Signalling System No 7 (SS7) Introduction and state of play Lisbon, 8 March 2017
SS7: Introduction and state of play SS7 vulnerability Factual and legal background Signalling System #7: ITU standard (~1975) Reported vulnerabilities Legal background Framework Directive 2002/21 Proposed EECC rules
SS7: Introduction and state of play Main institutional actors National Regulatory Authorities (NRAs) Binding instructions Request for information Security audits Powers of investigation Commission Policy maker No supervisory/enforcement powers Implementing measures
SS7: Introduction and state of play Main institutional actors (2) Communications Committee (COCOM) Body of European Regulators for Electronic Communications (BEREC) Article 13a Working Group European Network and Information Security Agency (ENISA)
SS7: Introduction and state of play Some suggested themes for ensuing discussion What has been done in MS Industry perspective: measures taken to remedy Experience and action of MS authorities What else is needed? Short, medium long term perspective Next steps: the role of Article 13a Working Group, ENISA, the Commission and the industry
EECC – Security of Networks and Services Thank you!