release of the lacnog-m3aawg joint best current

6
Release of the LACNOG-M3AAWG Joint Best Current Operational Practices (BCOP) Lucimara Desiderá LAC-AAWG chair

Upload: others

Post on 02-May-2022

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Release of the LACNOG-M3AAWG Joint Best Current

Release of the LACNOG-M3AAWG Joint Best Current

Operational Practices (BCOP) LucimaraDesiderá

LAC-AAWGchair

Page 2: Release of the LACNOG-M3AAWG Joint Best Current

Official release on 08 May 2019 LACNOGandM3AAWGjointBCOP

MinimumSecurityRequirementsforCustomerPremisesEquipment(CPE)Acquisition.

https://www.lacnog.net/docs/lac-bcop-1

https://www.m3aawg.org/CPESecurityBP

Comingsoon–Translationto:•  SpanishandPortuguese

•  JapaneseandKorean(JP-AAWG)

Page 3: Release of the LACNOG-M3AAWG Joint Best Current

Official release on 08 May 2019

Page 4: Release of the LACNOG-M3AAWG Joint Best Current

Why care about CPE Security?

Businessandoperationalimpacts•  Compromisingoftheprovider'snetwork

-  Someoneelseisusingyourresources• Degradationorunavailabilityofservices

-  Youcanloseclients•  Technicalsupportandrepairwork

-  Youarelosingmoney•  ProtectthereputationofyourISP

-  Customers,partnersandblacklists

Page 5: Release of the LACNOG-M3AAWG Joint Best Current

Problems the BCOP addresses

• Standardcredentialsforalargenumberofdevices• Credentialsthatcannotbechanged(hard-coded)• Useofobsoleteandinsecureprotocolsandalgorithms

• Undocumentedaccesses(backdoors)• Lackofautomatedandsecureupdatemechanismstoaddresssecurityissues

• Unnecessaryand/orinsecureservicesenabledbydefault

• Servicesthatcannotbedisabled•  Insecureremotemanagement

Page 6: Release of the LACNOG-M3AAWG Joint Best Current

What is inside? Areferencechecklistforhardwaredecisions→  Let’saskvendorsforbetterproductswhileimprovingournetworks!😀