& cplSiteName &

Putting a Dollar Sign on Network Security

Carol Wilson
12/6/2012
50%
50%

ORLANDO -- Management World Americas -- Wouldn't you think network service contracts would include security requirements?

It may seem like a no-brainer, but most contracts are built around availability and performance, not security. One of the more intriguing TM Forum Catalyst Projects on display here this week is aimed at helping enterprises and governments create contract terms that build in security requirements.

The idea is to create financial incentives to improve security. As network threats become more sophisticated -– most are currently the work of organized crime –- enterprises and governments want more assurance that network operators are working on the problem. The move to cloud services can make it even harder for enterprises and governments to easily track where their applications and data are, and if they are secure, according to Martin Huddleston of the U.K. Defence Science and Technology Lab, which is a participant in the Catalyst.

The key, being pursued in the Catalyst, is to find metrics and targets for the level of security. According to the other participants in the project, including CA Technologies (Nasdaq: CA), McAfee Inc. (NYSE: MFE) and Sooth Technology , the early metrics will be based on well-defined mitigations already established by the computer emergency response teams (CERTs) that operate in most countries. (Common CERTs include the Defence Signals Directorate of the Australian government, the National Institute of Science and Technology and the SANS Institute Top 20 in the United States. Verizon Enterprise Solutions 's annual Security Breach Report is another source of key mitigation data.)

Just implementing CERTs's basic advice could prevent 85 percent of security breaches, says Christy Coffey, the Government/Defense Market Support Center Head for TMForum. These "low-hanging fruit" include implementing patches for operating systems and applications; practicing mobile device management; improving training to reduce human errors; implementing defenses against denial of service attacks; and hardening servers to prevent data leakage.

Take patch management as an example. Contracts could require the network operator to document the time of exposure; the percentage of devices patched and the degree to which they have been patched; the criticality of patch exposure; the audited degree of systems that are susceptible to attack; the percentage of patches resulting in further problems; and the number of patches.

To date, the Catalyst has shown it is possible to monitor almost all of those things; the one that's been elusive to measure is the audited degree of systems that are susceptible to attack. That's basically an identification of those systems which aren't vulnerable and therefore don't require the same vigilance about patching.

All that detail would give enterprises or governments more confidence in the networks they are using. In the future, the data could be collected and benchmarked to establish industry standards, says Coffey.

If the telecom industry doesn't create ways of quantifying network security and building it into contracts, there is the possibility governments will choose to impose some tighter restrictions, to prevent the negative economic impact of continued security breaches, say the Catalyst participants.

— Carol Wilson, Chief Editor, Events, Light Reading

(0)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Educational Resources
sponsor supplied content
Educational Resources Archive
From The Founder
Cisco's Conrad Clemson, recently promoted to head up the company's Service Provider Apps & Platforms developments, talks to Light Reading's Founder and CEO Steve Saunders about how he's bringing cloud video, mobile and virtualization together to empower network operators.
Flash Poll
Live Streaming Video
Charting the CSP's Future
Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
LRTV Custom TV
CommScope – Meeting the Demands of Tomorrow's Networks

3|24|17   |     |   (0) comments


Phil Sorksy, Vice President International at CommScope, discusses addressing the challenges faced by service providers today, and as future trends emerge.
LRTV Huawei Video Resource Center
AMS-IX & Huawei's OSN 902

3|24|17   |     |   (0) comments


Huawei shows how its OSN 902 platform helps the Amsterdam Internet exchange to connect the world using multiplexing.
LRTV Huawei Video Resource Center
Huawei's Smart Energy Innovation Center

3|24|17   |     |   (0) comments


In Nuremberg, Huawei showcases its latest capabilities in the digitalization of Internet resources, network infrastructure and intelligence at its Smart Energy Innovation Center.
Valley Wonk
OFC & Hyperscale: A Good Mix?

