Ofcom Consultation: General policy on ensuring compliance with security duties    Started: 08 March 2022  Ends: 31st May 2022
Overview
Ofcom is consulting on new guidance for telecoms providers, following the introduction of the Telecommunications (Security) Act 2021. Last year, the Government passed new legislation regarding the security of public electronic communications services and networks in the UK.
Under the new framework, Ofcom must ensure providers comply with their security duties, including as to the availability, performance or functionality of the network or service; and Ofcom has the powers to proactively monitor and enforce these duties.
Ofcom have set out the procedures they expect to follow in carrying out monitoring and enforcement activities. Ofcom have also proposed new guidance on which security compromises they would expect providers to report.
Ofcom are also proposing to update existing guidance on network resilience to reflect the new framework, and draft regulations and Code of Practice, on which the UK Government is currently consulting.
What Ofcom are proposingÂ
Ofcom are consulting on the draft statement of their general policy under section 105Y of the Communications Act 2003 (the “2003 Act”) regarding how they will exercise their new functions to seek to ensure that providers comply with their new security duties under the revised security framework. Ofcom’s proposed statement explains the procedures that they generally expect to follow in carrying out monitoring and enforcement activity.Â
Ofcom are also providing general guidance about which security compromises they will normally expect providers to report and the process for reporting them. A key objective of the monitoring role over the first few years of the regime is to determine if each provider is implementing appropriate measures with sufficient pace, as they continue to work towards full compliance. Where Ofcom find areas of concern, they will seek to work with providers to ensure appropriate and proportionate measures are implemented in accordance with the security duties.Â
Ofcom expect that this collaborative approach will foster more compliant behaviours and reduce the volume of breaches under the 2003 Act, as well as reducing the need for regulatory investigations. Ofcom will stand ready to engage a suite of enforcement powers as needed and in addition, are consulting on updated guidance on security requirements in sections 105A to D of the 2003 Act made necessary by the changes arising out of Telecommunications (Security) Act 2021. The new security framework replaces existing sections 105A-105D of the 2003 Act, placing new security duties on providers of public electronic communications networks and services, both in the 2003 Act itself and in regulations. This is supplemented by statutory codes of practice which give guidance on the measures to be taken under sections 105A to 105D.
Given this new framework, Ofcom are proposing to update existing guidance on sections 105A to D of the 2003 Act, in particular recognising that much of this guidance is no longer required given the draft Code of Practice on which Government is currently consulting. In effect, this means that Ofcom are proposing to retain this guidance only insofar as it relates to the sub-category of security compromises relating to the resilience of networks and services, in terms of availability, performance or functionality. Ofcom have also taken this opportunity to update the guidance to take account of the revised framework, as well as to reflect the changing nature of resilience risks and Ofcom’s experience of incident reporting and investigation. The Telecommunications (Security) Act 2021 (the “Security Act”)1 introduces a revised framework for protecting the security and resilience of public electronic communications service and networks in the UK.
https://www.legislation.gov.uk/ukpga/2021/31/contents/enactedÂ
The new framework replaces sections 105A-105D of the 2003 Act and is expected to come into force from 1 October 2022. It places new security duties on providers of public electronic communications networks and services (“providers”), including: • the overarching security duties set out in the 2003 Act (sections 105A and 105C);Â
- duties to take specified measures imposed by the Secretary of State by regulations (sections 105B and 105D); and
- duties to report security compromises to Ofcom and to inform users (sections 105J and 105K).
1.4 The revised framework also provides for two forms of guidance for providers:Â
- The Secretary of State’s guidance on the measures to be taken by providers under sections 105A to 105D. The Secretary of State has powers to give such guidance by issuing codes of practice under section 105E of the 2003 Act;
- Ofcom’s general policy on how they will exercise their functions under sections 105I and 105M to 105V to seek to ensure compliance with the security duties. The 2003 Act (section 105Y) places a duty on Ofcom to publish a statement setting out such general policy and to have regard to it in exercising our relevant functions.
Ofcom’s roleÂ
Ofcom has a general duty under section 105M of the 2003 Act to seek to ensure that providers comply with their security duties. This gives Ofcom a clear remit to work with providers to improve their security and monitor their compliance.Â
Ofcom also has certain reporting functions concerning security-related matters. In particular, Ofcom has a duty to inform the Secretary of State about certain risks of security compromise under section 105L, and also must prepare and send to the Secretary of State:Â
- security reports under section 105Z; and
- infrastructure reports under section 134A which include the extent to which providers are complying with the security duties.
