WPCy c E$f_ĩj˱HS=y1[:Hhhw'U6ckd3Fe.Zc {0aHXDLRzeXœe(Kl^RCiWDx:q U!^j\wbgRk]SOFU0"H *dN(G3 & PM_;[+/U0451)0XQL F038d,bJ4sZA]/& oеd> r,)\!@\J@UGoQ|z&SἃhԛOjG#__yM`*#x] 3%1k׺*T(y`N4e#YZs ( o#{hU. % 0 0 0zQ 0 0f  0E" 0>$ 08b 06U 4 0 S 0=d 0MF 05P 0 C7Mz 0  {-#;  B  D3 0 0Jf AM o @"$p%R5AEBDU0E@E 0RG7jGo$H@lU0llnl 0fn4boU:0voow@p AQp.q 0q 0Dvr D/r Brsst`u&vU0>vpnvrU0sstU0uuU06vfvU0twU4wwU0xxxxxxxxxxxxxxxxxxxxxxxyL  9`(CourierPB0HeadingChapter Heading  @..  2I.3  Ԁ   tO 4Right ParRight-Aligned Paragraph Numbers.. 2I.3  Ԁ  0..R& 8BibliogrphyBibliography0.. ..L=6SubheadingSubheading 2A.3  ..    x?ot2PleadingHeader for numbered pleading paper  z  (  'XXX6 '*d66 '*d6HH 1HH 2HH 3HH 4HH 5HH 6HH 7HH 8HH 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28  .+(Y2$ 3,w!5# 5XX5#   20level 0  20level 1 0.italic34 `TimesRoman '5Ch5X@X5Ch  5X5X@5TELECOMMUNICATIONSECURITYGUIDELINEFORTMN(Y2$ 3,w!5# 5XX5#   ($0 ($0 0 (($0 0 0 ($     C oV$5Ch5X@X5ChӀ  1    5h X5X@h  5h"NS/EPtelecommunicationsservicesaretelecommunicationsserviceswhichareusedtomaintainastateofreadinessortorespondtoand  manageanyeventorcrisis(local,national,international)whichcausesorcouldcauseinjuryorharmtothepopulation,damagetoorlossofpropertyordegradesorthreatenstheNS/EPpostureoftheUnitedStates"[19](k!2oV$ 3,w!5# 5XX5#   Ӏ  0    oV$5Ch5X@X5ChӀ  2    5h X5X@h  5hSeetheAppendixforadescriptionofaTMNarchitecture # oV$5Ch5X@X5ChӀ  3    5h X5X@h  5hAcrackerisacomputerhackerwhospecializesinovercomingsoftwareprotectionsystems.  oV$5Ch5X@X5ChӀ  4    5h X5X@h  5hTheCommonCriteriawillallowforthecreationofprotectionprofilesforgeneralpurpose,multiuseroperatingsystems,trusted  components,andsecuredistributedsystems.Itisanticipatedthattheseprofiles,oraversionthereof,willformthebasisformutualrecognitionofsystemevaluationsamongnations.  oV$5Ch5X@X5ChӀ  5    5h X5X@h  5hTheDepartmentofDefenseTrustedComputerSystemEvaluationCriteria(TCSEC)describescriteriaforspecifyingandevaluatingthetrust  ofoperatingsystems.Itiswidelyknownasthe"OrangeBook." 1 oV$5Ch5X@X5ChӀ  6    5h X5X@h  5hForsomeservices(e.g.,EmergencyServices)acustomermaynotneedtobeauthenticatedbythesystem.  oV$5Ch5X@X5ChӀ  7    5h X5X@h  5hInsomecircumstancesacustomercanalsoplaytheroleofadministrator,forexample,whenthecustomerhasaccesstooperations  informationthatwouldpermithimtoreconfigurehiscircuits.Someserviceprovidersofferthisservice,aswellasotherOAM&Pfeatures,tocustomersforafee. d'dxd Level 1 Level 2 Level 3 Level 4 Level 5(Y2$ 3,w!5# 5XX5#   ("$ Figure     !"A<< cWPC0*x'.13'Standard - Wide ,,51900L1 -* K-.2-OAM&P !;cVJ-.2-USER"" WoI0k"AArial BoldIxxxADMINISTRATOR #1 d-.2-SECURITYSYSTEM(CUSTOMER) $(%M-.2-SERVICE %p 'N-.2-CUSTOMER+ &_ _  '   (' -Zz )Zc  *  >  + V(  ,  ZT (X \$|$U$Yp$$#$&TSGCHART.WPGWPWin 6.0/OLE 1.0 Prefix Information MarkerWPDraw30.Drawingࡱ;  Root Entry`.@pp Ole 9WPG20CompObj^  !"#$%&'()*)F! WPWin61[1]ࡱWPC0*x'.13'Standard - Wide ,,51900L1 -* K-.2-OAM&P !;cVJ-.2-USER"" WoI0k"AArial BoldIxxxADMINISTRATOR #1 d-.2-SECURITYSYSTEM(CUSTOMER) $(%M-.2-SERVICE %p 'N-.2-CUSTOMER+ &_ _  '   (' -Zz )Zc  *  >  + V(  ,  ZT (X \$|$U$Yp$$# `.@pWP Draw 3.0 Drawing Embed SourceWPDraw30.Drawingࡱ; ,`pࡱ; LY~@ 4  ~@LY  qa&Arial,-- .  "System-BOlePartOlePres000-2 dOAM&P! -- .  -- 2 6USER6-&Arial +-- .  --2 IO ADMINISTRATOR  I-&Arial*-- .  --42 !SECURITY SYSTEM (CUSTOMER) -- .  --2 USERVICE -- .  --2 HFCUSTOMER!H*--*--&--=--?--V--ZY--\- use or is specified as read-onlࡱࡱ;  METAFILEPICTLYLY~@ 4  ~@LY  qa&Arial,-- .  "System--2 dOAM&P! -- .  -- 2 6USER6-&Arial +-- .  --2 IO ADMINISTRATOR  I-&Arial*-- .  --42 !SECURITY SYSTEM (CUSTOMER) -- .  --2 USERVICE -- .  --2 HFCUSTOMER!H*--*--&--=--?--V--ZY--\- use or is specified as read-onl H oV$5Ch5X@X5ChӀ  8    5h X5X@h  5hStatisticsDataproResearchCorporationfigureinSecurityOverview1,14thNCSC,1991;WallStreetJournal,Aug15,1990 ; oV$5Ch5X@X5ChӀ  9    5h X5X@h  5hTheusermaybeaperson,asystem,anotherprocess,etc.Whenaprocessisinvokedbyanotherprocess,theinvokedprocessshallbe  associatedwiththeIDoftheinvokingprocess.Autonomousprocessesshallhaveanassociatedidentificationcode.Theuseofaliasesispermittedonlyafterauserhasbeenproperlyidentifiedandauthenticated. !#0Ch0X@X0Ch  Figure2TMNLogicalNetwork(GeneralRelationshipofaTMNtoaTelecommunications  Network). ) p`CG Times 6 oV$5Ch5X@X5ChӀ  10    5h X5X@h  5hForexample,ifthesystemishaltedtodownloadnewormodifiedsoftware,orasystemrestartisrequired.