Establishment of Mobile Internet Security System Is Urgent; Standardization Must Come First
November 1 news: With the rapid popularization and development of the mobile Internet, mobile Internet security issues have become increasingly prominent and a focus of industry discussion. At the 5th Mobile Internet International Symposium 2011 hosted by China Mobile Group yesterday, security was for the first time set up as an independent sub-forum for discussion, addressing security issues in areas such as smart terminals and cloud computing to safeguard mobile Internet security.
Xiong Sihao, Director of the Telecommunications Security Bureau of the Ministry of Industry and Information Technology (MIIT), stated that since mobile Internet terminals and services are closely related to user interests, malicious behaviors such as unauthorized fee deduction, user information theft, and fraudulent inducement have more prominent impacts and hazards. Therefore, MIIT has launched research on security assessment, focusing on issues such as mobile smart terminals, user information leakage, and mobile malware.
At present, the mobile Internet is characterized by four aspects: network convergence, terminal intelligence, application diversification, and platform openness. This also determines that the mobile Internet is fundamentally different from the telecommunications network. It is a convergence of the Internet and the telecommunications network, and thus carries the security risks inherent in the openness of the Internet.
Yang Jianjun, Deputy Secretary-General of the National Information Security Standardization Technical Committee, noted that the current proliferation of smart terminals provides a breeding ground for security risks. Terminal intelligence has broken the closed nature of traditional mobile phone applications, and the weak protection and self-control capabilities have made terminals one of the main entry points for virus intrusion. Therefore, personal information and security face significant risks.
Yang Jianjun stated that traditional information security standardization in China has mainly focused on the physical layer, while in the mobile Internet field, information content security and business application security are required, making standardization an important issue. It is understood that there are currently many organizations involved in mobile Internet information security standardization, with a lack of coordination among related standards, and more basic standards than dedicated ones.
In response to the information security system, China Mobile has proposed the "Fence Model" methodology, implementing MIIT's information security responsibility system, complying with information security compliance requirements, and following the guiding principle of shared responsibility and joint management. The approach progresses from person-to-person supervision to joint defense, continuously advancing information security management in a spiral manner.
Zhang Bin, Deputy General Manager of the Information Security Management Department of China Mobile Group, stated that the Fence Model uses business processes as the fence rails and information security management responsibilities, institutional development, and technical measures as the fence posts. Based on planning, service, control, and improvement, it promotes the integration of business processes with information security responsibilities and business systems, supported by corresponding technical measures. By continuously refining and improving the information security responsibilities and requirements of each process link, it deeply advances information security management.
