Service

+
:::
HomeServiceICT Tech Think TankICT Cyber Security Think Tank
Go back Print

ICT Cyber Security Think Tank

Published: Source: TTC
Share: FB line

Research on Communication Equipment for Critical Telecommunications Infrastructure and Communication Network Users’ Terminal Security Technical Specifications, Guidelines and Industry Standards

The network facilities provided by communication operators (including mobile communication, fixed-line communication, and communication network) network facilities are an important foundation for the development of digital convergence and Internet of Things (IoT), including digital service convergence among telecommunications, broadcasting, media, and information technology in close connection with all consumers who rely on communication networks for digital applications. However, the increasing complicated information security threat from cyberattacks, cyber espionage, and hackers brings a huge impact to the digital economy in daily society. In order to cope with information security issues from these emerging trends, TTC gradually assists the NCC in formulating IoT/communication equipment technical specifications, guidelines, and industry-standard as baselines of information security testing as well as product security by design.

Item

Technical Specifications

1

Technical specifications for security testing of information and communication equipment for critical telecommunications infrastructure: routers, switches and firewalls

Item

Technical guidelines

1

Technical guidelines for communication security testing on Wireless Local Area Network(WLAN) access and routing equipment

2

Technical guidelines for communication security testing on internet-connected fixed multimedia content delivery platform and cable broadcast TV set-up box information communication 

3

Technical guidelines for communication security testing on mobile communication repeater

Item

Industry standard

1

  • Infocom security test specification of embedded software on smartphone systems
  • Infocom security standard of embedded software on smartphone systems 

2

  • Cybersecurity standard for smart speakers
  • Cybersecurity test specification for smart speakers

3

  • Cybersecurity standard for consumer IoT products
  • Cybersecurity test specification for consumer IoT products

4

  • Cybersecurity test specification for wireless broadband routers
  • Cybersecurity standard for wireless broadband routers
 

5G Network Complete Information Security Protection to Guard Consumer Rights

5G network as the country’s key infrastructure is essential foundation of implementation towards digital country, digital economy, industry transformation and smart society. To comply with diversified applications, 5G network’s open architecture on service basis is expected to be expanded rapidly and flexibly; however, the derivative threats to information security are more than the past. With consideration of 5G technical evolution and operators’ implementation schedule, TTC continues to facilitate the NCC on regulatory rolling adjustment and regulatory completion as clear definition of information security obligations to 5G players, in addition, make regulation feasibility validation and assist operators to complete 5G network information security protection with 5G network information security laboratory establishment.

To ensure the country’s security, reliability and resilience at 5G network, TTC has successively assisted the NCC in formulating the fifth-generation mobile communication system information security maintenance plan reference framework, examination guidelines, audit plans and standard operating procedures for confirmation on the security maintenance plan’s appropriateness, feasibility and implementability of the telecommunications industry.  At the same time, TTC’s solution or mitigation proposals, based on analytic research of global organizations/major countries’5G cyber security threats and implementation at laboratory, are to facilitate operators’5G network security uplift, protect consumer rights and further to develop vertical application fields and related innovative application services.