(W$     - oV$5Ch5X@X5ChӀ  11    5h X5X@h  5hForexample,auditfeaturesshouldbeenabled,defaultaccountsshouldbepasswordprotected,etc.WPC!,7T'13'Standard - Wide ,,519@0\0)+""w 01p1p)""!wL|L|"""w q q  ""#w    ""$w M M  ""%wd )# )# d ""&w  ""'w"A'A'"""(w f f"")w}}+"*wR !trO, \AZ"Arial RegularO&&&Operations"+w fnO, \AZ"Arial RegularOSystem",warO, \AZ"Arial RegularO&&&Operations"-w nO, \AZ"Arial RegularOSystem".wrO, \AZ"Arial RegularO&&&Operations"/wAnO, \AZ"Arial RegularOSystem+"0w#i{D:"1w||"2w|sN+"3w"i'ftO, \AZ"Arial RegularO&&&WorkStation"4w N--2`-XXXExchange"5wY N--2`-XXXExchange"6w" N--2`-XXXExchange"7w f tO, \AZ"Arial RegularO&&&Transmission"8w xAN nO, \AZ"Arial RegularO&&&System"9w} 9S tO, \AZ"Arial RegularO&&&Transmission":w_e; nO, \AZ"Arial RegularO&&&System+";we""<w{ "=wA2 ">wE &"?w*! (Lp:"@w; X:+"Aw&~O, \AZ"Arial RegularOXXX @TelecommunicationNetwork+"Bw&W %'W "Cw$S %S  "w3(  D111B E$$66^^tt F Gsna_ Hmm__ I^lm J K L M N O P Q R   S T U!" V $  WBBB X" Y{~~~TkTjT{ Zwttt [rhh \n___ ]RvvM_M]MSu ^~<~=~ _u>u?u `iCi aTHTIT bz}~ c djUgMg@{@{M~U e~GGG& fHHHTLKKU gLAAAI hLCA iLLL j~   ~ k ~  wwx~ l~~ m~ n~ o33 p~ q~ r~ sSvPvOv tkpv uv v]A]K]L w}t x+}+t y?~?u?s zrh {ri |si }xszi ~8i8`8_ ^U ^U ^U ^T _U _U -_-U t^vU ^U _V ^V TLCA TKBA uLBA jXjUj Y^^ [UUU tLCA nuvU gN|N" rW@aRkhqyrs" @Rhy vKNv" MB]B]BRkRtRv ~T~G~G{@ th ~t h_ h_ h_ ~t ~t* UKA@@@KLU ~t ~t ~t ~t h_ ~ ~ h_ h_ _T h_ th sh  t h ~t &h%_ ti h_ _U  t h 5s5i5h NhN_ ItIh GH T~Tt `` C_DT Z_[T atbh j~lt fhg_ ~~t ~h_ th h_ ~t ~t th h_ _T th h_ ~t h_ th ~t ;Dii {^hh KLK& TI@K@L@LILKIT TK@"  @ K].].]3K3@ ]UT ^C^C^ChCh h_^ "*h*_*^ K$ K K  $   6 .$ . / 1 4 6 8 8 9 9 9$ 9$ : $           $ $  K > 9 ^ . + + * * + - < O w                  K ; : & .  '#           j     !d \ \ _ c e g h h 2h 8h ;f =d ?c ?_ @] @e @c ?` =] ;] 8[ 4Y 2X X X Y [ ] ] _ b d ~ p R W [ \ \ )\ -[ 0[ 2X 3V 5R 5R 5m 4j 3i 2e 2d /c +b b c c d f g k n p p  &A &E 1E 1A &A z B        U [ _ b c d e eB d> d: a6 ]4 X3 V2 2 3 4 6 ; < B z G }       N U Y [ ] ^ _} _G ^D ]? [< V: S8 P7 7 8 ; < @ C G &  <<< __ __ <FF<< ''22'F }~~~~}^ c830,*(7(6*3,3-3379Z\`ac 1 & % % 2 ""w {LL+"wO, \AZ"Arial RegularO&&&DataCommunicationsNetwork+6"w$S $S $ J%" %# h&( & $'S $'S ""w$ & &5$5)""w `S$`S$U"wh$h$( )#( "w  )"w"w  "w"wt"wOb"w*#$+"wR kO, \AZ"Arial RegularOxxxTMN)+"w "w  "wl  "wD d m !m !m !m !m !m !m !m !m !m !~m !ym !tm !om !jm !em !`m ![m !Vm !Qm !Lm !Gm !Bm !=m !8m !3m !.m !)m !$m !m !m !m !m ! m .DDCN.WPG) p`CG Times3|KL  9`(Couriern  @C@34 `TimesRomanf4 PCP34 `TimesRomanS4 PCP(>,w$5U5X|X5UԷp) p`CG Times  (5Ch5X@X5Ch  ݀5 pX5X@TELECOMMUNICATIONSECURITYGUIDELINEFORTMN UDE9:!;<C<< CLevel 1Level 2Level 3Level 4Level 5(Z3$ 3,w!5# 5XX5#   ($$   1  ==' dxdP Pd 'CChCX@X5Ch  CX5X@N5TELECOMMUNICATIONSECURITYGUIDELINEFORTMNLevel 1Level 2Level 3Level 4Level 5Level 1Level 2Level 3Level 4Level 5Level 1Level 2Level 3Level 4Level 5 ) p`CG TimesWPWin 6.0/OLE 1.0 Prefix Information MarkerWPDraw30.Drawingࡱ;   !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIRoot Entry`.@p"l/Ole 9WPG20$CompObj^)F! WPWin61[0]ࡱ `.@pWP Draw 3.0 Drawing Embed SourceWPDraw30.Drawingࡱ; XIࡱ; WPC!,7T'13'Standard - Wide ,,519@0\0)+""w 01p1p)""!wL|L|"""w q q  ""#w    ""$w M M  ""%wd )# )# d ""&w  ""'w"A'A'"""(w f f"")w}}+"*wR !trO, \AZ"Arial RegularO&&&Operations"+w fnO, \AZ"Arial RegularOSystem",warO, \AZ"Arial RegularO&&&Operations"-w nO, \AZ"Arial RegularOSystem".wrO, \AZ"Arial RegularO&&&Operations"/wAnO, \AZ"Arial RegularOSystem+"0w#i{D:"1w||"2w|sN+"3w"i'ftO, \AZ"Arial RegularO&&&WorkStation"4w N--2`-XXXExchange"5wY N--2`-XXXExchange"6w" N--2`-XXXExchange"7w f tO, \AZ"Arial RegularO&&&Transmission"8w xAN nO, \AZ"Arial RegularO&&&System"9w} 9S tO, \AZ"Arial RegularO&&&Transmission":w_e; nO, \AZ"Arial RegularO&&&System+";we""<w{ "=wA2 ">wE &"?w*! (Lp:"@w; X:+"Aw&~O, \AZ"Arial RegularOXXX @TelecommunicationNetwork+"Bw&W %'W "Cw$S %S  "w3(  D111B E$$66^^tt F Gsna_ Hmm__ I^lm J K L M N O P Q R   S T U!" V $  WBBB X" Y{~~~TkTjT{ Zwttt [rhh \n___ ]RvvM_M]MSu ^~<~=~ _u>u?u `iCi aTHTIT bz}~ c djUgMg@{@{M~U e~GGG& fHHHTLKKU gLAAAI hLCA iLLL j~   ~ k ~  wwx~ l~~ m~ n~ o33 p~ q~ r~ sSvPvOv tkpv uv v]A]K]L w}t x+}+t y?~?u?s zrh {ri |si }xszi ~8i8`8_ ^U ^U ^U ^T _U _U -_-U t^vU ^U _V ^V TLCA TKBA uLBA jXjUj Y^^ [UUU tLCA nuvU gN|N" rW@aRkhqyrs" @Rhy vKNv" MB]B]BRkRtRv ~T~G~G{@ th ~t h_ h_ h_ ~t ~t* UKA@@@KLU ~t ~t ~t ~t h_ ~ ~ h_ h_ _T h_ th sh  t h ~t &h%_ ti h_ _U  t h 5s5i5h NhN_ ItIh GH T~Tt `` C_DT Z_[T atbh j~lt fhg_ ~~t ~h_ th h_ ~t ~t th h_ _T th h_ ~t h_ th ~t ;Dii {^hh KLK& TI@K@L@LILKIT TK@"  @ K].].]3K3@ ]UT ^C^C^ChCh h_^ "*h*_*^ K$ K K  $   6 .$ . / 1 4 6 8 8 9 9 9$ 9$ : $           $ $  K > 9 ^ . + + * * + - < O w                  K ; : & .  '#           j     !d \ \ _ c e g h h 2h 8h ;f =d ?c ?_ @] @e @c ?` =] ;] 8[ 4Y 2X X X Y [ ] ] _ b d ~ p R W [ \ \ )\ -[ 0[ 2X 3V 5R 5R 5m 4j 3i 2e 2d /c +b b c c d f g k n p p  &A &E 1E 1A &A z B        U [ _ b c d e eB d> d: a6 ]4 X3 V2 2 3 4 6 ; < B z G }       N U Y [ ] ^ _} _G ^D ]? [< V: S8 P7 7 8 ; < @ C G &  <<< __ __ <FF<< ''22'F }~~~~}^ c830,*(7(6*3,3-3379Z\`ac 1 & % % 2 ""w {LL+"wO, \AZ"Arial RegularO&&&DataCommunicationsNetwork+6"w$S $S $ J%" %# h&( & $'S $'S ""w$ & &5$5)""w `S$`S$U"wh$h$( )#( "w  )"w"w  "w"wt"wOb"w*#$+"wR kO, \AZ"Arial RegularOxxxTMN)+"w "w  "wl  "wD d m !m !m !m !m !m !m !m !m !m !~m !ym !tm !om !jm !em !`m ![m !Vm !Qm !Lm !Gm !Bm !=m !8m !3m !.m !)m !