DCMS consultations on the Regulations and the CodeÂ
1.7 As mentioned above, the Secretary of State has powers to impose specific security measures on providers by making regulations and give guidance on the measures to be taken by issuing codes of practice. In exercise of these powers, DCMS is currently consulting on:Â
- draft regulations which the Secretary of State intends to make under sections 105B and 105D (the “Regulations”);5 and
- a draft code of practice which the Secretary of State intends to issue under section 105E to give guidance for providers with relevant turnover in the relevant period of more than or equal to £50m (the “Code”).
Ofcom’s procedural guidanceÂ
The revised framework gives Ofcom a general duty under section 105M of the 2003 Act to seek to ensure that providers comply with their security duties. To allow Ofcom to fulfil this role, the 2003 Act gives Ofcom powers to monitor and enforce industry’s compliance with their security duties (sections 105I and 105N to 105V). In particular, it allows Ofcom to:Â
- require providers to share information that Ofcom considers necessary for the purpose of carrying out its security functions (section 135, as amended by the Security Act7);
- direct providers to explain any failure to act in accordance with guidance given by the Secretary of State in a code of practice (section 105I);
- carry out, or commission others to carry out, an assessment of whether a provider is complying with the security duties (section 105N);
- give assessment notices (section 105O), including issuing an assessment notice which requires a provider to comply with a duty urgently (sections 105P and 105Q). Assessment notices may include requiring providers to complete system tests, make staff available for interview and permit persons authorised by Ofcom to enter operators’ premises to view information, equipment and observe tests;
- enforce compliance with the security duties (section 105S), including by imposing penalties (section 105T) and directing a provider to take interim steps (sections 105U and 105V).
Under section 105Y of the 2003 Act Ofcom has a duty to publish a statement of their general policy with respect to the exercise of their functions under sections 105I and 105M 5 DCMS consultation on “The Electronic Communications (Security Measures) Regulations 2022”, which are still in draft form, is available at:
https://www.gov.uk/government/consultations/proposal-for-new-telecoms-securityregulations-andcode-of-practice
https://www.gov.uk/government/consultations/proposal-for-new-telecoms-securityregulations-and-code-of-practice. See, in particular, section 135(3)(iza)-(izc), section 135(3A)(za) and section 135(3C) of the 2003 Act. 8 The 2003 Act (section 105R) places a duty on Ofcom to publish a statement in our annual report setting out the number of occasions on which premises have been entered pursuant to a duty imposed in an assessment notice. General policy on ensuring compliance with security duties 5 to 105V of the 2003 Act. Annex [A5] contains our draft general statement of policy under section 105Y of the 2003 Act, setting out how Ofcom propose to exercise their new powers.Â
In particular, Ofcom’s draft general statement of policy under section 105Y of the 2003 Act, explains the procedures that they are generally expecting to follow in carrying out monitoring and enforcement activity. It also provides general guidance about which security compromises Ofcom would normally expect providers to report and the process for reporting them. This guidance on providers’ duties to report security compromises is intended to replace the incident reporting guidance which is currently set out in Ofcom’s 2017 Guidance. In addition to the above, our draft general statement provides guidance about Ofcom’s approach to sharing information with other public bodies, including DCMS, the National Cyber Security Centre and the Information Commissioner. Ofcom’s resilience guidanceÂ
The Security Act introduces the definition of a “security compromise”. The guidance set out in Annex [A6] applies to the sub-category of security compromises relating to the resilience of networks and services, in terms of availability, performance or functionality (referred to hereafter as “Resilience Incidents”).Â
Given the new framework described above, we are proposing to update our existing 2017 guidance on sections 105A to D of the 2003 Act, in particular recognising that much of this guidance is no longer required given the draft Code on which Government is currently consulting. Our updated guidance is set out in Annex [A6]. This guidance is intended to update the resilience-related guidance which is currently set out in Ofcom’s 2017 Guidance.Â
Ofcom’s current guidance, insofar as it relates to security compromises other than Resilience Incidents, will be superseded by the Code.Â
Ofcom’s current guidance about incident reporting will be replaced by Ofcom’s guidance on the reporting of security compromises (including Resilience Incidents) included in Ofcom’s statement of general policy.Â
The proposed updated guidance now describes how Ofcom intend to use its powers and sets out the sources of guidance which we will consider when carrying out our functions in relation to resilience. It also provides some general observations and specific incident scenarios which will inform our approach to resilience. In recognition of this, we are proposing to recast what was general guidance as guidance on resilience requirements in sections 105A to D of the Communications Act 2003. As and when Government decisions are made arising out of the UK Government’s National Resilience Strategy Review, Ofcom would expect to review and update or revoke it as appropriate.
