Defining measurements for analyzing information security risk reports in the telecommunications sector
Yves Le Bray, Nicolas Mayer, Jocelyn Aubert · 2016
It is clearly acknowledged that to consider an Information System (IS) as fully secure, although desirable, this is not achievable. In this context, risk management is becoming both a key aspect and the main trust vector which is particularly included in specific regulations. Our paper is in the context of the telecommunications sector and is about its regulation on security and integrity of networks and services. The objective is to establish a framework to analyse risk-related data collected by the National Regulatory Authority (NRA) through a standard approach they recommend to the Telecommunications Service Providers (TSPs). Our research results are, first, the establishment of the measurement types expected and the definition of a measurement template used as the standard format to define a measurement. Second, we propose a set of measurements to assess the collected, risk-related data, and thus the trust the NRA can have both in a TSP and the entire telecommunications sector. Finally, these measurements are implemented in a tool to be used by the NRA.