Martin Euchner, Advisor, ITU-T Study Group 17

Slides:



Advertisements
Similar presentations
Committed to connecting the world Major issues related to working methods of ITU-T ITU Americas Region Preparatory Meeting Buenos Aires, Argentina,
Advertisements

ITU-T activity in ICT security
Summary of Actions ITU Regional Standardization Forum for Africa (Kampala, Uganda, June 2014)
Cloud computing security related works in ITU-T SG17
The 6th CJK IT Standards Meeting April 10 ~ 12, 2006, Hangzhou, China CJK IT Standards Meeting (Collaboration of Security Activity between CJK On NGN and.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ITU-T Identity Management Update Bilel Jamoussi, Chief, SGD/TSB ITU Abbie Barbir, Q10/17 Rapporteur.
Committed to Connecting the World International Telecommunication Union April 2015 Presentation of contributions to ITU-T SG17: GuidelinesITU-T SG17 Martin.
Geneva, Switzerland, 4 December 2014 ITU-T Study Group 17 activities in the context of digital financial services and inclusion: Security and Identity.
Geneva, Switzerland, 4 December 2014 ISO work on Mobile Financial Services Patrice Hertzog, Chairman, ISO T68/SC7 ITU Workshop.
Geneva, Switzerland, 4 December 2014 Evolving Payments into The Digital World Richard Smith, Vice President, MasterCard Customer Fraud Management
1 Overview of WTSA-12 Outcome Xiaoya Yang Head, WTSA Programmes Division ITU-TSB Joint ATU-ITU Seminar on WTSA-12 and WCIT-12 Outcome (Durban, South Africa,
DOCUMENT #:GSC15-GTSC-05 FOR:Presentation SOURCE:ITU-T AGENDA ITEM:4.1 NGN, Testing specification and Beyond Chaesub.
Africa's involvement in ITU-T Including Quality Aspects
ITU-T Focus Group on Digital Financial Services 1st Athens Digital Payments Summit Athens, Greece 30 September 2015 Hiroshi Ota, Study Group Advisor, ITU.
ITU Focus Group Digital Financial Services ITU Regional Standardization Forum for Americas (Washington D.C., United States, 21 September 2015) Vijay Mauree,
Geneva, Switzerland, April 2012 Introduction to session 7 - “Advancing e-health standards: Roles and responsibilities of stakeholders” ​ Marco Carugi.
ITU Overview Empowering global ICT development Malcolm Johnson DOCUMENT #:GSC13-XXXX-nn FOR:Presentation SOURCE:ITU AGENDA ITEM:Opening Plenary, 4.6 CONTACT(S):Malcolm.
Committed to Connecting the World ITU-T Cloud Computing standardization activities Dr Chaesub Lee, SG13 Chairman ITU Workshop on "Cloud Computing Standards.
Durban, South Africa, 8 July 2013 Outcome of WTSA-12 on spam Xiaoya Yang, Head, WTSA Programmes Division ITU-TSB ITU Workshop on “Countering.
AUB Department of Electrical and Computer Engineering Imad H. Elhajj American University of Beirut Electrical and Computer Engineering
Executive Summary on the First Meeting of ITU-T Study Group 20 “IoT and its applications including smart cities and communities (SC&C)” Meeting October.
Geneva, Switzerland, September 2014 ITU-T SG 17 Identity management (IdM) Progress Report Abbie Barbir Ph.D., ITU-T Study Group 17 Q10/17 (Identity.
ITU Workshop on “Voice and Video over LTE” Geneva, Switzerland, 1 December 2015 ACTIVITIES OF THE ITU-T SG11 TOWARDS IMS AND VoLTE/ViLTE INTEROPERABILITY.
International Telecommunication Union Accra, Ghana, June 2009 Telecommunication Security Standardization in ITU-T SG 17 Georges Sebek, ITU/TSB ITU.
Outputs from APT, RCC and Arab Regions WTSA preparatory events ITU Americas Region Preparatory Meeting Buenos Aires, Argentina, May 2012 Paolo Rosa.