3|24|17   |   01:50   |   (0) comments


Cloud and telecom players want different types of equipment for their networks, as the chatter at OFC reveals.
LRTV Custom TV
Etisalat on NFV Journey

3|24|17   |   10:37   |   (0) comments


Etisalat is a service provider that prides itself on bringing innovative technologies to the markets it serves. It was one of the first operators to implement 3G and leads the pack in fiber penetration. Now, Esmaeel Al Hammadi, Etisalat's SVP of Network Development, explains the operator's journey to virtualization, beginning with the network core, as well as the ...
LRTV Huawei Video Resource Center
Huawei at CeBIT 2017: Day 3

3|22|17   |     |   (0) comments


Light Reading reports from CeBIT 2017 in Germany, where Huawei is exhibiting on the application of technologies and key business verticals such as transportation, smart city, manufacturing, media and finance.
LRTV Documentaries
No Regrets: Cox's Finkelstein on Fiber & More

3|22|17   |     |   (0) comments


At the Cable Next-Gen Technologies & Strategies event in Denver, Cox's Jeff Finkelstein examines the cable capex conundrum.
LRTV Documentaries
Cable Next-Gen: The 'Mile High' View From Denver

3|22|17   |   11:56   |   (0) comments


Alan Breznick kicks off the Cable Next-Gen Technologies & Strategies event in Denver, casting his thousand-yard stare over cable's current competitive landscape.
LRTV Huawei Video Resource Center
Huawei at CeBIT 2017: Day 2

3|21|17   |   2:27   |   (0) comments


Light Reading reports from CeBIT 2017 in Germany, where Huawei is exhibiting digital transformation solutions around IoT, smart data centers, OpenCloud ecosystem and its newly announced storage-as-a-service solution.
LRTV Custom TV
Driving Better Mobile Customer Experience While Transforming the Mobile Network

3|21|17   |   7:47   |   (0) comments


The Citrix NetScaler mobile gateway is an intelligent traffic management solution which can markedly improve the customer experience provided by mobile operators, even when traffic is encrypted. Critical network services can be consolidated and virtualized using NetScaler. Because of the unique architecture, NetScaler can be deployed on any hypervisor, on a ...
LRTV Custom TV
Mastercard: What's Next for Mobile Payments?

3|21|17   |   7:49   |   (0) comments


2017 marks the fifth consecutive year for Mastercard at Mobile World Congress and it was a great time to reflect on the amazing advances the payments industry has made as well as discuss "What's Next' in the digital commerce future. We spoke to James Anderson, executive vice president of digital payments at MasterCard, about digital wallets to tokenization to ...
LRTV Custom TV
Mastercard: 2 Billion Adults 'Trapped' in Cash Economy

3|21|17   |   03:51   |   (1) comment


Despite advances made in the last several years, two billion adults around the world are trapped in a cash economy and lack what we take for granted -- a safe way to receive, save and use money. Shamina Singh, executive vice president of sustainability and president of the Mastercard Center for Inclusive Growth, chats about how Mastercard is developing new ways to ...
Upcoming Live Events
May 15-17, 2017, Austin Convention Center, Austin, TX
May 15, 2017, Austin Convention Center - Austin, TX
June 6, 2017, The Joule Hotel, Dallas, TX
All Upcoming Live Events
Infographics
With the mobile ecosystem becoming increasingly vulnerable to security threats, AdaptiveMobile has laid out some of the key considerations for the wireless community.
Hot Topics
High-Band 5G: Let's Address the Range Question, Shall We?
Dan Jones, Mobile Editor, 3/21/2017
Eurobites: A1, Nokia Turn It Up to 11
Paul Rainford, Assistant Editor, Europe, 3/22/2017
FTTH No Slam Dunk for Cable
Carol Wilson, Editor-at-large, 3/23/2017
Top Priorities for B/OSS Transformation
James Crawshaw, Senior Analyst – OSS/BSS Transformation, Heavy Reading, 3/20/2017
Like Us on Facebook
Twitter Feed
BETWEEN THE CEOs - Executive Interviews
TEOCO Founder and CEO Atul Jain talks to Light Reading Founder and CEO Steve Saunders about the challenges around cost control and service monetization in the mobile and IoT sectors.
At MWC 2017, Qualcomm's CTO Matt Grob talks to Light Reading's CEO and Founder Steve Saunders about the progress being made in the development of the technologies and standards that will underpin 5G.
Animals with Phones
Neither Do We Click Here
Is that a prerequisite?
Live Digital Audio

Playing it safe can only get you so far. Sometimes the biggest bets have the biggest payouts, and that is true in your career as well. For this radio show, Caroline Chan, general manager of the 5G Infrastructure Division of the Network Platform Group at Intel, will share her own personal story of how she successfully took big bets to build a successful career, as well as offer advice on how you can do the same. We’ll cover everything from how to overcome fear and manage risk, how to be prepared for where technology is going in the future and how to structure your career in a way to ensure you keep progressing. Chan, a seasoned telecom veteran and effective risk taker herself, will also leave plenty of time to answer all your questions live on the air.