$m !m !m !m !m ! m BOlePartOlePres000e]v<e 2 j  v<]  J -- ! !---- ! !---- ! ! ! ---- !#---- !& !*---- !+ !/ !3 !7---- !8 != !B !G---- !L !Q !V ![---- !` !e !j !o---- !t !y !~ ! ! !---- ! ! ! ! ! !---- ! ! ! ! ! !---- ! ! ! ! ! ! !---- ! ! ! ! ! ! !---- !  ! ! ! ! !# !(---- !- !2 !7 !< !A !F !K !P---- !Q !V ![ !` !e !j !o !t !y !~ ! ! ! ! ! !---- ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !---- ! ! ! ! ! ! !  !---- ! ! ! !$ !) !. !3---- !8 != !B !G !L !Q !V---- !W !\ !a !f !k !p !u---- !z ! ! ! ! !---- ! ! ! ! ! !---- ! ! ! ! ! !---- ! ! ! ! !---- ! ! ! !---- ! ! !---- ! !  ! !---- ! !---- !---- ! !  !"---- !# !$---- !$ !%---- !% ! $---- ! $ !#---- !# !! !---- !---- !# !&---- !' !* !-  !0---- !1 !4 !6 !9---- !; !> !@ !C---- !C !E !F !H !J---- !L !M !O !P !R---- !T !U !V !W !Y !Z---- !Z ![ !\ !] !^ !_} !`x---- !`x !as !bn !bi !cd !d_ !eZ---- !eU !fP !gK !hF !hA !i< !j7---- !j2 !k- !k( !l# !l !l !m---- !m !n  !n !n !o !o !p---- !p !p !p !p !q !q !q !q !q !q !q !q !r !r !r !r---- !r !r !r !r !q !q !q~ !qy !qt !qo !qj !qe !p` !p[ !pV !pQ---- !pQ !pL !oG !oB !n= !n8 !n3 !m.---- !m) !l$ !l !k !k !k !j ---- !j !i !h !g !g !f !e---- !e !d !c !c !b !a !`---- !` !_ !^ !] !\ ![---- !Y !X !W !V !T !S---- !S !Q !P !N~ !My !Kt---- !Ks !In !Gi !Fd !D_---- !BZ !?U !=P !;K---- !8F !6A !3<---- !07 !-3 !*/ !'+---- !'+ !$'---- ! #---- ! ! !---- ! !---- !  !---%hHHhh--%sss--%]]--%MM--%ccc--%--%66--%jJJjj--%hhhhhh-&Arialo-- .  "System--2 } Operations }9-&ArialF-- .  --2 System  (-- .  --2 {q Operations {-- .  --2 {System  -- .  --2 { Operations {8-- .  --2 System  '-- %FG-- %---- .  --2 " Work Station "-&Arial-- .  --2 Exchange  -- .  --2 Exchange  -- .  --2 qExchange  -- .  --2  Transmission  S-- .  --2  System  =-- .  --2  Transmission  C-- .  --2 System  ---c--P--MV,--#K--%,D*A*>*C-- %HC-&Arial-- .  ---2 ?@Telecommunication Network        ? -- ---- %KKK--"%>SSUU^^``cceegg-- %SSTT-- %edcc-- %ddcc-- %cdd--WW--WW--XX--YY--YY--ZZ--[[--[[--\\--]]--^^-- %F^^--GJ-- %aaa--VV--%< Y Y Z ; ; < -- %< Y Y -- < Z-- %; Z Z --%b j kccb -- %[ ` ` -- %[ ` ` -- [ a-- %\ a a -- %< < > > -- > >--%; ;;<<= -- %=??--%UWWW WZZZ --%ZZWWW-- %WWW-- %U@?--%@ A H H H --%I I I P P Q -- %R R Y Y -- %R R R -- B B-- K K-- T T-- U V-- W X-- %b b b -- d d-- f g-- %ccc-- > =-- J J-- %L L L -- ? ?-- A A-- D D-- Q Q-- %K K K -- ? >-- @ @-- A A-- D D-- F F-- G G-- K K-- P P-- S T-- U U-- W W-- %A AAA-- %S SSS-- %h iii-- %j b b -- c i-- %c i i -- %f ggg-- d e--;<--%< 9: ; ; < < --%j lk k j j j -- %i i a b --%kkccb b b -- %= ==<-- > >-- ? ?-- > >-- @ ?-- A A-- @ @-- B A--% @ ???UUUUT -- E D-- C C-- F F-- G G-- H H-- D D-- F F-- C B-- D D-- C C-- E E-- F F-- E E-- H H-- I I-- J J-- B B-- G G-- I I-- I I-- %K K K -- M M-- M M-- M M-- N N-- O O-- L L-- N N-- O O-- O P-- O O-- Q Q-- Q Q-- R R-- S S-- S S-- U U-- T T-- T T-- R R-- V V-- V V-- V W-- W W-- W X-- X X--%[ ` a [ [ --%[ [ [ [ [ --\a--%\ \\aaaaa -- %\ \\--%^^^ _ _ __-- %] ] ] --%[ a a a a -- %] ] ] ] -- %^ _ _ _ -- %MMM-- %XXX--% KKKKKKKKKKKK--% YYYYYYYYYYYYY-- %MLK--0%KJJJJJKLMPSVXYZZZZZZZY-- %YXX-- %MLL--%KHFF_^]Y-- %YXX--%===AGG--%gggd]]-- %=gg--F%!CCCCCDDDD_`````aaa`````_DDDDCCCCC--@%DDDEEE_____````_____EEEDDDDDDD--%^^__^-->%@@@@AAAAbcccccccccccbbAAA@@@@-->%AAAAAABBbbcccccccccbbbBBAAAAA--%>ggg>>>>--%LLUUL-- %OORR-- %RROO--%LLMML--%_____--$%eeeffffffffffeee--0%:kkk k noonnn777777: : :::--%HHH[[--j%3 >bu*7MU \aded#a(\-U2M67>*BEKOPQQuPbO>KEB>62-(#-- .  --02 ;Data Communications Network      --%  --%--- !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !{m !vm !qm !lm !gm !bm !]m !Xm !Sm !Nm !Im !Dm !?m !:m !5m !0m !+m !&m !!m !m !m !m ! m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !|m !wm !rm !mm !hm !cm !^m---- !^m !^r !^w !^| !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^  !^ !^ !^ !^! !^& !^+ !^0 !^5 !^: !^? !^D !^I !^N !^S !^X !^] !^b !^g !^l !^q !^v !^{ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^  !^ !^ !^ !^  !^% !^* !^/ !^4 !^9 !^> !^C !^H !^M !^R !^W !^\ !^a !^f !^k !^p !^u !^z !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^---- !_ !d !i !n !s !x !} ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !---- !6 !; !@ !E !J !O !T !Y !^ !c !h !m !r !w !| ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !---- ! ! ! ! !---- !m !r !w !| !---m----]s----Mc---&ArialF- -  .  -- 2 vTMN--- ! ! ! ! !---- !] !b !g !l !q---- ! ! ! ! !---- !L !Q !V ![ !`--*ࡱ;  METAFILEPICT]e]v< 2 j  v<]  J -- ! !---- ! !---- ! ! ! ---- !#---- !& !*---- !+ !/ !3 !7---- !8 != !B !G---- !L !Q !V ![---- !` !e !j !o---- !t !y !~ ! ! !---- ! ! ! ! ! !---- ! ! ! ! ! !---- ! ! ! ! ! ! !---- ! ! ! ! ! ! !---- !  ! ! ! ! !# !(---- !- !2 !7 !< !A !F !K !P---- !Q !V ![ !` !e !j !o !t !y !~ ! ! ! ! ! !---- ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !---- ! ! ! ! ! ! !  !---- ! ! ! !$ !) !. !3---- !8 != !B !G !L !Q !V---- !W !\ !a !f !k !p !u---- !z ! ! ! ! !---- ! ! ! ! ! !---- ! ! ! ! ! !---- ! ! ! ! !---- ! ! ! !---- ! ! !---- ! !  ! !---- ! !---- !---- ! !  !"---- !# !$---- !$ !%---- !% ! $---- ! $ !#---- !# !! !---- !---- !# !&---- !' !* !-  !0---- !1 !4 !6 !9---- !; !> !@ !C---- !C !E !F !H !J---- !L !M !O !P !R---- !T !U !V !W !Y !Z---- !Z ![ !\ !] !^ !_} !`x---- !`x !as !bn !bi !cd !d_ !eZ---- !eU !fP !gK !hF !hA !i< !j7---- !j2 !k- !k( !l# !l !l !m---- !m !n  !n !n !o !o !p---- !p !p !p !p !q !q !q !q !q !q !q !q !r !r !r !r---- !r !r !r !r !q !q !q~ !qy !qt !qo !qj !qe !p` !p[ !pV !pQ---- !pQ !pL !oG !oB !n= !n8 !n3 !m.---- !m) !l$ !l !k !k !k !j ---- !j !i !h !g !g !f !e---- !e !d !c !c !b !a !`---- !` !_ !^ !] !\ ![---- !Y !X !W !V !T !S---- !S !Q !P !N~ !My !Kt---- !Ks !In !Gi !Fd !D_---- !BZ !?U !=P !;K---- !8F !6A !3<---- !07 !-3 !*/ !'+---- !'+ !$'---- ! #---- ! ! !---- ! !---- !  !---%hHHhh--%sss--%]]--%MM--%ccc--%--%66--%jJJjj--%hhhhhh-&Arialo-- .  "System--2 } Operations }9-&ArialF-- .  --2 System  (-- .  --2 {q Operations {-- .  --2 {System  -- .  --2 { Operations {8-- .  --2 System  '-- %FG-- %---- .  --2 " Work Station "-&Arial-- .  --2 Exchange  -- .  --2 Exchange  -- .  --2 qExchange  -- .  --2  Transmission  S-- .  --2  System  =-- .  --2  Transmission  C-- .  --2 System  ---c--P--MV,--#K--%,D*A*>*C-- %HC-&Arial-- .  ---2 ?@Telecommunication Network        ? -- ---- %KKK--"%>SSUU^^``cceegg-- %SSTT-- %edcc-- %ddcc-- %cdd--WW--WW--XX--YY--YY--ZZ--[[--[[--\\--]]--^^-- %F^^--GJ-- %aaa--VV--%< Y Y Z ; ; < -- %< Y Y -- < Z-- %; Z Z --%b j kccb -- %[ ` ` -- %[ ` ` -- [ a-- %\ a a -- %< < > > -- > >--%; ;;<<= -- %=??--%UWWW WZZZ --%ZZWWW-- %WWW-- %U@?--%@ A H H H --%I I I P P Q -- %R R Y Y -- %R R R -- B B-- K K-- T T-- U V-- W X-- %b b b -- d d-- f g-- %ccc-- > =-- J J-- %L L L -- ? ?-- A A-- D D-- Q Q-- %K K K -- ? >-- @ @-- A A-- D D-- F F-- G G-- K K-- P P-- S T-- U U-- W W-- %A AAA-- %S SSS-- %h iii-- %j b b -- c i-- %c i i -- %f ggg-- d e--;<--%< 9: ; ; < < --%j lk k j j j -- %i i a b --%kkccb b b -- %= ==<-- > >-- ? ?-- > >-- @ ?-- A A-- @ @-- B A--% @ ???UUUUT -- E D-- C C-- F F-- G G-- H H-- D D-- F F-- C B-- D D-- C C-- E E-- F F-- E E-- H H-- I I-- J J-- B B-- G G-- I I-- I I-- %K K K -- M M-- M M-- M M-- N N-- O O-- L L-- N N-- O O-- O P-- O O-- Q Q-- Q Q-- R R-- S S-- S S-- U U-- T T-- T T-- R R-- V V-- V V-- V W-- W W-- W X-- X X--%[ ` a [ [ --%[ [ [ [ [ --\a--%\ \\aaaaa -- %\ \\--%^^^ _ _ __-- %] ] ] --%[ a a a a -- %] ] ] ] -- %^ _ _ _ -- %MMM-- %XXX--% KKKKKKKKKKKK--% YYYYYYYYYYYYY-- %MLK--0%KJJJJJKLMPSVXYZZZZZZZY-- %YXX-- %MLL--%KHFF_^]Y-- %YXX--%===AGG--%gggd]]-- %=gg--F%!CCCCCDDDD_`````aaa`````_DDDDCCCCC--@%DDDEEE_____````_____EEEDDDDDDD--%^^__^-->%@@@@AAAAbcccccccccccbbAAA@@@@-->%AAAAAABBbbcccccccccbbbBBAAAAA--%>ggg>>>>--%LLUUL-- %OORR-- %RROO--%LLMML--%_____--$%eeeffffffffffeee--0%:kkk k noonnn777777: : :::--%HHH[[--j%3 >bu*7MU \aded#a(\-U2M67>*BEKOPQQuPbO>KEB>62-(#-- .  --02 ;Data Communications Network      --%  --%--- !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !{m !vm !qm !lm !gm !bm !]m !Xm !Sm !Nm !Im !Dm !?m !:m !5m !0m !+m !&m !!m !m !m !m ! m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !m !|m !wm !rm !mm !hm !cm !^m---- !^m !^r !^w !^| !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^  !^ !^ !^ !^! !^& !^+ !^0 !^5 !^: !^? !^D !^I !^N !^S !^X !^] !^b !^g !^l !^q !^v !^{ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^  !^ !^ !^ !^  !^% !^* !^/ !^4 !^9 !^> !^C !^H !^M !^R !^W !^\ !^a !^f !^k !^p !^u !^z !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^ !^---- !_ !d !i !n !s !x !} ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !---- !6 !; !@ !E !J !O !T !Y !^ !c !h !m !r !w !| ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !---- ! ! ! ! !---- !m !r !w !| !---m----]s----Mc---&ArialF- -  .  -- 2 vTMN--- ! ! ! ! !---- !] !b !g !l !q---- ! ! ! ! !---- !L !Q !V ![ !`--*   (FcFXX5c  Fj X5XԀTELECOMMUNICATIONSECURITYGUIDELINEFORTMN) p`CG Times   (IcIXX5c  Ij X5XԀTELECOMMUNICATIONSECURITYGUIDELINEFORTMN  (5c5XX5c  ݀) p`CG Times v !#KChKX@XKCh  Figure1UserRoles. ) p`CG Times   (McMXX5c  Mj X5XԀTELECOMMUNICATIONSECURITYGUIDELINEFORTMN) p`CG Times34 `TimesRoman  (PChPX@X5Ch  ݀P pX5X@TELECOMMUNICATIONSECURITYGUIDELINEFORTMN) p`CG Times    3,w!5Ch5X@X5Ch  ݛ  5X5X@>7dd7Ӝ    40     1.0  PREFACE#""w(#. (#(##14O݌  Ќ    0  0` (#(#    1.1 ` INTRODUCTION#""w(#.((,` (#` (##1݌  Ќ    0  0` (#(#0 ` (#` (# `   1.1.1 BACKGROUND#""w(#.//2 (# (##1݌ G I Ќ    0  0` (#(#0 ` (#` (# `   1.1.2 SCOPEOFTSGEFFORT#""w(#.< (# (##2݌   Ќ    0  0` (#(#0 ` (#` (# `   1.1.3 DEFINITIONS#""w(#.3 (# (##5݌   Ќ    0  0` (#(#0 ` (#` (# `   1.1.4 AUDIENCE#""w(#.0 (# (##6݌   Ќ    0  0` (#(#0 ` (#` (# `   1.1.5 TERMINOLOGY#""w(#.\\3 (# (##7݌ S U Ќ    0  0` (#(#0 ` (#` (# `   1.1.6 CONFORMANCE#""w(#.3 (# (##7݌   Ќ    0  0` (#(#0 ` (#` (# `   1.1.7 APPLYINGTHETSG#""w(#.8 (# (##8݌    Ќ     0  0` (#(#0 ` (#` (# `   1.1.8 AREAFORFURTHERRESEARCH#""w(#.ZZA (# (##8 ݌   Ќ     0     2.0  SECURITYTHREATSANDCONCERNS#""w(#.