POLICY. Contents. Introduction 2. Policy Statement 3. Information Security at RCA 5. Annexes
INFORMATION SECURITY POLICY Ratified by RCA Senate, February 2007 Contents Introduction 2 Policy Statement 3 Information Security at RCA 5 Annexes A. Applicable legislation and interpretation 8 B. Most
REPORT FROM THE COMMISSION TO THE COUNCIL AND THE EUROPEAN PARLIAMENT. Evaluation report on the Data Retention Directive (Directive 2006/24/EC)
EUROPEAN COMMISSION Brussels, 18.4.2011 COM(2011) 225 final REPORT FROM THE COMMISSION TO THE COUNCIL AND THE EUROPEAN PARLIAMENT Evaluation report on the Data Retention Directive (Directive 2006/24/EC)
Click here for Explanatory Memorandum
Click here for Explanatory Memorandum AN BILLE CUMARSÁIDE (SONRAÍ A CHOIMEÁD) 2009 COMMUNICATIONS (RETENTION OF DATA) BILL 2009 Section 1. Interpretation. Mar a tionscnaíodh As initiated ARRANGEMENT OF
European Commission Directorate General for HOME AFFAIRS. Guide for applicants. Call for expression of interest HOME/2014/AMIH/001
European Commission Directorate General for HOME AFFAIRS Guide for applicants Call for expression of interest HOME/2014/AMIH/001 for the establishment of a list of individual external experts to assist
ETNO Expert Contribution on Data retention in e- communications - Council s Draft Framework Decision, Commission s Proposal for a Directive
October 2005 ETNO Expert Contribution on Data retention in e- communications - Council s Draft Framework Decision, Commission s Proposal for a Directive INTRODUCTION 1.- Purpose of the document This document
24/7 High Tech Crime Network
24/7 High Tech Crime Network Albert Rees Computer Crime & Intellectual Property Section Criminal Division, U.S. Department of Justice 24/7 Network The G-8 24/7 Network for Data Preservation Points of contact
Employees monitoring of information and communication technologies private usage Guidelines updated in Portugal
COELHO RIBEIRO E ASSOCIADOS SOCIEDADE CIVIL DE ADVOGADOS Employees monitoring of information and communication technologies private usage Guidelines updated in Portugal CRA Coelho Ribeiro e Associados,
Cookies and consent. The Article 29 Working Party has identified seven types of cookies that are not subject to the consent requirement.
Cookies and consent Cookies are small text files placed on a computer and accessed by the browser when opening a webpage. - DDMA 2012 The statutory requirements governing the placement of cookies were
Third party Web hosting services security Policy
Office of the Prime Minister Policy document CIMU P 0013:2003 Version: 2.0 Effective date: 09.04.2003 Third party Web hosting services security Policy 1. Policy statement i) General The Government of Malta
An Overview of Cybersecurity and Cybercrime in Taiwan
An Overview of Cybersecurity and Cybercrime in Taiwan I. Introduction To strengthen Taiwan's capability to deal with information and communication security issues, the National Information and Communication
WHITE PAPER. Gaining Total Visibility for Lawful Interception
WHITE PAPER Gaining Total Visibility for Lawful Interception www.ixiacom.com 915-6910-01 Rev. A, July 2014 2 Table of Contents The Purposes of Lawful Interception... 4 Wiretapping in the Digital Age...
SERIES A : GUIDANCE DOCUMENTS. Document Nr 3
DATRET/EXPGRP (2009) 3 - FINAL EXPERTS GROUP "THE PLATFORM FOR ELECTRONIC DATA RETENTION FOR THE INVESTIGATION, DETECTION AND PROSECUTION OF SERIOUS CRIME" ESTABLISHED BY COMMISSION DECISION 2008/324/EC
Position Paper 4. Closer understanding of the term third party networks and service providers" in relation to its application in Directive 2006/24/EC
DATRET/EXPGRP (2009) 4 FINAL EXPERTS GROUP "THE PLATFORM FOR ELECTRONIC DATA RETENTION FOR THE INVESTIGATION, DETECTION AND PROSECUTION OF SERIOUS CRIME" ESTABLISHED BY COMMISSION DECISION 2008/324/EC
University of Liverpool
University of Liverpool Information Security Policy Reference Number Title CSD-003 Information Security Policy Version Number 3.0 Document Status Document Classification Active Open Effective Date 01 October
Fit and proper person form
Fit and proper person form Last updated: 9 March 2015 About this form To hold any maritime document(s), you are required to be a fit and proper person. This applies at all times while the documents are
TICSA. Telecommunications (Interception Capability and Security) Act 2013. Guidance for Network Operators. www.gcsb.govt.nz www.ncsc.govt.