A4. Consultation questionsÂ
Questions concerning Ofcom’s draft general statement of policy under section 105Y of the Communications Act 2003 (see Annex A5) Consultation questionÂ
1: Do you have any comments on our proposed approach to compliance monitoring? FCS proposed response – FCS has concerns with how Ofcom allocate providers to Tier 1, Tier 2 and Tier 3, based simply on annual turn-over. In our response to the associated DCMS consultation, FCS flagged concerns with the proposed approach of defining the Tiers by a
Providers annual financial turnover only. FCS believes other aspects such as whether a Provider has responsibility and capability should also be taken into account.
FCS understands that Ofcom plans to complete the process for establishing tiering with providers within 3 months of the framework coming into force, but that it may take longer. FCS supports the approach that Ofcom proposes of informing providers judged to fall into Tier 1 and Tier 2, and seeking to hold an introductory meeting to discuss the approach to compliance monitoring. We currently believe that some FCS members will be in the proposed Tier 2 and that it will be key that these members/providers clearly understand their security responsibilities, how Ofcom will monitor and report on these and what specifically they need to do to ensure compliance. FCS believes that Ofcom working collaboratively with providers in this area will be a positive way to progress.
FCS also questions when providers allocated in Tier 3, (the majority of our members) will be informed of this and recommends that Ofcom working collaboratively with Tier 3 providers to establish exactly what they need to consider and implement, to ensure compliance going forward.
The whole Tier chain (1, 2 & 3) must fully understand their individual responsibilities to ensure communication services and the whole network is secure and that they as a Provider are compliant with security requirements going forward.
FCS questions whether and how the application providers (for applications such as Teams/Zoom etc) ensure the compliance of the applications they supply?
2: Do you have any comments on our proposed approach to testing? FCS supports the proposed Ofcom approach to testing.
3: Do you have any comments on our proposed approach to enforcement? FCS supports the proposed Ofcom approach to enforcement.Â
4: Do you have any comments on our proposed approach to reporting security compromises? FCS asks whether, where security issues are identified, the whole Tier chain will be informed and the issue made public to enhance awareness, increase confidence and enable users of any services impacted to be kept informed.
5: Do you have any comments on our proposed approach to information sharing? FCS asks whether Ofcom proposes to make a list of compliant providers available to enhance confidence in those providers.
6: Do you have any other comments on our draft statement of general policy set out at Annex A5 to this consultation? Questions concerning Ofcom’s draft guidance on resilience requirements in sections 105A to D of the Communications Act 2003 (see Annex A6) FCS believes that any resilience requirements should be appropriately targeted on the capability owner and linked to the appropriate risk.
7: Do you have any comments on our proposed approach to resilience set out in section 4 of the draft guidance at Annex A6 to this consultation? FCS – no comments proposed
8: Do you have any comments on our proposed resilience guidance set out in section 5 of the draft guidance at Annex A6 to this consultation? FCS – no comments proposed
9: Do you have any other comments on our draft guidance set out at Annex A6 to this consultation? FCS proposed response – we encourage Ofcom to work collaboratively with providers on security. FCS is aware that providers have complex, costly and timeconsuming regulatory requirements to plan and complete in challenging timescales (including EECC, One Touch Switching & Number Porting and Moving customer bases to
IP). Our FCS members who are assigned to Tier 2 and in some cases Tier 3, will need strong engagement from Ofcom and clarity around specifically what is required and when, to enable them to plan effectively to ensure compliance with the new security requirements.
Going forward, FCS asks that Ofcom consider a best practice security guide for all future networks, products and service developments to enable and ensure industry best practice and standards that meet and comply with the new security regulation.