``6(#(##9 ݌ "$  Ќ    e 0  0` (#(#    2.1 ` INTRODUCTION#""w(#.((,` (#` (##9e ݌   Ќ    C 0  0` (#(#    2.2 ` SCOPEOFSECURITYTHREATS#""w(#.9` (#` (##9C ^ ݌   Ќ    . 0  0` (#(#    2.3 ` SOURCESOFTHREATS#""v(#.552` (#` (##10. I ݌ km  Ќ    0  0` (#(#0 ` (#` (# `   2.3.1 EMPLOYEES/INSIDERS#""v(#.xx: (# (##10.݌ .0  Ќ    0  0` (#(#0 ` (#` (# `   2.3.2 NATURALDISASTERS#""v(#.HH9 (# (##10)݌   Ќ    0  0` (#(#0 ` (#` (# `   2.3.3 MALICIOUSHACKERS#""v(#.ZZ9 (# (##10#݌   Ќ    0  0` (#(#    2.4 ` THREATCATEGORIES#""v(#.1` (#` (##110݌ wy Ќ    0     3.0  REQUIREMENTSFRAMEWORK#""v(#.22.(#(##12݌  Ќ    0  0` (#(#    3.1 ` REQUIREMENTSAPPLICABILITY#""v(#.##:` (#` (##12݌  Ќ    0  0` (#(#0 ` (#` (# `   3.1.1 MEDIATIONDEVICESANDELEMENTMANAGERS#""v(#.N (# (##12݌  Ќ    0  0` (#(#0 ` (#` (# `   3.1.2 COMPONENTVIEW#""v(#.yy6 (# (##12݌ FH Ќ    0  0` (#(#0 ` (#` (# `   3.1.3 SECURITYPOLICY#""v(#.CC7 (# (##12݌    Ќ    0  0` (#(#0 ` (#` (# `   3.1.4 USERACCESS#""v(#.3 (# (##12݌  Ќ    0  0` (#(#0 ` (#` (# `   3.1.5 FRAUD#""v(#. - (# (##123݌  Ќ    0  0` (#(#0 ` (#` (# `   3.1.6 NEWTECHNOLOGIES#""v(#.$$8 (# (##13݌ RT Ќ    0  0` (#(#    3.2 ` HIGHLEVELSECURITYREQUIREMENTS#""v(#.oo@` (#` (##13݌  Ќ    0     4.0  DETAILEDGUIDELINE#""v(#. *(#(##15݌  Ќ    q0  0` (#(#    4.1 ` IDENTIFICATION#""v(#.pp.` (#` (##15q݌ ^`  Ќ    R0  0` (#(#    4.2 ` AUTHENTICATION#""v(#..` (#` (##15Rm݌ ! #! Ќ    30  0` (#(#    4.3 ` SYSTEMACCESSCONTROL#""v(#.5` (#` (##183N݌  " Ќ    0  0` (#(#    4.4 ` RESOURCEACCESSCONTROL#""v(#.cc7` (#` (##196݌ !# Ќ    0  0` (#(#    4.5 ` DATAANDSYSTEMINTEGRITY#""v(#.9` (#` (##19 ݌ j"l$ Ќ    0  0` (#(#    4.6 ` AUDIT#""v(#.X X %` (#` (##20 ݌ -#/% Ќ     0  0` (#(#    4.7 ` SECURITYADMINISTRATION#""v(#.7` (#` (##21 ݌ #& Ќ    !0  0` (#(#    4.8 ` DATACONFIDENTIALITY#""v(#.((5` (#` (##23!!݌ $' Ќ    "0     5.0  DEVELOPMENTLIFECYCLEREQUIREMENTS#""v(#.;(#(##24""݌ 9&;) Ќ    ~#0  0` (#(#    5.1 ` SECURITYPOLICY#""v(#./` (#` (##24~##݌ &* Ќ    `$0  0` (#(#    5.2 ` REQUIREMENTSANALYSIS#""v(#.5` (#` (##24`${$݌ ' + Ќ    H%0  0` (#(#    5.3 ` SYSTEMDESIGN#""v(#.[[-` (#` (##24H%c%݌ (!, Ќ    (&0  0` (#(#    5.4 ` DETAILEDSYSTEMDESIGN#""v(#.6` (#` (##25(&C&݌ E)G"- Ќ    '0  0` (#(#    5.5 ` IMPLEMENTATION#""v(#.  .` (#` (##25','݌ * #. Ќ    '0  0` (#(#    5.6 ` DEVELOPMENTENVIRONMENT#""v(#.7` (#` (##25' (݌ *#/ Ќ    (0  0` (#(#    5.7 ` SYSTEMTEST#""v(#. +` (#` (##26((݌ +$0 Ќ    )0  0` (#(#    5.8 ` PACKAGINGANDDELIVERY#""v(#.6` (#` (##26))݌ Q,S%1 Ќ    6O*0  0` (#(#    5.9 ` DOCUMENTATION#""v(#.-` (#` (##27*+݌ _ Ќ    +0  0` (#(#    5.10 ` SUPPORT#""v(#.' ' '` (#` (##28++݌ " Ќ    ,0      LISTOFACRONYMS #""v(#.< < (#(##29,,݌ I Ќ    s-0     REFERENCES #""v(#. (#(##30s--݌ U  Ќ    :.0     APPENDIX #""v(#.(#(##32:.U.݌   Ќ  (ӛ    R   1.0  PREFACE  \/  ThePublicSwitchedNetwork(PSN)providescriticalcommercialtelecommunicationsservicesandNationalSecurityandEmergencyPreparedness(NS/EP)   1      ׀telecommunications.Serviceproviders,equipmentmanufacturers,users,andtheFederal 1 3 МGovernmentareconcernedthatvulnerabilitiesinthePSNcouldbeexploitedandresultindisruptionsordegradationofservice.Toaddressthesethreats,theNationalInstituteofStandardsandTechnology(NIST)iscollaboratingwithBellcoretoinvestigatethevulnerabilitiesandrelatedsecurityissuesthatresultfromtheuseofopensystemsarchitecturesinthetelecommunicationsindustry.Securityfeaturesrequiredtocounterthethreatsareidentified.AseriesofTelecommunicationSecurityGuidelines(TSGs)thataddressahierarchyoftelecommunicationarchitecturesofincreasingcomplexitymaybeproduced.ThisfirstguidelinefocusesontwospecificcomponentsofaTelecommunicationsManagementNetwork(TMN)   2      ׀NetworkElements(NEs)andMediationDevices(MDs)with IK  emphasisonthesecurityfeaturesneededtoprotecttheOperations,Administration,Maintenance,andProvisioning(OAM&P)ofthesecomponents.ThisTSGisintendedtoprovideasecuritybaselineforNEsandMDsthatisbasedoncommercialsecurityneeds.Inaddition,someNS/EPsecurityrequirementswillbeintegratedintothebaselinetoaddressspecificnetworksecurityneeds.TheguidelineshouldassisttelecommunicationsvendorsindevelopingsystemsandserviceprovidersinimplementingsystemswithappropriatesecurityforintegrationintothePSN.Itcanalsobeusedbyagovernmentagencyoracommercialorganizationtoformulateaspecificsecuritypolicy.ItdoesnotstipulateregulatoryrequirementsormandatedstandardsoftheNationalInstituteofStandardsandTechnology.  