Showing posts with label ETSI. Show all posts
Showing posts with label ETSI. Show all posts

Sunday, January 24, 2021

Cyber: Cyber Security for Consumer Internet of Things (IoT)

 


Still olden but golden, when it comes to IoT Connected Devices


I have briefly touched upon IoT (Internet of Things) at my blog previously:

Fast moving wireless world

https://trewmte.blogspot.com/2014/10/fast-moving-wireless-world.html

The Internet of Things (IoT)

https://trewmte.blogspot.com/2016/03/the-internet-of-things-iot.html

The Rise of (IoT) Domestic Appliance Forensic Examiners

https://trewmte.blogspot.com/2016/03/the-rise-of-iot-domestic-appliance.html

Smart Phones with Smart Homes

https://trewmte.blogspot.com/2016/06/smart-phones-with-smart-homes.html

eSIM - Observing Possible Outcomes Part 1

https://trewmte.blogspot.com/2019/12/esim-observing-possible-outcomes-part-1.html


I am adding update reference materials available on IoT and Cyber, if you haven't seen this info or weren't aware, which you might find useful.

ETSI in February 2019 released the first globally applicable standard for consumer IoT security:

etsi-releases-first-globally-applicable-standard-for-consumer-iot-security?jjj=1611490283528

This publicised event introduced the ETSI Stand ts_103645v010101 (2019)

CYBER; Cyber Security for Consumer Internet of Things

ts_103645v010101p.pdf

In 2020 ETSI updated the standard ts_103645v020102 with enhanced baseline requirements:

CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements

ts_103645v020102p.pdf

The object of these standards is to improve security and privacy. A common default password for all products are to be scrubbed with a unique default password per device applied instead. Moreover, it should not be possible to enable the password set at default in the first place once user changed. Apparently, many IoT (consumer) products on the market may still not (even today) meet this password objectives or other more basic requirements that have been stated in this newly released standard. 

Measures vendor companies should understake range from adopting simple installation and user guidance with good documentation in support; good hardware/software security engineering practice; for personal privacy the standard sets out protection objectives for all sensitive personal data required to be stored securely - that is both on devices, themselves, and in any related services e.g. in the cloud. Any personal data should be encrypted and should be protected against attack; and with clear instructions how consumers can easily delete their personal data.

Whilst this standard provides consumers with confidence in their IoT product, it equally has been designed to allow vendors companies sufficient flexibility to enable them to innovate and find the best solution for security and privacy for their particular IoT products. Password protection, encryption, and safe deletion are some solutions. Others could be block-off network ports; close-off software not being used; avoidance of exploited data (OOR) by adoption of a validation approach; secure-boot mechanisms (hardward-based); with ease and secure device software updates (e.g. use- menu selection or autonomic/automated (e.g. ZTP etc)). These are possible solutions.

I did like that ETSI had included specific demands about disclosure in this standard for vendor companies to identify, act upon and promptly report vulnerabilities.

However, from a cyber aspect, the ETSI Technical Committee on Cybersecurity (TC CYBER) has overseen and published over 50 cyber standards, some of which are referenced below:

ETSI TS 103 744 V1.1.1 (2020-12)Published

CYBER; Quantum-safe Hybrid Key Exchanges


ETSI TS 103 523-1 V1.1.1 (2020-12)Published

CYBER; Middlebox Security Protocol; Part 1: MSP Framework and Template Requirements


