Light Reading

Putting a Dollar Sign on Network Security

Carol Wilson

ORLANDO -- Management World Americas -- Wouldn't you think network service contracts would include security requirements?

It may seem like a no-brainer, but most contracts are built around availability and performance, not security. One of the more intriguing TM Forum Catalyst Projects on display here this week is aimed at helping enterprises and governments create contract terms that build in security requirements.

The idea is to create financial incentives to improve security. As network threats become more sophisticated -– most are currently the work of organized crime –- enterprises and governments want more assurance that network operators are working on the problem. The move to cloud services can make it even harder for enterprises and governments to easily track where their applications and data are, and if they are secure, according to Martin Huddleston of the U.K. Defence Science and Technology Lab, which is a participant in the Catalyst.

The key, being pursued in the Catalyst, is to find metrics and targets for the level of security. According to the other participants in the project, including CA Technologies (Nasdaq: CA), McAfee Inc. (NYSE: MFE) and Sooth Technology , the early metrics will be based on well-defined mitigations already established by the computer emergency response teams (CERTs) that operate in most countries. (Common CERTs include the Defence Signals Directorate of the Australian government, the National Institute of Science and Technology and the SANS Institute Top 20 in the United States. Verizon Enterprise Solutions 's annual Security Breach Report is another source of key mitigation data.)

Just implementing CERTs's basic advice could prevent 85 percent of security breaches, says Christy Coffey, the Government/Defense Market Support Center Head for TMForum. These "low-hanging fruit" include implementing patches for operating systems and applications; practicing mobile device management; improving training to reduce human errors; implementing defenses against denial of service attacks; and hardening servers to prevent data leakage.

Take patch management as an example. Contracts could require the network operator to document the time of exposure; the percentage of devices patched and the degree to which they have been patched; the criticality of patch exposure; the audited degree of systems that are susceptible to attack; the percentage of patches resulting in further problems; and the number of patches.

To date, the Catalyst has shown it is possible to monitor almost all of those things; the one that's been elusive to measure is the audited degree of systems that are susceptible to attack. That's basically an identification of those systems which aren't vulnerable and therefore don't require the same vigilance about patching.

All that detail would give enterprises or governments more confidence in the networks they are using. In the future, the data could be collected and benchmarked to establish industry standards, says Coffey.

If the telecom industry doesn't create ways of quantifying network security and building it into contracts, there is the possibility governments will choose to impose some tighter restrictions, to prevent the negative economic impact of continued security breaches, say the Catalyst participants.

— Carol Wilson, Chief Editor, Events, Light Reading

(0)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Educational Resources
sponsor supplied content
Educational Resources Archive
From The Founder
The comms industry is rallying to the cause of open, independent interoperability testing.
Flash Poll
Live Streaming Video
CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
Telecom Innovators Video Showcase
Tail-f, Cisco & What the Future Holds

10|9|15   |   8:17   |   (0) comments

Steve Saunders meets with Tail-f's Director of Technology, Carl Moberg, in Stockholm to discuss becoming part of Cisco, ETSI MANO, virtualization and the need to combine science and business in order to create opportunities for service providers.
LRTV Interviews
Broadband Forum Embraces SDN & NFV

10|9|15   |   02:42   |   (0) comments

At Gigabit Europe 2015, Robin Mersh and Kevin Foster from the Broadband Forum explain how the industry body is adapting to meet the SDN, NFV and cloud needs of the access network sector.
LRTV Interviews
Top Tips for FTTH Operators

10|8|15   |   02:26   |   (0) comments

At Gigabit Europe 2015, Ventura Team co-founder Richard Jones talks about some of the key business case considerations for FTTH network operators.
LRTV Interviews
M-net Calls for FTTx Unity

10|8|15   |   03:45   |   (0) comments

At the Gigabit Europe event, Jörn Schoof from M-net, the Munich city network operator, calls for industry collaboration on fiber broadband access rollouts.
LRTV Documentaries
The Business Case Challenge for NFV

10|7|15   |   03:47   |   (0) comments

Virtual CPE is one of the early success stories for network functions virtualization, as service providers are finding flexible, programmable CPE solves a lot of logistics problems and reduces their cost. But even here, Masergy Communications faced a business case challenge, says CTO Tim Naramore.
LRTV Interviews
JT Offers Some Gigabit Lessons

10|7|15   |   4:08   |   (1) comment

Barna Kutvolgyi, managing director, Global Consumer, at JT, the incumbent operator on the island of Jersey, talks about how other service providers can learn from his company's gigabit broadband rollout experiences.
LRTV Interviews
AT&T's Chiosi on the Potential of Open Source

10|6|15   |   06:27   |   (0) comments

AT&T Distinguished Network Architect Margaret T. Chiosi talks to Light Reading's Carol Wilson about the potential for open source technology to liberate communications service providers.
LRTV Interviews
Network Security in a Gigabit World

10|6|15   |   05:52   |   (0) comments

Masergy's James Harrison talks about some of the network security and data center issues network operators need to consider as they expand their broadband services portfolios.
LRTV Documentaries
Telefónica: In Search of Virtual Simplicity

10|5|15   |   07:30   |   (0) comments

Francisco-Javier Ramon Salguero, head of Telefónica's NFV initiative, admits virtualization initially means greater complexity, but with the right abstraction layer, it is possible to create a services-driven network architecture. He explains how Telefónica's current trials and initiatives are aimed at doing that, and what his company and other carriers need to ...
LRTV Interviews
Gigabit Europe Takeaways

10|5|15   |   03:47   |   (0) comments

Participants from the inaugural Gigabit Europe event in Munich share their key takeaways from the conference.
Women in Comms Introduction Videos
Intel Urges Women to Take Advantage of Their Seat at the Table

10|5|15   |   4:27   |   (1) comment

Have inclusive and constructive conversations, attach a bigger meaning to your work and get involved in the cause, Intel's Monique Hayward advises women in comms.
LRTV Interviews
BT Updates on Plans

10|2|15   |   03:16   |   (2) comments

Peter Bell, CIO at Openreach, the access network division at UK incumbent BT, provides an update on the operator's trials and how Openreach is planning to deploy the broadband technology in its street cabinets.
Upcoming Live Events
October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
November 5, 2015, Hilton Santa Clara, Santa Clara, CA
November 17, 2015, Santa Clara, California
December 1, 2015, The Westin Times Square, New York City
December 2, 2015, The Westin Times Square, New York City
All Upcoming Live Events
Network appliances have a strong value proposition in today's networks and will continue to do so in the NFV and SDN-enabled networks of tomorrow.
Hot Topics
M&A Speculation Swirls Around Juniper
Ray Le Maistre, Editor-in-chief, 10/6/2015
Cisco's Chambers Rules Out Political Bid
Mitch Wagner, West Coast Bureau Chief, Light Reading, 10/6/2015
Cord Cutting? 'Fraid so.
Brett Sappington, 10/7/2015
Infinera Fleshes Out Its Metro 100G Story
Ray Le Maistre, Editor-in-chief, 10/7/2015
Cisco Makes 'Martian' Connection
Mitch Wagner, West Coast Bureau Chief, Light Reading, 10/9/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
With so many new and exciting communications technologies now under development, it's easy to get caught up in the industry's escalating hype cycle. That's why the ...
Last week saw a big day in the 15-year history of Light Reading when Editor-in-Chief Ray Le Maistre and I were invited to interview the Deputy Chairman and Rotating ...
Cats with Phones
"What?! I'm on with Finisar about their stock price tanking" Click Here