1.1  INTRODUCTION 7 02   1.1.1  BACKGROUND 8 |~ ThePublicSwitchedNetwork(PSN)providesservicesthatareessentialtoU.S.citizensandgovernmentagenciesalike.Disruptionoftelecommunicationsserviceswouldclearlyrepresentaseriousthreattopublicsafetyandsecurity.A1989reportoftheNationalResearchCouncil,"TheGrowingVulnerabilityofthePublicSwitchedNetwork,"[1]outlinedtheconcernsofthegovernmentformaintainingtheintegrityofthePSNagainstintruders.AreportthefollowingyearbythePresident'sNationalSecurityTelecommunicationsAdvisoryCommittee(NSTAC)concludedthat"untilthereisconfidencethatstrong,comprehensivesecurityprogramsareinplace,theindustryshouldassumethatamotivatedandresourcefuladversary,inoneconcertedmanipulationofthenetworksoftware,coulddegradeatleastportionsofthePSNandmonitorordisruptthetelecommunicationsserving[government]users"[2].Inaddition,outagesexperiencedbyserviceprovidersintherecentpasthavefocusedtheFederalGovernment'sattentionontheneedtoensurethattelecommunicationsservicesareavailableandreliable.MorerecentNSTACstudieshaveshownthatthethreatandvulnerabilitiesforpublicnetworksisstillsignificant[18]. f&h) R  Inthepast,therewererelativelyfewtelecommunicationsproviders,andthesystemstheyusedwerebuiltonproprietaryplatforms.TheFederalCommunicationCommission's(FCC)OpenNetworkArchitecture(ONA)requirementsspecifyunbundledandequalaccesstothePSNforBellOperatingCompaniesandtheirenhancedservicescompetitors[3].Theenvironmentischangingtodaytoonewheremanyserviceprovidersareusingproductsandofferingservicesthatmustworkwithproductsfrommanyvendors[4],[5],[6].Thisnewopentelecommunicationsenvironmenthasbeencharacterizedasonewith:alargenumberoffeatures;multimedia,multiuserservices;incompleteknowledgeofthefeaturesetbyservicedesigners;lowerskillandknowledgelevelsofsomeservicecreators;multipleexecutionenvironmentsfromdifferentvendors;anddistributedintelligence[7].ANetworkOperationsForum(NOF)reportnotesthat:0  Whiletheadventofopensystemsinterfaceshasassistedtheacceptanceandinternationaldeploymentofnetworkingtechnology,ithasalsoseenadownsideinthatithasbecomeeasiertointrudeonnetworksdesignedwithsuchopenfeatures....Bellcore'ssecuritySubjectMatterExpertshaveindicatedthatmanyoftheintruderswereassistedintheirendeavorsbytheopennessandstandardizationthatthetelecommunicationsindustryhasundergoneduringthelastdecade[8]. (#(# Fraudulentuseoftelecommunicationsresourcesisalsoontheincrease.Intrudersaretakingadvantageofdifferentsituationstocommitfraud.Twosituationsarelistedbelow:  1.0 ` Customersfrequentlyfailtoadequatelyprotecttheircustomerpremisesequipment(CPE)whichallows   intruderstostealservicewithoutmodifyingdata,information,orsoftwarecontrollingNetworkElements(NEs). ` (#` (#   2.0 ` Customershavedemandedandreceivedgreateraccesstodata,information,andsoftwarecontrolling ! NEstoexpandtheircapabilitiestocontrolandcustomizetheirservice.Intrudersgainunauthorizedaccesstocustomers'capabilitiesandstealservicebymodifyingdata,information,orsoftwarecontrollingNEs. ` (#` (# Thesecondsituationisofgreaterconcern,becauseinadditiontosimpletheftofservice,itcreatesthepotentialforintruderstocausedenialofservicethatmayaffectalargenumberofusers.SafeguardingthesecurityandintegrityofthePSNinsuchanenvironmentisachallengingtask.Inthecurrentopenenvironment,industry/governmentcooperationwillhelpensurethatorganizationsimplementthebaselinesecuritymeasuresneededtoprotecttheirsystems.ThisdocumentprovidesbaselineprotectionmeasuresthatgovernmentagenciesorcommercialorganizationscanusetosafeguardTelecommunicationManagementNetworks(TMN)resourcesandcountersecuritythreats.  1.1.2  SCOPEOFTSGEFFORT I "/% Telecommunicationsnetworksofferawiderangeofcommunicationservices(packetswitching,datatransfer,voice,video,etc.)tocustomers.Thesenetworks,whichmaybepublicorprivate,arepopulatedbyalargeandincreasingnumberofOperationsSystems(OSs),NetworkElements(NEs),ElementManagers(EMs)andMediationDevices(MDs)suppliedbydifferentvendors.OSstendtohavecentralizedfunctionality,aspanofcontrolthatcoversalargeportionofthenetwork,andgenerallyprovidemostoftheoperationsfunctions.NEsaredistributedcomponentsthatprovidetelecommunicationsservices,haveaspanofcontrolgenerallylimitedtothemselves,andhavearelativelylimitedsetofoperationsfunctionality.MDsactonthecontextofoperationsinformationpassingbetweenNEsandOSs.MDsmayprovidefunctionssuchasupperlayerprotocolinternetworking,filtering,formatconversion,storage,etc.TheAppendixprovidesmoredetailonthedifferencesamongthesecomponents. {,&2 ATMNallowsfortheexchangeofmanagementinformationandofferscommunicationsbetweenitselfandthetelecommunicationsnetworks.Managementinformationaboutmostaspectsofnetworkoperations,includingtesting,maintenance,billing,andengineeringisexchangedoverTMNinterfaces.TMNsprovidetheorganizednetworkstructurethatisneededtointerconnectvarioustypesofOSsandtelecommunicationsequipmentusingstandardizedprotocolsandinterfaces.Therapidgrowthinthenumberoftelecommunicationsnetworksandthevarietyofservicestheyofferhavecreatedawidediversityofmanagementandsecurityneedstobesatisfied.TMNinterfaces,suchasthosebetweenNEsandOSs,arevulnerabletoavarietyofthreats.Adequatesecuritymeasuresmustbeprovidedtoprotectthem.TheconnectivityprovidedbyopensystemsaccentuatesthesecurityrisksofunauthorizedaccesstotheTMNenvironmentanditssoftwareanddatabases.TheTelecommunicationSecurityGuidelines(TSG)forTMNwilldefineaframeworkandprovideguidanceforestablishingasecureTMN.SecurityinaTMNreferstoasetofprocedural,logical,andphysicalmeasuresthatprevent,detectandcorrectcertaintypesofactionsorthreatsthatmaycompromisetheintegrity,availability,timeliness,andconfidentialityofinformationandservices.SecuritymechanismsfortheinterfacesandcommunicationsrequiredtomanagethevariousOperations,Administration,Maintenance,andProvisioning(OAM&P)functionsinaTMNarediscussed.Variouslevelsofdecompositionexistwithinatelecommunicationsnetwork.TheTMNarchitectureprovidesonesuchlevel.Thefirstphaseofthiseffortwilladdressthenetworkatacomponentlevel.Subsequentphaseswilladdressbothcomponentandgloballevels.