양 수 미양 수 미. 차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준  기타 내용.

Slides:



Advertisements
Similar presentations
ICT research priorities and recommendations for strategy development in the WBC Ulrike Kunze / PT-DLR, Germany Consultation session on recommendations.
Advertisements

Cloud computing security related works in ITU-T SG17
Interoperability Roadmap Comments Sections E, F, and G Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March 11, 2015.
Conformity Assessment Practical Implications InterAgency Committee on Standards Policy June 2007 Gordon Gillerman Conformity Assessment Advisor Homeland.
Chapter 1 1.  Introduction to Networking  Fundamental Network Characteristics  Type and Sizes of Networks  Network Performance issues and Concepts.
양 수 미양 수 미. 차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준  기타 내용.
Security Controls – What Works
Chapter 1 – Introduction
Update on Interoperability Roadmap Comments Sections E, F, and G Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March.
GSC16-OBS-03 ITU-T GSC – 16 Observer Presentation Karen Higginbottom, JTC 1 Chair.
EEC-484/584 Computer Networks Lecture 3 Wenbing Zhao
ISO 17799: Standard for Security Ellie Myler & George Broadbent, The Information Management Journal, Nov/Dec ‘06 Presented by Bhavana Reshaboina.
Networking Standards. Objectives Identify organizations that set standards for networking.
Geneva, Switzerland, 4 December 2014 ITU-T Study Group 17 activities in the context of digital financial services and inclusion: Security and Identity.
Networking standards organizations. Objectives Identify networking standards organizations Describe the functions of the principal networking standards.
Standards for Shared ICT Jeju, 13 – 16 May 2013 Gale Lightfoot Senior Staff Program Manager, Office of the CTO, SPB Cisco ATIS Cybersecurity Standards.
Management of the Internet
1 CS 4396 Computer Networks Lab The Internet. 2 A Definition On October 24, 1995, the FNC unanimously passed a resolution defining the term Internet.
Giandonato CAGGIANO ENISA MANAGEMENT BOARD REPRESENTATIVE LEGAL ADVISER ON EUROPEAN AFFAIRS OF THE MINISTRY OF COMMUNICATIONS U. OF ROMA TRE LAW FACULTY.
Evolving IT Framework Standards (Compliance and IT)
양 수 미양 수 미. 차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준.
Business Data Communications, Fourth Edition Chapter 1: Introduction to Communications.
Chapter 1 1.  Introduction to Networking  Fundamental Network Characteristics  Type and Sizes of Networks  Network Performance issues and Concepts.
Update on Interoperability Roadmap Comments Sections G, F and E Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March.
Standards and innovation What is a standard? How do standards promote innovation? What is the role of governments and the UN?
©Richard L. Goldman Regulatory & Standards Organizations ©Richard Goldman December 19, 2001.
STANDARDS OVERVIEW Wednesday, April 30, 2015 KAREN RECZEK, STANDARDS COORDINATION OFFICE, NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
Proposal for device identification PAR. Scope Unique per-device identifiers (DevID) Method or methods for authenticating that device is bound to that.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All SMART GRID ICT: SECURITY, INTEROPERABILITY & NEXT STEPS John O’Neill, Senior Project Manager CSA.
INTRODUCTION. A Communications Model Source –generates data to be transmitted Transmitter –Converts data into transmittable signals Transmission System.
Technical Education Click here to move on Index H.323 Related Standards Lesson 4.