The 6th CJK IT Standards Meeting April 10 ~ 12, 2006, Hangzhou, China CJK IT Standards Meeting (Collaboration of Security Activity between CJK On NGN and.
Jeju Island, Korea, 13 – 16 May 2013Identity Management and Identification Systems GSC17-PLEN-43 ITU-T IDENTITY MANAGEMENT UPDATE Bilel Jamoussi, Chief,
ITU - Empowering global ICT development Malcolm Johnson DOCUMENT #:GSC13-PLEN-44 FOR:Presentation SOURCE:ITU AGENDA ITEM:Opening Plenary, 4.6 CONTACT(S):Malcolm.
ITU-T Activities in Bridging The Standardization Gap Vijay Mauree Programme Coordinator, TSB ITU ITU Regional Standardization Forum for Asia-Pacific (Jakarta,
World Telecommunication Standardization Assembly (WTSA-08) DOCUMENT #:GSC13-XXXX-nn FOR:Presentation or Information SOURCE:ITU AGENDA ITEM:GTSC, 8.1 CONTACT(S):Malcolm.
Flavio Cucchietti 18 May 2016, Rome Chairman, WP2/20, ITU-T SG20 "IoT and its applications including smart cities and communities (SC&C)" Driving the Internet.
ITU-T SG17 Q.3 Telecommunication information security management An overview Miho Naganuma Q.3/17 Rapporteur 17 March 2016.
ITU-T SG17 Q.2 Security Architecture and Framework An overview for newcomers Patrick Mwesigwa Q.2/17 Rapporteur 15 March 2016.
World summit on the information society 1 WSIS: Building the Information Society: a global challenge in the new Millennium Tim Kelly, Claudia Sarrocco.
Overview of ITU, ITU-T and ITU-T Study Group 17 Odessa, Ukraine, June 2016 Martin Euchner Adviser, ITU-T ITU Regional Workshop for the CIS countries.
International Telecommunication Union ICT Security Role in National Trusted Identities Initiatives Abbie Barbir, PhD ITU-T Study Group 17 Identity Management.
Inter-American Telecommunication Commission
Updates: ITU-T Study Group 17 Standardization of “Security”
Inter-American Telecommunication Commission
ITU-T Study Group 17 Security
ITU Regional Standardization Forum For Arab Region SESSION 2 11:05-11:35 Overview of key documents and terms used in study groups and WTSA meetings.
Issues need harmonization
Preparation for World Telecommunication Standardization Assembly 2016
The ITU-T X.500 series and X.509 in a changing world
Tutorials of Q.8: cloud security related works in SG17
WTSA-12 Resolutions addressing security
WTSA-12 Resolutions addressing security
ITU-T STUDY GROUP 17 Security Heung-Youl Youm Arkadiy Kremer
Guidelines for Drafting WTSA Resolutions
ITU-T Study Group 17 Security
Ramy Ahmed Fathy ITU-T SG20 Vice Chairman
ITU an Overview Combined International SNO and 8th African SNO
The ITU-T SG 17 Q10/17 IdM standardization activity
Updates: ITU-T Study Group 17 Standardization of “Security”
WP2/17 (Cybersecurity) Chair of ITU-T SG17
Summary of Actions ITU Regional Standardization Forum for Africa
E-Commerce for Developing Countries (EC-DC)
ITU Overview Empowering global ICT development Malcolm Johnson
ITU Update since GSC-15 Bilel Jamoussi
Marco Carugi Senior Advisor – Nortel, Carrier Networks
ITU-T SG17 Q.3 Telecommunication information security management
ITU-T Study Group 17 Security
ITU-T Study Group 17 Security
Reinhard Scholl, GTSC-7 Chairman
Presentation of contributions to ITU-T SG17: Guidelines
ITU-T activity in ICT security
Updates: ITU-T Study Group 17 Standardization of “Security”
Standardization efforts at ITU for Inclusive ICT Society
Wayne Zeuch, GTSC-6 Chair Nicole Butler, ATIS Staff
Hans, KIM TTA Future of NGN Standards - FG NGN and SGs - Hans, KIM TTA
Presentation transcript:

Martin Euchner, Advisor, ITU-T Study Group 17 Martin.euchner@itu.int ITU Workshop on “Digital Financial Services and Financial Inclusion” ​Session 4: Security Issues in Digital Financial Services (Geneva, Switzerland, 4 December 2014) ITU-T Study Group 17 activities in the context of digital financial services and inclusion: Security and Identity Management 16:00 - 17:15​ ​Session 4: Security Issues in Digital Financial Services This session will consider the main security issues in digital finance especially with the increasing penetration of smartphones and apps. The sessions will also discuss technical measures and standards that can be implemented to overcome these issues and to ensure the security of financial transactions. Moderator: De Nederlandsche Bank (TBC) Speakers: Martin Euchner, ITU-T Study Group 17 Richard Smith, Head, Customer Security & Risk Services, MasterCard Europe Region Olutunmbi Idowu, Head of Compliance and Risk Control, Ericsson UK Martin Euchner, Advisor, ITU-T Study Group 17 Martin.euchner@itu.int Geneva, Switzerland, 4 December 2014

ITU-T SG17’s interests in FG-DFS Annex Contents ITU-T SG17 overview ITU-T SG17’s interests in FG-DFS Annex Selected ITU-T Recommendations for digital financial services and inclusion Geneva, Switzerland, 4 December 2014

ITU-T Study Group 17 mandate established by World Telecommunication Standardization Assembly (WTSA-12) Title: Security Responsible for building confidence and security in the use of information and communication technologies (ICTs). This includes studies relating to cybersecurity, security management, countering spam and identity management. It also includes security architecture and framework, protection of personally identifiable information, and security of applications and services for the Internet of things, smart grid, smartphone, IPTV, web services, social network, cloud computing, mobile financial system and telebiometrics. Also responsible for the application of open system communications including directory and object identifiers, and for technical languages, the method for their usage and other issues related to the software aspects of telecommunication systems, and for conformance testing to improve quality of Recommendations. Lead Study Group for: Security Identity management Languages and description techniques Responsible for specific E, F, X and Z series Recommendations Responsible for 12 Questions

ITU-T Study Group 17 Overview Primary focus is to build confidence and security in the use of Information and Communication Technologies (ICTs) Meets twice a year. Last meeting had 166 participants from 31 Member States, 17 Sector Members, 4 Associates, and 2 Academia. As of 17 November 2014, SG17 is responsible for 330 approved Recommendations, 22 approved Supplements and 3 approved Implementer’s Guides in the E, F, X and Z series. Large program of work: 26 new work items added to work program in 2014 Results of September 2014 meeting: approval of 1 Recommendation, 1 Amendment; 2 Supplements, 1 Recommendation in TAP; 3 Recommendations in AAP 89 new or revised Recommendations and other texts are under development for approval in April 2015 or later Work organized into 5 Working Parties with 12 Questions 4 Correspondence groups operating See SG17 web page for more information http://itu.int/ITU-T/studygroups/com17

Network and information security IdM + Cloud Computing Security ITU-T SG17, Security Study Group 17 WP 1/17 Fundamental security WP 2/17 Network and information security WP 3/17 IdM + Cloud Computing Security WP 4/17 Application security WP 5/17 Formal languages Q1/17 Telecom./ICT security coordination Q4/17 Cybersecurity Q8/17 Cloud Computing Security Q6/17 Ubiquitous services Q11/17 Directory, PKI, PMI, ODP, ASN.1, OID, OSI Q2/17 Security architecture and framework Q5/17 Countering spam Q10/17 IdM Q7/17 Applications Q12/17 Languages + Testing Q3/17 ISM Q9/17 Telebiometrics