@D 1.1.2.1  SCOPEOFSECURITYFEATURES  FH ThisfirstofaseriesofTSGsdescribessecurityfeaturesthatarenecessarytoprotectTMNcomponents,specificallyNEsandMDs,fromvarioustypesofattacksleadingtomisuseandabuseofthesoftwarefunctionswithinthecomponents.Thesesecurityfeaturesaddresssuchareasasauthentication,accesscontrol,audit,integrity,andadministration.ThisdocumentaddressesboththeglobalnatureoftheTMNandtheinteractionsamongTMNcomponents.SecurityfeaturesarenotsufficientbythemselvestoprovideasecureTMN.SecurityhastobeconsideredthroughouttheentiredevelopmentlifecycleoftheTMNanditscomponentsaspartofqualityassuranceandsystemreliability.Allsecurityfeaturesneedtobeproperlyconceived,designed,implemented,tested,installed,documented,andmaintained.Otherwise,afalsesenseofsecuritymayresult.ThisTSGeffortspecifiesappropriatesecurityrequirementstoensurethatanacceptablesecuritylevelismaintainedthroughoutthesystemdevelopmentlifecycleandisalsoreflectedinsystemdocumentation. 1.1.2.2  PERSPECTIVES  $'  1.1.2.2.1 ` TELECOMMUNICATIONSSECURITYGUIDELINE  ' * ThisTelecommunicationsSecurityGuidelineadoptsanOAM&Pperspectiveratherthanauserserviceperspective.Thisdocumentdescribessecurityfeaturesneededbythenetworknodesandthenetworktoprotectthemselvesfromvarioustypesofsecuritythreatsandattacks.ThefocusisonthesecurityofNEandMDoperations,NE/MDinteractionswithothercomponents,informationresidentintheNE,andfraudprevention.Thesecurityfeatureswillnotaddresssecurityinthecontextoftheinherentfeaturesinthenetwork'scallprocessing Z,\%1 functionsorhowvariousnetworkserviceswillprovidesecuritywithintheframeworkoftheservice.TheOAM&Poftheinformationandsoftwareusedbythenetworktoprocessacalloraservicerequestarewithinthepurviewofthiseffort.EmphasisisplacedondefiningaminimumsecuritybaselinetoprotecttheTMNcomponentsfromvarioussecuritythreats.Itisrecognizedthatnetworkenvironmentsandserviceneedswillvary.Thisdocumentwillestablishasecuritybaselinethatisapplicabletoacommoncommerciallevelofsecurity.Forsomeuserenvironments,additionalsecurityfeaturesandstrongermechanismsmaybeneededtoaugmentthespecifiedbaseline,dependingontheorganizationalsecuritypolicies. 1.1.2.2.2 ` MINIMUMSECURITYREQUIREMENTS/COMMONCRITERIA  :   NISTIR5153, MinimumSecurityRequirementsforMultiUserOperatingSystems(MSR) ,specifiescomputerbased d  protectionmechanismsforthedesign,use,andmanagementofinformationsystems.Theserequirementsincludetechnicalmeasuresthatcanbeincorporatedintomultiuser,remoteaccess,resourcesharing,andinformationsharingcomputersystems.TheMSRprovidesadministratorsofanMSRconformantcomputersystemwiththetoolstocontrolthesharingofinformationandresourcesbasedprimarilyontheidentityofusers,butalsoonthetimeofday,terminallocation,ortypeofaccessrequestedbyusers.Thetechnicalmeasuresalsoprovidetoolstoprotectagainstcommonuseractionsthatmaycompromisesecurityandagainstdeliberatepenetrationattemptsby"crackers   3      ל".Inaddition,therearerequirementsthat [  aconformantcomputersystemprovideatailorableabilitytologeventsthatmayimpactthesecurityofeitherthesystemortheinformationthatitisprocessing.TheMSRprovidesbasiccommercialcomputersystemsecurityrequirementsapplicabletobothgovernmentandcommercialorganizations.TheMSRdocumentwaswrittenfromtheperspectiveofprotectingtheconfidentialityandintegrityofanorganization'sresourcesandpromotingthecontinualavailabilityoftheseresources.TheMSRisbeingsupersededbythedraftCommonCriteria.w   4      ׀ Q  1.1.2.2.3 ` DIFFERENCESBETWEENTHETSGANDMSR   Inthepast,differencesbetweentelecommunicationssystemsandcomputersystemswerereadilyapparent.Todaythatdistinctionisnotsoclear.Forexample,onetypeofNE,thesoftwarecontrolleddigitalswitch,hasreplacedmuchoftheoldermechanicallyswitchedtelecommunicationsequipment.Thenewerdigitalsystemsaretakingonthecharacteristicsofspecialpurposecomputersystemsprocessingacommunicationapplication.Assuch,theyaresubjectedtomanyofthesamethreatsthatconfrontcomputersystems,whileatthesametimeretainingmuchoftheuniquefunctionalityassociatedwithrespondingtocustomerdemandsforvoicecommunications.TheTSGandtheMSR/CommonCriteriatakedifferentapproachestodealingwithsecurity.Thelattercanbeusedtospecifyasetofsecurityrequirementsneededinaclassofcomputerproductsoftendescribedasgeneralpurpose,multiuseroperatingsystems.TheCommonCriteriaisintendedtobroadenitsscopetoincluderequirementsfortrustedsubsystems