{"id":25120,"date":"2022-07-09T16:32:02","date_gmt":"2022-07-09T20:32:02","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=492009"},"modified":"2022-07-18T11:02:30","modified_gmt":"2022-07-18T15:02:30","slug":"worried-about-your-firms-internet-and-telecom-resiliency-ask-these-questions","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/worried-about-your-firms-internet-and-telecom-resiliency-ask-these-questions\/","title":{"rendered":"Worried About Your Firm\u2019s Internet And Telecom Resiliency? Ask These Questions"},"content":{"rendered":"<p data-ar-index=\"0\">The cross-Canada internet and wireless outages caused by last week\u2019s <a href=\"https:\/\/www.itworldcanada.com\/article\/rogers-network-down-across-canada\/491911\" rel=\"noopener\">incident at Rogers Communications<\/a> should make corporate telecom and IT decision-makers think carefully about telecom resiliency in the services they buy.<\/p>\n<p data-ar-index=\"1\">There is help: In 2006 the U.K.\u2019s National Infrastructure Security Co-ordination Centre <a href=\"https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/85910\/flu_niscc.pdf\" rel=\"noopener\">issued a good practice guide<\/a> to help organizations there make those decisions. The advice is still good and applies to organizations in any country.<\/p>\n<p data-ar-index=\"2\">Here are some of the highlights:<\/p>\n<p data-ar-index=\"3\">\u2013know your communications system requirements. Identify communications systems that are deemed mission-critical, and which carry a high risk to the organization if they are disrupted;<\/p>\n<p data-ar-index=\"4\">\u2013analyze the threats and vulnerabilities to the mission-critical high-risk services (for example, natural disaster, malicious attack, single point of failure, commercial dependency, lack of transparency);<\/p>\n<p data-ar-index=\"5\">\u2013challenge the service provider to explain the marketing statements made on its resilience and availability. In some cases, you might need to ensure that you are talking to the right provider representative;<\/p>\n<p data-ar-index=\"6\">\u2013focus on the services you require, not the technology;<\/p>\n<p data-ar-index=\"7\">\u2013apply rigorous due diligence in selecting the service provider, including assurance that they have visibility and control over the services they deploy to ensure that separacy (which ensures that specified circuits are physically separated throughout the network so that there are no common exchanges, interconnection points, or cable routes) and diversity (which ensures that the specified circuits are not routed over the same cables or transmission systems) is provided and maintained. Also ensure they have adequate contingency plans in place to recover from a disaster.<\/p>\n<p data-ar-index=\"8\">\u2014 recognize that high availability and high resilience services will cost more than standard services, but don\u2019t use cost as the main criterion when procuring these services.<\/p>\n<p data-ar-index=\"9\">The report differentiates between best practices (measures that can be taken to guarantee resilience, irrespective of cost) and good practices (measures that provide a degree of resilience relating to corporate risk strategy).<\/p>\n<p data-ar-index=\"10\">One option for organizations is paying for internet failover, where the provider switches to a different network if the main network goes down. Many ISPs \u2014 including Bell, Rogers and Telus \u2014 provide this service. For example, a wired service may switch to a wireless service. However, the report makes clear that telecom and IT buyers have to clarify if the failover is to an alternate network from the same provider. That may not provide the needed resiliency.<\/p>\n<p data-ar-index=\"11\">The U.K. report suggests organizations ask themselves questions like:<\/p>\n<p data-ar-index=\"12\">\u2013do you have a full and complete list of your business-critical telecommunications services, and the critical systems that support them, as well as ranking those services by criticality?<\/p>\n<p data-ar-index=\"13\">\u2013can you identify the telecommunications services that support your critical systems and name them in a way that you and the provider know you\u2019re talking about the same thing?<\/p>\n<p data-ar-index=\"14\">\u2013are you aware of where in the provider\u2019s core network your network services connect, how they are connected, and the physical routings they take once they leave your premises?<\/p>\n<p data-ar-index=\"15\">\u2013if you are using dual providers, are you confident that there are no physical routings or points of failure common to both providers?<\/p>\n<p data-ar-index=\"16\">\u2013within your own premises do you have visibility of your telecommunications services all the way into the provider\u2019s duct? Are any parts of the cabling, for example, exposed to external contractors or others beyond your control? Are there any third-party components, such as ADSL routers, which may fall between areas of responsibility?<\/p>\n<p data-ar-index=\"17\">\u2013do all of your services leave your premises in the same cable? Are they all in the same duct?<\/p>\n<p data-ar-index=\"18\">\u2013do you know if critical services are routed via different network components so that a failure of one component will not affect all critical services?<\/p>\n<p data-ar-index=\"19\">\u2013when you order new services, do you discuss your existing services to ensure there are no dangerous assumptions made about separacy or diversity?<\/p>\n<p data-ar-index=\"20\">\u2013do you regularly review your specific resilience requirements with your provider?<\/p>\n<p data-ar-index=\"21\">\u2013do you have primary and alternate methods for contacting your provider (e.g. telephone, e-mail). Have you provided your provider with alternative contact details for your own response teams? Have you discussed your respective emergency plans with your provider?<\/p>\n<p data-ar-index=\"22\">The U.K. report also suggests questions to ask the provider. One of the most important is:<\/p>\n<p data-ar-index=\"23\">\u2013can we work together on business continuity planning and disaster recovery, including testing to provide network assurance?<\/p>\n<p data-ar-index=\"24\">In 2019, Todd Rychecky, vice president of Americas for Opengear, <a href=\"https:\/\/www.thefastmode.com\/expert-opinion\/15552-achieving-network-resilience-in-the-telecoms-industry\" rel=\"noopener\">wrote a column with similar advice<\/a>, including this: \u201cBy continually reminding those outside of the IT department how much money network resilience can save the organization, IT teams within telecom organizations will have greater luck implementing resilience into their networks.\u201d<\/p>\n<p data-ar-index=\"25\">The post <a href=\"https:\/\/www.itworldcanada.com\/article\/worried-about-your-firms-internet-and-telecom-resiliency-ask-these-questions\/492009\">Worried about your firm\u2019s internet and telecom resiliency? Ask these questions<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A report suggests questions firms should ask themselves and their service providers to better assure telcom<\/p>\n","protected":false},"author":17,"featured_media":20693,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16,422],"tags":[391,585,393,586,275],"class_list":["post-25120","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-supply-chain","tag-di","tag-reliability","tag-security-strategies","tag-telecom","tag-top-story"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/25120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=25120"}],"version-history":[{"count":4,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/25120\/revisions"}],"predecessor-version":[{"id":25590,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/25120\/revisions\/25590"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media\/20693"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=25120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=25120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=25120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}