SG17’s interests SG17 is pleased to cooperate with FG-DFS Find common language (across ICT, banking, telecommunication), start with by definitions and terms. Standardize security architecture for digital financial services. Overall objective is to provide confidence and security in the uses of ICTs to support financial services. SG17 is interested to receive requirements from FG-DFS on gap analysis, opportunities for new standards. Coordinate work with UPU Treat regulatory issues with care. Next SG17 meetings: 8 – 17 April 2015, 16 – 25 September 2015 Geneva, Switzerland, 4 December 2014

Annex Selected ITU-T Recommendations for digital financial services and inclusion Mobile security Security protocols Identity management Remote financial transactions Miscellaneous Geneva, Switzerland, 4 December 2014

Mobile security Recs. ITU-T X.1120-X.1139 X.1121: Framework of security technologies for mobile end-to-end data communications X.1122: Guideline for implementing secure mobile systems based on PKI X.1123: Differentiated security service for secure mobile end-to-end data communication X.1124: Authentication architecture for mobile end-to-end data communication X.1125: Correlative Reacting System in mobile data communication Geneva, Switzerland, 4 December 2014

Security protocols Recs. ITU-T X.1150-X.1159 X.1151: Guideline on secure password-based authentication protocol with key exchange X.1152: Secure end-to-end data communication techniques using trusted third party services X.1153: Management framework of a one time password- based authentication service X.1154: General framework of combined authentication on multiple identity service provider environments X.1156: Non-repudiation framework based on a one-time password X.1157 (draft): Technical capabilities of fraud detection and response for services with high assurance level requirements X.1158: Multi-factor authentication mechanisms using a mobile device X.1159: Delegated non-repudiation architecture based on ITU-T X.813 Geneva, Switzerland, 4 December 2014

Identity management Recs. ITU-T X.1250-X.1279 X.1250: Baseline capabilities for enhanced global identity management and interoperability X.1251: A framework for user control of digital identity X.1252: Baseline identity management terms and definitions X.1253: Security guidelines for identity management systems X.1254: Entity authentication assurance framework X.1255: Framework for discovery of identity management information (DOA can play a great role in payment processing security) X.1275: Guidelines on protection of personally identifiable information in the application of RFID technology Geneva, Switzerland, 4 December 2014

Remote financial transactions in NGN Recs. ITU-T Y.2740, Y.2741 Y.2740: Security requirements for mobile remote financial transactions in next generation network Y.2741: Architecture of secure mobile financial transactions in next generation networks Geneva, Switzerland, 4 December 2014

Miscellaneous Supplement 16 to ITU-T X.800-X.849 series: Supplement on architectural systems for security controls for preventing fraudulent activities in public carrier networks Supplement 19 to ITU-T X.1120-X.1139 series: Supplement on security aspects of smartphones Geneva, Switzerland, 4 December 2014

Reference links Webpage for ITU-T Study Group 17 http://itu.int/ITU-T/studygroups/com17 Webpage on ICT security standard roadmap http://itu.int/ITU-T/studygroups/com17/ict Webpage on ICT cybersecurity organizations http://itu.int/ITU-T/studygroups/com17/nfvo Webpage for JCA on identity management http://www.itu.int/en/ITU-T/jca/idm Webpage on lead study group on security http://itu.int/en/ITU-T/studygroups/com17/Pages/telesecurity.aspx Webpage on lead study group on identity management http://itu.int/en/ITU-T/studygroups/com17/Pages/idm.aspx Webpage on lead study group on languages and description techniques http://itu.int/en/ITU-T/studygroups/com17/Pages/ldt.aspx ITU Security Manual: Security in Telecommunications and Information Technology http://www.itu.int/pub/publications.aspx?lang=en&parent=T-HDB-SEC.05-2011