TICSA Telecommunications (Interception Capability and Security) Act 2013 Guidance for Network Operators www.gcsb.govt.nz www.ncsc.govt.nz Contents Introduction...2 Overview of the Guidance...3 Focus of
CROATIAN PARLIAMENT Pursuant to Article 88 of the Constitution of the Republic of Croatia, I hereby pass the
CROATIAN PARLIAMENT Pursuant to Article 88 of the Constitution of the Republic of Croatia, I hereby pass the DECISION PROMULGATING THE ACT ON THE SECURITY INTELLIGENCE SYSTEM OF THE REPUBLIC OF CROATIA
A Framework for Secure and Verifiable Logging in Public Communication Networks
A Framework for Secure and Verifiable Logging in Public Communication Networks Vassilios Stathopoulos, Panayiotis Kotzanikolaou and Emmanouil Magkos {v.stathopoulos, p.kotzanikolaou}@adae.gr [email protected]
Cybercrime & Cybersecurity
Cybercrime & Cybersecurity Professor Ian Walden Institute for Computer and Communications Law Centre for Commercial Law Studies, Queen Mary, University of London Introductory Remarks Inherently transnational
Act on Background Checks
NB: Unofficial translation Ministry of Justice, Finland Act on Background Checks (177/2002) Chapter 1 General provisions Section 1 Scope of application (1) This Act applies to background checks, which
STFC Monitoring and Interception policy for Information & Communications Technology Systems and Services
STFC Monitoring and Interception policy for Information & Communications Technology Systems and Services Issue 1.0 (Effective 27 June 2012) This document contains a copy of the STFC policy statements outlining
DOCUMATION S DOCUMENT MANAGEMENT
Documation is a leading provider of document-centric workflow and content management software, delivering services and solutions to businesses and organisations in the UK, Europe and around the world.
EDI BROCHURE ELECTRONIC DATA INTERCHANGE WITH FORD. created by GSEC, Global Supplier Electronic Communications
ELECTRONIC DATA INTERCHANGE WITH FORD EDI BROCHURE created by GSEC, Global Electronic Communications Page 1 of 23 Brochure map EDI Brochure Overview Connecting to Ford Further Information Support Who is
Cautela Labs Cloud Agile. Secured. Threat Management Security Solutions at Work
Cautela Labs Cloud Agile. Secured. Threat Management Security Solutions at Work Security concerns and dangers come both from internal means as well as external. In order to enhance your security posture
On-Line Privacy Statement
On-Line Privacy Statement Custom House Financial (UK) Limited Western Union International Bank GmbH, French Branch Effective Date: 1 Mars 2016 In France, services are provided by Custom House Financial
Review Report. CTIVD nr. 43. Review Committee on the Intelligence and Security Services. arising from the crash of flight MH17
Review Report arising from the crash of flight MH17 The role of the General Intelligence and Security Service of the Netherlands (AIVD) and the Dutch Military Intelligence and Security Service (MIVD) in
Remote searches in the cloud
Remote searches in the cloud A comparative perspective Charlotte Conings & Ruben Roex Setting the scene Elements considered Access to the cloud Network search (art. 88ter CCP) What? Expanding initial search
3rd Party Assurance & Information Governance 2014-2016 outlook IIA Ireland Annual Conference 2014. Straightforward Security and Compliance
3rd Party Assurance & Information Governance 2014-2016 outlook IIA Ireland Annual Conference 2014 Continuous Education Services (elearning/workshops) Compliance Management Portals Information Security
LAW ON MILITARY SECURITY AGENCY AND MILITARY INTELLIGENCE AGENCY I GENERAL PROVISIONS. Article 1
LAW ON MILITARY SECURITY AGENCY AND MILITARY INTELLIGENCE AGENCY I GENERAL PROVISIONS Article 1 This Law shall regulate competences, activities, tasks, authority, oversight and control of the Military
Security MWC 2014. 2013 Nokia Solutions and Networks. All rights reserved.
Security MWC 2014 2013 Nokia Solutions and Networks. All rights reserved. Security Ecosystem overview Partners Network security demo + End-user security demo + + + + NSN end-to-end security solutions for
www.samcom.com.au Samsung OfficeServ ACD Call Centre Interactive Voice Response (IVR) Samsung OfficeServ ACD/IVR
www.samcom.com.au Samsung OfficeServ ACD Call Centre Interactive Voice Response (IVR) Samsung OfficeServ ACD/IVR OfficeServ ACD Call Centre Samsung OfficeServ ACD Call Centre is specifically tailored for
General Terms & Conditions
General Terms & Conditions Service Provider This section sets out the terms and conditions under which BestForeignExchange.com will provide you (the customer) with your foreign exchange needs. For the
CLOUD COMPUTING READINESS CHECKLIST
CLOUD COMPUTING READINESS VOLKER RATH VOLKER RATH 1 CONTENTS HOW SHOULD THIS GUIDE BE USED? 2 WILL MY COMPANY BENEFIT FROM 2 TRANSITIONING SERVICES TO THE CLOUD? CLOUD READINESS OVERVIEW 3 SECURITY CONCERNS
Committee on Civil Liberties, Justice and Home Affairs - The Secretariat - Background Note on
Committee on Civil Liberties, Justice and Home Affairs - The Secretariat - Background Note on US Legal Instruments for Access and Electronic Surveillance of EU Citizens Introduction This note presents
6. AUDIT CHECKLIST FOR NETWORK ADMINISTRATION AND SECURITY AUDITING
6. AUDIT CHECKLIST FOR NETWORK ADMINISTRATION AND SECURITY AUDITING The following is a general checklist for the audit of Network Administration and Security. Sl.no Checklist Process 1. Is there an Information
Network neutrality. Guidelines for Internet neutrality. Version 1.0 24 February 2009
Network neutrality Guidelines for Internet neutrality Version 1.0 24 February 2009 The guidelines in general These network neutrality guidelines have been drawn up by the Norwegian Post and Telecommunications
LCM IT Asset Management
LCM IT Asset Management Management Summary Version 1.0 (16.03.2011) Table of Contents 1 LCM IT Asset Management... 3 1.1 License master data... 4 1.2 Management of IT-relevant contractual relationships,
FIREWALL CHECKLIST. Pre Audit Checklist. 2. Obtain the Internet Policy, Standards, and Procedures relevant to the firewall review.