anddistributedsystems.ExamplesofsuchproductsfromtheTMNenvironment(architecture)includeOperationsSystems  $' (OSs)andWorkstations(WSs).TheMSRisbasedontheTCSEC   5      כC2criteriaclass,withadditionsfromcurrentcomputer   industrypracticeandcommercialsecurityrequirementsspecifications.Incontrast,thefocusoftheTSGisonNEsandMDscomponentsthatdifferfromthegeneralpurposecomputersnormallyassociatedwithOSsandWSs.Also,thefullfunctionalityofanNEcanincludecallhandlingOAM&Pfunctionsaswellasabillingcapability.SecurityrequirementsforTMNcomponentssuchasOSsandWSsareaddressedbytheMSR/CommonCriteria.ForthatreasontheTSGdoesnotdealwithsuchsystems,butinsteadfocusesontheremainingcomponentsoftheTMNarchitecture.TheAppendixprovidesadescriptionoftheTMNarchitecture. 1.1.2.3  ENVIRONMENTALASSUMPTIONS  "$  ThefollowingspecificenvironmentalconditionshavebeenassumedinspecifyingthesecuritymechanismsrequiredtoprotectTMNs:  1.0 ` Physicalsecurity-itisassumedthatTMNcomponentsareinphysicallysecurelocationsorthatmanual   proceduresandcontrolsandotherphysicalsafeguards(e.g.,lockedequipmentcabinet)canprovidephysicalsecurityforagivenlocation. ` (#` (#   2.0 ` TrainingandAwareness-thesetopicsareviewedaspartoftheoverallsecuritystrategyforagiven  environment.Managementmustmakeaninformeddecisionregardingtheadequacyofexistingtrainingandawarenessefforts. ` (#` (#   3.0 ` UserServicePerspective-thesecurityfeaturesofagivenserviceorapplicationareoutsidethescope   ofthiseffort.Thisincludesservicespecific,andfrauddetectionandpreventionrequirements. ` (#` (#   4.0 ` Therewillbeoneormorepersonnelassignedtomanagethesystem,includingthesecurityofthe UW informationitcontains. ` (#` (#   5.0 ` Ifanetworkinterfaceissupported,theattachednetworkswillprovidesomefacilitytotransportthe  identityofremoteusers. ` (#` (# ̛̛̛̛̛̛̛̛̛̛̛̛̜  1.1.3  DEFINITIONS s #&   User |%~(  0  Thetermuserreferstoanindividual,group,host,domain,trustedcommunicationchannel,networkaddress/port, ' * anothernetwork,aremotesystem(e.g.,operationssystem),oraprocess(e.g.,serviceorprogram)thataccessesthenetwork,orisaccessedbyit,includinganyentitythataccessesanetworksupportentitytoperformOAM&Prelatedtasks.Regardlessoftheirrole,usersmustberequiredtosuccessfullypassanidentificationand T)V"- authentication(I&A)mechanism.Forexample,I&Awouldberequiredforasecurityorsystemadministrator.Forcustomers,I&Acouldberequiredforbillingpurposes.   6      ׀SeeFigure1."(#(#   Customer  I 0  Thetermcustomerappliestoapersonororganizationwhosubscribestoaserviceofferedbya 1  telecommunicationsproviderandisaccountableforitsuse.AcustomerispermittedtouseanNEtomakecallsandconfigurelocallineparameters(e.g.,configurethenumbersthatshouldreceiveforwardedcalls).w   7      ׀ @!  ^(#(#   SecurityAdministrator  C   *5  Thetermsecurityadministratorisusedgenericallytomeanthehighlyprivilegedroleapersonmayhavefor#5*ƃy# 0  *5  performingsecurityrelatedadministrativetasks(e.g.,customizetheauditfeaturesforthesystem).#5*Zz# X  ̜̜#%JI95z p 8b `0*x@@@E <   < d< ߛ̛̜  Domain  W " 0  Thetermdomainreferstoapartofthenetworkthatisadministeredbyasingleauthority.!$(#(#   1.1.4  AUDIENCE | /$' TheTSGtargetsfourdistinctaudiences:users,vendors,evaluatorsandserviceproviders. {& *   *0 ` TheTSGaddressesthesecurityneedsoftelecommunicationssystemsusers.Thisincludesapplication  developers,customers,andprivatesectorandgovernmentadministrators.Therequirementsfocusonthebasicsecurityrequirementsofcommercialtelecommunicationssystems. ` (#` (#   *0 ` TheTSGprovidesvendorswithasingle,welldefinedsetofsecurityrequirementsthatareapplicable   acrosstheirentirecustomerbase.Theserequirementsrepresenttheintegrationofanumberofsecurityrequirementspecificationsfromvarioussources(seeSection1.1.2.2.2)intoasinglesetthatisexpectedtohavewideacceptance.Vendorscanmoreconfidentlyusethissettodevelopasinglesystemwithfeaturesthatmeettheneedsofasignificantcustomerbase.Thelevelofdetailprovidedbytheserequirementsshouldhelpclarifywhatthevendormustdotocomply. ` (#` (#   *0 ` ProductandsystemevaluatorscanapplythewelldefinedsetofsecurityrequirementsintheTSGto _a  theirwork.Thedetailedleveloftherequirementssignificantlydecreasetheneedforevaluatorinterpretation.AformatsimilartothatusedintheCommonCriteriaprovidesabasisforwidespreadacceptanceoftherequirementsandmutualrecognitionofevaluations. ` (#` (#   *0 ` Serviceprovidersareprovidedaclearlydefinedandwidelyacceptedsetofsecurityrequirementsthat .0  areconsistentwithuserexpectations.ItisanticipatedthattheTSGwillresultinawiderarrayofcompetitivelypricedproductsfromwhichserviceproviderscanchoosewhenrespondingtousersolicitationsandrequirements. ` (#` (#   1.1.5  TERMINOLOGY   TheTSGprojectadoptsthefollowingterminologyusedintheMSRdocument:  *0 ` Requirement 󀄀Afeatureorfunctionthatisnecessarytosatisfythesecurityneedsofatypical  commercialorgovernmentorganizat