VoIP and compliance regulations make strange and difficult bedfellows
Network World - As attacks against VoIP persist businesses not only have to defend themselves, they have to do it under the gun of regulators who want proof that security was addressed in accordance with their ever-changing rules.
VoIP denial of service, toll fraud and eavesdropping attacks are serious problems, yet many businesses lack some of the most basic VoIP protections such as encryption, experts say. There is a sense of urgency to deal with these issues because at the same time, businesses are forced to comply with regulations such as the Sarbanes-Oxley Act, the Health Insurance Portability and Accountability Act (HIPPA) and Payment Card Industry (PCI) standards that present a moving target as they are revised and updated.
"Recent events involving financial fraud, product safety recalls, and disasters in environmental health and safety have escalated this issue even more in the past two years," according to a Forrester Research study, "The Regulatory Intelligence Battlefield Heats Up", "and the appetite among legislators in the U.S. and abroad seems decidedly in favor of tighter regulatory control."
For the most part, regulations try to protect personally identifiable information that can lead to identity theft, fraudulent use of credit cards, pilfered bank accounts and toll fraud against corporate phone systems.
VoIP is rarely addressed directly in these regulations, but the rules nevertheless apply in some cases. For example, PCI standards say, "Use strong cryptography and security such as SSL/TLS or IPSEC to safeguard sensitive cardholder data during transmission over open, public networks."
That calls for encrypting VoIP calls that cross the open Internet in which credit card numbers are being recited, says Michelle Klinger, a PCI qualified security assessor from Dallas. "I would be inclined to validate that the calls are being encrypted," she says, although VoIP on internal networks would not need that protection. Businesses need to look out for language in regulations that sound like it refers to VoIP.
For instance, HIPAA says businesses must take steps to secure electronic protected health information, which might not seem to affect VoIP calls, but relates directly to recorded calls and digitally stored voice mail, part of any VoIP system. Similarly, if interactive voice response is used to navigate to protected information, its use should be monitored and documented.
On the other hand, the Federal Deposit Insurance Corporation (FDIC) has published specific VoIP guidelines to protect customer data traveling in IP voice networks in accordance with Graham-Leach-Bliley regulations.
"The risks associated with VoIP should be evaluated as part of a financial institution's periodic risk assessment," the advisory says, "with status reports submitted to the board of directors as mandated by section 501(b) of the Gramm-Leach-Bliley Act (GLBA). Any identified weaknesses should be corrected during the normal course of business." That is accompanied by a list of nine recommended actions.
- Mobile First: Securing Information Sprawl Learn how the partnership between Box and MobileIron can help you execute a "mobile first" strategy that manages and secures both mobile apps...
- The Truth About Cloud Security "Security" is the number one issue holding business leaders back from the cloud. But does the reality match the perception?
- Enable secure remote access to 3D data without sacrificing visual perfomance Design and manufacturing companies must adapt quickly to the demands of an increasingly global and competitive economy. To speed time to market for...
- Virtually Delivered High Performance 3D Graphics "A picture is worth a thousand words." That old phrase is as true today as it ever was. Pictures (i.e., those with heavy...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!