1. Obtain previous workpapers/audit reports. FIREWALL CHECKLIST Pre Audit Checklist 2. Obtain the Internet Policy, Standards, and Procedures relevant to the firewall review. 3. Obtain current network diagrams
7 August 2015. I. Introduction
Suggestions for privacy-related questions to be included in the list of issues on Hungary, Human Rights Committee, 115th session, October-November 2015 I. Introduction 7 August 2015 Article 17 of the International
Strategic Priorities for the Cooperation against Cybercrime in the Eastern Partnership Region
CyberCrime@EAP EU/COE Eastern Partnership Council of Europe Facility: Cooperation against Cybercrime Strategic Priorities for the Cooperation against Cybercrime in the Eastern Partnership Region Adopted
Vetting for a Security Clearance
New Zealand Security Intelligence Service Te Pa Whakamarumaru An introduction to Vetting for a Security Clearance Information for candidates and referees Vetting for security clearance A New Zealand government
DOCUMATION S SELF-SERVICE PORTAL
Documation is a leading provider of document-centric workflow and content management software, delivering services and solutions to businesses and organisations in the UK, Europe and around the world.
Hosted Exchange Opportunity in Cloud Computing Complete Turnkey Solution
Hosted Exchange Opportunity in Cloud Computing Complete Turnkey Solution Enterprises have seen their communication technologies evolving towards greater unification Unified Messaging Hosting Key Concept:
Template for Automatic Number Plate Recognition (ANPR) Infrastructure Development Privacy Impact Assessment
Template for Automatic Number Plate Recognition (ANPR) Infrastructure Development Privacy Impact Assessment This template is provided to support the police service and other law enforcement agencies (LEA)
The Electronic Transactions Law Chapter I Title and Definition
The Union of Myanmar The State Peace and Development Council The Electronic Transactions Law ( The State Peace and Development Council Law No. 5/2004 ) The 12th Waxing of Kason 1366 M.E. (30th April, 2004)
White Paper: Reach for the Sky. Master the Might of the Hybrid Cloud
White Paper: Reach for the Sky Master the Might of the Hybrid Cloud Introduction We have all heard of cloud computing shared computing resources available over a cloud or the Internet, and we have all
INFORMATION TECHNOLOGY MANAGEMENT CONTENTS. CHAPTER C RISKS 357-7 8. Risk Assessment 357-7
Information Technology Management Page 357-1 INFORMATION TECHNOLOGY MANAGEMENT CONTENTS CHAPTER A GENERAL 357-3 1. Introduction 357-3 2. Applicability 357-3 CHAPTER B SUPERVISION AND MANAGEMENT 357-4 3.
1 Processing of personal data... 1. 2 Information collected for use... 1. 3 WHOIS search function... 2. 1.1 Introduction... 2. 1.2 Purpose...
.WIEN WHOIS-Policy Content 1 Processing of personal data... 1 2 Information collected for use... 1 3 WHOIS search function... 2 1.1 Introduction... 2 1.2 Purpose... 3 1.3 Identification of natural and
Mailwall Remote Features Tour Datasheet
Management Portal & Dashboard Mailwall Remote Features Tour Datasheet Feature Benefit Learn More Screenshot Cloud based portal Securely manage your web filtering policy wherever you are without need for
ACCESS CONTROL SOLUTIONS
ACCESS CONTROL SOLUTIONS ACCESS CONTROL If you need a high level of control over who is entering your building and want to know when people have entered, our state of the art electronic locking systems
Brocade Telemetry Solutions
WHITE PAPER www.brocade.com Service provider Brocade Telemetry Solutions telemetry applications such as Monitoring and Lawful Intercept are important to Service Providers and impose unique requirements
Automated Regional Justice Information System (ARJIS) Acceptable Use Policy for Facial Recognition
Automated Regional Justice Information System (ARJIS) Acceptable Use Policy for Facial Recognition Revised: 02/13/2015 A. STATEMENT OF PURPOSE The purpose of this document is to outline the responsibilities