Network Standards By Rashid Amin. “A standard provides a model for development that makes it possible for a product to work regardless of the individual.
McGraw-Hill©The McGraw-Hill Companies, Inc., 2004 Overview of Data Communications and Networking PART I.
1 Network Model. 1-2 Divide and Conquer A method of managing large system.
Network Standards ISQS 3349/6341. The Importance of Standards Ensure that hardware and software produced by different vendors can work together. Makes.
GSC-19 Meeting, July 2015, Geneva Guest Presentation by ISO and IEC Henry Cuschieri, ISO Gilles Thonet, IEC Jim MacFie, JTC 1 Document No:GSC-19_009.
Chapter 4Industrial Standards  4.0Introduction to Standards 4.0Introduction to Standards 4.0Introduction to Standards  4.1Standards Organisations in.
AUB Department of Electrical and Computer Engineering Imad H. Elhajj American University of Beirut Electrical and Computer Engineering
Standards in Telecommunications n Origin of standards – Standard setting bodies – Governments n Rationale – Market-driven and voluntary – Government-regulated.
1 Chapters 2 & 3 Computer Networking Review – The TCP/IP Protocol Architecture.
TCP/IP Protocol Suite 1 Chapter 1 Objectives Upon completion you will be able to: Introduction Understand the history of the Internet Understand the meaning.
Internet and Intranet Fundamentals Class 3 Session B.
When we communicate, we are sharing information. This sharing can be local or remote. Between individuals, local communication usually occurs face to face,
ISA99 - Industrial Automation and Controls Systems Security
Jeju Island, Korea, 13 – 16 May 2013Identity Management and Identification Systems GSC17-PLEN-43 ITU-T IDENTITY MANAGEMENT UPDATE Bilel Jamoussi, Chief,
Chapter 1 The Data Communication Industry The best way to approach data communication The data communication industry Challenge & solution to business-oriented.
1 Network Security: Introduction Behzad Akbari Fall 2009 In the Name of the Most High.
ITU Regional Standardization Forum for Asia-Pacific (Jakarta, Indonesia, October 2015) TELECOMMUNICATION STANDARDIZATION IN INDONESIA Mochamad Hadiyana.
Information Security tools for records managers Frank Rankin.
Federal Department of Environment, Transport Energy and Communications UVEK Federal Office of Communications OFCOM Telecom/FG, Fix Network and Universal.
SMART GRID Standardization and Implementation Experience Narendra Singh Head (Electronics and IT) Bureau of Indian Standards.
1 Mi-Jung Choi Dept. of Computer Science and Engineering Chapter 1 Introduction Chapter 1 Introduction.
Models of Security Management Matt Cupp. Overview What is Security Management? What is Security Management? ISO/IEC ISO/IEC NIST Special Publication.
ITU-T SG17 Q.3 Telecommunication information security management An overview Miho Naganuma Q.3/17 Rapporteur 17 March 2016.
Standards Certification Education & Training Publishing Conferences & Exhibits 1 Copyright © ISA, All Rights reserved ISA99 - Industrial Automation and.
Standards in Telecommunications
Standards and Standards Bodies
Chapter 1 Introduction.
Chapter 1 Introduction.
HIS Smart Grid – Summary (1)
The Role of European Standards in Support of the Cybersecurity Act
DATA COMMUNICATION Lecture-4.
ITU-T SG17 Q.3 Telecommunication information security management
Chapter 1 Introduction.
ITU-T Study Group 17 Security
Martin Euchner, Advisor, ITU-T Study Group 17
Introduction Prof. Choong Seon HONG.
Conformity Assessment Approach for Homeland Security
ITU-T activity in ICT security
Presentation transcript:

양 수 미양 수 미

차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준  기타 내용

IETF 표준  IETF (Internet Engineering Task Force) 의 I ESG (Internet Engineering Steering Group) 내의 Security Area 에서 제정한 표준들로 여 러 Working Group 에서 연구 / 제정된다.  It is established to support internet protocol engineering and development tool at 1986 under the ISOC( internet society).

 IETF (Internet Engineering Task Force) 의 주요한 목표는 인터넷의 운영상, 기술상의 문제점을 해결하기 위 하여 프로토콜 및 구조에 대한 표준을 제안하고 개발 하는 것

Henric Johnson 5 Internet standards and RFCs  The Internet society  IAB (Internet Architecture Board) : responsible for defining the overall architecture of the Internet, providing guidance and broad direction to the IETF  IETF (Internet Engineering Task Force) : The protocol engineering and development arm of the Internet, 비영리 단체인 IAB(Internet Archetecture Board) 의 하위 조직. TCP/IP 와 인 터넷에 관한 정책과 표준안 작성을 담당  IESG (Internet Engineering Steering Group) : responsible for technical management of IETF activities and the Internet standards process

IETF 표준화 과정  Standard development stages  Internet drafts : they are on working documents for RFC(request for comments), register on directory during 6M.  Proposed standard : implement and test protocol( 6M-2Y)  Draft standard : at least 2 independent and interoperated products, need more field test on different wide environments( 4M-2Y)  Internet standard : successfully implemented operated protocol

IETF Working Groups(Active)  APPLICATIONS  INTERNET  OPERATIONS and MANAGEMENT  REAL-TIME APPLICATIONS and INFRAS TRUCTURE  ROUTING  SECURITY  TRANSPORT

Security area Working Groups  abfabApplication Bridging for Federated Access Beyond web  daneDNS-based Authentication of Names Entities  emuEAP(Extensible Authentication Protocol) Method Update  ipsecmeIP Security Maintenance and Extensions  joseJavascript Object Signing and Encryption  keyprovProvisioning of Symmetric Keys

Security area Working Groups  kittenCommon Authentication Technology Next Generation  krb-wgKerberos  mileManaged Incident Lightweight Exchange  neaNetwork Endpoint Assessment  oauthWeb Authorization Protocol  pkixPublic-Key Infrastructure (X.509)  tlsTransport Layer Security

차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준  기타 내용

ISO/IEC JTC1 표준  ISO ( International Organizaton for Standardization )/ IEC ( International Electronical Commission ) JTC ( Joint Technical Committee ) 1  A combined organization ( ISO/TC97 : information processing system fields and IEC/TC 83 : information equipments)  정보처리시스템에 대한 국제표준화 활동과 정보기기에 대한 국제표준화 활동을 통합하여 구성된 정보기술분야의 국제표준화 활동을 위한 공동기술위원회  SC20( data cryptographic techniques) was expended into SC27( security techniques).

ISO/IEC JTC1 표준  Standard development stages  Preliminary stage : preliminary work item (PWI)  Proposal stage : new work item proposal ( NP)  Preparatory stage : working drafts (WD)  Committee stage : committee drafts (CD)  Enquire stage : enquire drafts i.e. draft international standard (ISO) (DIS), committee draft for vote(IEC) (CDV)  Approval stage : final draft international standard (FDIS)  Publication stage : international standard(ISO,IEC,ISO/IEC)

ISO/IEC JTC1 표준  SC27 : IT Security techniques  IT 보안에 관한 일반적인 방법과 기술에 대한 표준을 주로 연구 / 제정한다.  응용에 보안 메커니즘을 삽입하는 것을 제외한 정보기 술 보안을 위한 일반적 방법과 기술에 대한 표준화  암호화 알고리즘의 표준화, 정보기술 시스템 보안 서비 스를 위한 일반적 요구 명세, 보안 기술 및 메커니즘 개 발, 문서 및 표준을 지원하는 관리 개발을 포함  SC27 이외

ISO/IEC :2004  Information technology -- Security techniques -- Management of information and communications technology security -- Part 1: Concepts and models for information and communications technology security management  ISO/IEC :2004 presents the concepts and models fundamental to a basic understanding of ICT security, and addresses the general management issues that are essential to the successful planning, implementation and operation of ICT security. Part 2 of ISO/IEC (currently 2nd WD) provides operational guidance on ICT security. Together these parts can be used to help identify and manage all aspects of ICT security.

