Ofcom releases network security guidance

From: Eversheds

On 8 August 2014, Ofcom published new guidance on how communication service and network providers should comply with the security measures brought into force in the UK, following revisions to the Communications Act 2003 (“CA 2003”) (made in response to changes to the European Communications Regulatory Framework). The new guidance replaces the previous guidance published by Ofcom in May 2011.

Historically, the security and reliability of networks and services were not fully addressed and formally regulated. However, on 25 May 2011, sections 105A – D were incorporated into CA 2003 (the “Network Security Requirements”), which imposed specific security and reliability requirements on providers of public communications networks and service (“CPs”). While Ofcom quickly released guidance in the same month, it has long been considered that an update would be required, due to the rapid growth and importance of communications networks and services (particularly with respect to online banking and shopping) and the accordingly increasing concerns around cyber security (as recently highlighted by the nude celebrity scandal).

Notification

Much of the focus on Ofcom’s latest guidance will relate to the obligations to notify Ofcom of a security breach. The Network Security Requirements specifically provided that CPs must notify Ofcom where there is “a breach of security which has a significant impact on the operation of a public electronic communications [network]/[service]”. However the Network Security Requirements do not specify a time frame in which such notice should be given.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *