ENISA ,secure electronic communication and electronic communications services. It thus attempts to contribute to reducing the risks that European fixed and mobile networks faced in 2013, after finding that providers increasingly rely on the provision of services on behalf of third parties.
The European Network and Information Security Agency (ENISA) is publishing two reports today:
a) the report "Secure Procurement for Secure Electronic Communications", which highlights the increasing dependence of providers on ICT products and outsourced services, while also analysing the associated security risks posed by this process.
b) the "Guide to Secure ICT Contracting for Electronic Communications Service Providers", the aim of which is to serve as a practical tool for providers to better address security risks when dealing with sellers and suppliers of ICT products and services.
The report entitled "Secure ICT Procurement for Secure Electronic Communications" follows the latest edition of the Annual Incident Report, which provides a consolidated analysis of security incidents leading to serious disruptions, primarily caused by third-party ICT products and outsourced services, especially in the area of hardware failures and software code errors.
This year's report is the result of ENISA's collaboration with providers and vendors, in an effort to address these issues.
The main issues raised by electronic communications providers include:
- The lack of security checks on the part of the seller
- Software vulnerabilities in ICT products or services
- Non-compliance with the security requirements of the contracts
- Lack of support from vendors in case of incidents
- The low bargaining power of providers
- The lack of framework or guidance for providers when contracting and outsourcing
In this context, ENISA provides general recommendations and includes the results of a survey it conducted among electronic communications providers and ICT vendors. The recommendations to Member States include raising awareness of the security risks associated with the procurement of ICT products and outsourced services. Furthermore, vendors and providers are encouraged to develop a collaborative approach in relation to the definition of security requirements, the exchange of information on vulnerabilities and security threats, and the mitigation of incidents.
Guide to secure ICT contracting for electronic communications service providers
The Guide maps security risks to the full framework of security requirements that can be used by vendors as a tool when contracting, while examining security risks for core services in communications networks and services.
Professor Udo Helmbrecht, Executive Director of ENISA, commented: "Every year we see from the annual incident report that third-party managed ICT products and services are a major cause of disruption. A simple software code error can have a serious impact on the availability of internet and telephony services, and providers are not always able to resolve such issues quickly themselves. The Security Guide for ICT Procurement that we are publishing today is a practical tool that will help providers purchase ICT products and services from vendors and suppliers with the necessary security requirements.".
- The full reports are published at https://www.enisa.europa.eu/activities/Resilience-and-CIIP/Incidents-reporting/requirements-ecomms-vendors
