Supply chain security
Shared responsibility of all stakeholders should drive supply chain security. Operators of
communication infrastructure often depend on technology from other suppliers. Major
security risks emanate from the cross-border complexities of an increasingly global supply
chain which provides ICT equipment. These risks should be considered as part of the risk
assessment based on relevant information and should seek to prevent proliferation of
compromised devices and the use of malicious code and functions.
Bearing in mind these perspectives, the chair calls upon a responsible development,
deployment, and maintenance of 5G networks and future communication technologies,
considering the following proposals and best practices.
PRAGUE PROPOSALS
The Chairman suggests following proposals in four distinct categories in preparation for the
roll out of 5G and future networks.
A. Policy
Communication networks and services should be designed with resilience and security
in mind. They should be built and maintained using international, open, consensusbased standards and risk-informed cybersecurity best practices. Clear globally
interoperable cyber security guidance that would support cyber security products and
services in increasing resilience of all stakeholders should be promoted.
Every country is free, in accordance with international law, to set its own national
security and law enforcement requirements, which should respect privacy and adhere
to laws protecting information from improper collection and misuse.
Laws and policies governing networks and connectivity services should be guided by
the principles of transparency and equitability, taking into account the global economy
and interoperable rules, with sufficient oversight and respect for the rule of law.
The overall risk of influence on a supplier by a third country should be taken into
account, notably in relation to its model of governance, the absence of cooperation
agreements on security, or similar arrangements, such as adequacy decisions, as
regards data protection, or whether this country is a party to multilateral, international
or bilateral agreements on cybersecurity, the fight against cybercrime, or data
protection.
B. Technology
Stakeholders should regularly conduct vulnerability assessments and risk mitigation
within all components and network systems, prior to product release and during
system operation, and promote a culture of find/fix/patch to mitigate identified
vulnerabilities and rapidly deploy fixes or patches.
3