Signalling System No 7 (SS 7) I ntroduction and state of play Lisbon, 8 March 2017
SS 7: Introduction and state of play SS 7 vulnerability Factual and legal background • Signalling System #7: ITU standard (~1975) • Reported vulnerabilities • Legal background • Framework Directive 2002/21 • Proposed EECC rules
SS 7: Introduction and state of play Main institutional actors • National Regulatory Authorities (NRAs) • Binding instructions • Request for information • Security audits • Powers of investigation • Commission • Policy maker • No supervisory/enforcement powers • Implementing measures
SS 7: Introduction and state of play Main institutional actors (2) • Communications Committee (COCOM) • Body of European Regulators for Electronic Communications (BEREC) • Article 13 a Working Group • European Network and Information Security Agency (ENISA)
SS 7: Introduction and state of play Some suggested themes for ensuing discussion • What has been done in MS • Industry perspective: measures taken to remedy • Experience and action of MS authorities • What else is needed? Short, medium long term perspective • Next steps: the role of Article 13 a Working Group, ENISA, the Commission and the industry
EECC – Security of Networks and Services Thank you! DRAFT 6