ETSI TS 103 718 V1.1.1 (2020-10)Published

CYBER; External encodings for the Advanced Encryption Standard


ETSI TR 103 644 V1.2.1 (2020-09)Published

CYBER; Observations from the SUCCESS project regarding smart meter security


ETSI TS 103 485 V1.1.1 (2020-08)Published

CYBER; Mechanisms for privacy assurance and verification


ETSI TR 103 619 V1.1.1 (2020-07)Published

CYBER; Migration strategies and recommendations to Quantum Safe schemes


ETSI EN 303 645 V2.1.1 (2020-06)Published

CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements


ETSI TS 103 645 V2.1.2 (2020-06)Published

CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements


ETSI TR 103 306 V1.4.1 (2020-03)Published

CYBER; Global Cyber Security Ecosystem


ETSI TR 103 644 V1.1.1 (2019-12)Published

CYBER; Increasing smart meter security


ETSI TR 103 618 V1.1.1 (2019-12)Published

CYBER; Quantum-Safe Identity-Based Encryption


ETSI TR 103 331 V1.2.1 (2019-09)Published

CYBER; Structured threat information sharing


ETSI TS 103 523-3 V1.3.1 (2019-08)Published

CYBER; Middlebox Security Protocol; Part 3: Enterprise Transport Security


ETSI TS 103 523-3 V1.2.1 (2019-03)Published

CYBER; Middlebox Security Protocol; Part 3: Enterprise Transport Security


ETSI TS 103 645 V1.1.1 (2019-02)Published

CYBER; Cyber Security for Consumer Internet of Things


ETSI TR 103 370 V1.1.1 (2019-01)Published

CYBER; Practical introductory guide to Technical Standards for Privacy


ETSI TS 103 457 V1.1.1 (2018-10)Published

CYBER; Trusted Cross-Domain Interface: Interface to offload sensitive functions to a trusted domain


ETSI TR 103 642 V1.1.1 (2018-10)Published

CYBER; Security techniques for protecting software in a white box model


ETSI TS 103 523-3 V1.1.1 (2018-10)Published

CYBER; Middlebox Security Protocol; Part 3: Profile for enterprise network and data centre access control


ETSI TR 103 617 V1.1.1 (2018-09)Published

CYBER; Quantum-Safe Virtual Private Networks


ETSI TR 103 305-1 V3.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 1: The Critical Security Controls


ETSI TR 103 305-2 V2.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 2: Measurement and auditing


ETSI TR 103 305-3 V2.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 3: Service Sector Implementations


ETSI TR 103 305-5 V1.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 5: Privacy enhancement


ETSI TR 103 305-4 V2.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 4: Facilitation Mechanisms


ETSI TR 103 306 V1.3.1 (2018-08)Published

CYBER; Global Cyber Security Ecosystem


ETSI TS 103 458 V1.1.1 (2018-06)Published

CYBER; Application of Attribute Based Encryption (ABE) for PII and personal data protection on IoT devices, WLAN, cloud and mobile services - High level requirements


ETSI TS 103 307 V1.3.1 (2018-04)Published

CYBER; Security Aspects for LI and RD Interfaces


ETSI TS 103 532 V1.1.1 (2018-03)Published

CYBER; Attribute Based Encryption for Attribute Based Access Control


ETSI TR 103 456 V1.1.1 (2017-10)Published

CYBER; Implementation of the Network and Information Security (NIS) Directive


ETSI TS 102 165-1 V5.2.3 (2017-10)Published

CYBER; Methods and protocols; Part 1: Method and pro forma for Threat, Vulnerability, Risk Analysis (TVRA)


ETSI TR 103 570 V1.1.1 (2017-10)Published

CYBER; Quantum-Safe Key Exchanges


ETSI TR 103 421 V1.1.1 (2017-04)Published

CYBER; Network Gateway Cyber Defence


ETSI TR 103 306 V1.2.1 (2017-03)Published

CYBER; Global Cyber Security Ecosystem


ETSI TS 103 307 V1.2.1 (2016-10)Published

CYBER; Security Aspects for LI and RD Interfaces


ETSI TR 103 305-2 V1.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 2: Measurement and auditing


ETSI TR 103 305-3 V1.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 3: Service Sector Implementations


ETSI TR 103 305-4 V1.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 4: Facilitation Mechanisms


ETSI TR 103 305-1 V2.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 1: The Critical Security Controls


ETSI TR 103 331 V1.1.1 (2016-08)Published

CYBER; Structured threat information sharing


ETSI TR 103 304 V1.1.1 (2016-07)Published

CYBER; Personally Identifiable Information (PII) Protection in mobile and cloud services


