Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Tuesday, June 27, 2023
Managing risk appropriately requires a risk-benefit analysis incorporating both the risk environment and the costs of government and private intervention.
FREMONT, CA: The global ICT ecosystem faces many challenges, including hardware, software, and network vulnerabilities. Although actors' capabilities are clear, their intentions are often unclear, so national security issues often need clarification with economic competitiveness concerns.
Certain solutions could improve network and ICT security holistically.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Network and ICT security improvements: Apply universal standards to the telecommunications industry. It is common for industry players to have standards for 5G and conformance programs geared toward the risks associated with telecom equipment. Operators can use these standards and recommended risk-mitigative measures to evaluate equipment (and software updates) before deployment and manage risks accordingly. The Cybersecurity Framework has been developed as part of the US National Institute of Standards and Technology (NIST). Organizations can customize this risk-analytic tool to align with their mission and risk posture with assistance from the Department of Commerce, the private sector, and government experts.
Implement technical risk assessments and risk mitigation: It is possible to assess and mitigate risk using various models. Security by design is a well-known approach that builds security features into software from the beginning instead of at the end. Regular testing of maintenance procedures ensures that no malicious code is inserted into software solutions at the time of initial delivery or after updates or maintenance are performed.
Trusted delivery mechanisms can support Independent third-party hardware, software, and firmware reviews. As a result of third-party evaluators' reviews, mobile network operators can reasonably ensure that the vendor has delivered the same software and hardware as the third-party evaluator. Additionally, they can prevent vendors from delivering software updates directly to wireless carriers without undergoing independent testing and review.
Participation in global standards-setting organizations: In addition to the technical standards governing network performance and network security, the US can and should participate more in the 5G standards-setting process. According to the Commerce Department, international standards help ensure that 5G networks, autonomous vehicles, artificial intelligence, and other cutting-edge technologies are interoperable and secure. It would be beneficial if the US government and private experts participated more actively in telecom standard-setting organizations.
The US and every government worldwide must fully commit to a zero-trust strategy. Zero-trust approaches recognize the need to scrutinize trusted suppliers just as closely as untrusted ones, given the capability of malicious cyber actors.
More in News