ISO/IEC 27002:2005(2007)  BS 7799:1999 으로부터 발전 -> >  12 main sections  Risk assessment  Security policy - management direction  Organization of information security - governance of information security  Asset management - inventory and classification of information assets  Human resources security - security aspects for employees joining, moving and leaving an organization  Physical and environmental security - protection of the computer facilities  Communications and operations management - management of technical security controls in systems and networks  Access control - restriction of access rights to networks, systems, applications, functions and data  Information systems acquisition, development and maintenance - building security into applications  Information security incident management - anticipating and responding appropriately to information security breaches  Business continuity management - protecting, maintaining and recovering business-critical processes and systems  Compliance - ensuring conformance with information security policies, standards, laws and regulations

차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준  기타 내용

ITU-T 표준  ITU-T (International Telecommunication Union-Telec ommunication Standardization Sector) 통신표준을 정했던 국제적인 기관인 CCITT (Consultative Committee for International Telegraph and Telephone) 가 개칭한 단체. 디지털전송을 위한 표준과 아날로 그 전송을 위한 인터페이스 표준을 정의

ITU-T 표준  SG 2, 3, 5, 9, 11, 12, 13, 15, 16, 17, TSAG(Telecommunication Standardization Advisory Group)  SG 17 : Security [, languages and telecommunication software]  국내에서는 한국정보통신기술협회 (TTA : Telecommunication Technology Association) : 민 간단체 성격의 정보통신표준제정기관이 담당  TC10 : security committee( IT security management, crypto technology, system security group)

 WP 1/17 Network and information security  Q1/17 Telecommunications systems security project  Q2/17 Security architecture and framework  Q3/17 Telecommunications information security management  Q4/17 Cybersecurity  Q5/17 Countering spam by technical means  WP 2/17 Application security  Q6/17 Security aspects of ubiquitous telecommunication services  Q7/17 Secure application services  Q8/17 Cloud computing security  Q9/17 Telebiometrics  WP 3/17 Identity management and languages  Q10/17 Identity management architecture and mechanisms  Q11/17 Directory services, Directory systems, and public-key/attribute certificates  Q12/17 Abstract Syntax Notation One (ASN.1), Object Identifiers (OIDs) and associated registration  Q13/17 Formal languages and telecommunication software  Q14/17 Testing languages, methodologies and framework  Q15/17 Open Systems Interconnection (OSI)

ITU-T SG17 주요 내용

차례  IETF 표준  ISO/IEC JTC1 표준  SC27  SC27 이외  ITU-T 표준  기타 내용

기타 표준화기구 ECMA (European computer manufacturers association)  establish for data processing standard in Europe at 1961  TC 17( include communication), TC 36(IT security).TC 32( communication, network and interoperability, security) ETSI (European telecommunication standards institute)  establish for communication/information/broadcasting standards in Europe at 1988  Standard process  Inception : start development of standard  Conception : define concept  Drafting : propose standard  Adoption ; adopt standard  Promotion ; implement standard  TC sec is security standard technical committee -> OGG(Operational Co-ordination Group)

기타 인터넷보안기술포럼 (ISTF : Information Security Technology Forum) : 인터넷 보안기술분야의 민간업체들이 중심이 되어 구성된 포럼으로 시장수요를 반영한 사실 (de-facto) 표준을 개발  Establish at 2000 for public internet security standard  Network, PKI, mobile group.

NIST  NIST (National Institute of Standards and Technology)  To establish at 1901, named NBS(national bureau of standards) and then renamed NIST at 1988 under DoC(Department of Commerce).  10 research laboratories  Building and fire research Chemical science and technology Electronics and electrical engineering Information technology Manufacturing engineering Materials science and engineering Nanoscale science and technology Neutron research Physics Technology services Building and fire research Chemical science and technology Electronics and electrical engineering Information technology Manufacturing engineering Materials science and engineering Nanoscale science and technology Neutron research Physics Technology services

NIST  information technology lab. : 6 research areas  Advanced Network Technologies  Computer Security  Information Access  Mathematical & Computational Sciences  Software & Systems  Statistical Engineering

NIST  암호화 기술  첨단 인증 기술  공개키 기반 구조  인터네트워킹 보안  평가 기준 및 제도  보안 관리 및 지원  컴퓨터 보안 자원 정보 센터

ANSI  ANSI (American national standards institute)  To establish a non-profit organization at  Have three characteristics : don’t develop standards, ANS is used all industries, ANS is voluntary.  Major fields : all technical fields ( accreditation 인정서, patent,etc) contribute ISO, IEC ANSI certifies other standard organizations of USA

KATS

43