ETSI TR 103 369 V1.1.1 (2016-07)Published

CYBER; Design requirements ecosystem


ETSI EG 203 310 V1.1.1 (2016-06)Published

CYBER; Quantum Computing Impact on security of ICT Systems; Recommendations on Business Continuity and Algorithm Selection


ETSI TS 103 307 V1.1.1 (2016-04)Published

CYBER; Security Aspects for LI and RD Interfaces


ETSI TR 103 303 V1.1.1 (2016-04)Published

CYBER; Protection measures for ICT in the context of Critical Infrastructure


ETSI TS 103 487 V1.1.1 (2016-04)Published

CYBER; Baseline security requirements regarding sensitive functions for NFV and related platforms


ETSI TR 103 308 V1.1.1 (2016-01)Published

CYBER; Security baseline regarding LI and RD for NFV and related platforms


ETSI TR 103 306 V1.1.1 (2015-11)Published

CYBER; Global Cyber Security Ecosystem


ETSI TR 103 309 V1.1.1 (2015-08)Published

CYBER; Secure by Default - platform security technology


ETSI TR 103 305 V1.1.1 (2015-05)Published

CYBER; Critical Security Controls for Effective Cyber Defence

Sunday, October 29, 2017

New Cyber Report recognises legal actions

June 2015 I sketched foreseen legal actions impacting on cybercrime. I posted a diagram-infographic in Feb 2016 "LEGALLY SPEAKING – OBSERVATIONS CHART FOR JUDGES BARRISTERS AND SOLICIT0RS" - http://trewmte.blogspot.co.uk/2016/02/threatware-legally-speaking.html.

I am pleased to see that ETSI (European Telecommunications Standards Institute) have also picked up on my themes in their 2017 published technical report (TR) CYBER; Implementation of the Network and Information Security (NIS) Directive ETSI TR 103 456 V1.1.1 (2017-10) with reference to Contract, Tort and Crime.



Saturday, June 25, 2016

British business back to work Monday morning

British business back to work Monday morning



Have a look at this excellent example of learning from poster (above) showing a sector of business that involves global market players. Can Brexit stop this happening? Of course not. All the players including British players will continue because there is absolutely no reason to end the relationship.

Look at some other aspects in the financial sector that never get as much promotion relating to British achievement within global markets. Great Britain is and has been for many, many years an essential contributor to the secure transactions industry. From an array of new concepts, such as transport cards, electronic purse, open OS, open loop etc. these originated and are efficiently developed by British companies. Globally, including EU member states, developers collaborated with British companies and recognised this by setting up a presence in Britain including investing in offices, plant and machinery, laboratories, etc. to ensure that the collaboration works. This won’t change either because of Brexit as these markets are global and feed into EU. To dismantle this area (which has absolutely nothing to do with a British sovereignty decision) might turn the tables and adversely affect EU member’s states unnecessarily scrambling to reform something that is already works perfectly well.

London is acknowledged as probably the leading financial place in Europe, which I believe is still undisputed. This has enabled traditional financial institutions and the FinTech sector to be the most advanced in Europe through adopting British innovation and new technologies.  Britain has the highest level of penetration and usage of contactless banking cards and POS terminals which is also acknowledged globally and in Europe.

Moreover, and unsurprisingly, Britain is at the forefront for developments and innovation concerning mWallets adoption:

- Paym,
- Pingit,
- bPay
- Zapp

Global players have also launched FIN-product in the UK too such as Apple Pay and Android Pay and now Samsung Pay will soon join the British marketplace, too. These are great global players who understand that choices at the domestic level shouldn't throttle business. And these players didn't settle here simply for our wonderful British charm (although I suspect maybe this gives them a warm feeling also) but due to their acumen, professionalism, maturity, awareness and, equally, astute nature they know Britain is not frightened by FinTech. Transports for London (TfL) is a glowing international success story demonstrating how Britain introduced the first large-scale transport network to have successfully adopted open loop payments for customers.

Lastly, all the new developments in the secure transactions industry that have been happening over the last years have been happening in Britain and which Britain is happy to work with and share the knowledge, skillsets, experience and successes with our European neighbours and friends. That position was not brought about nor has it anything to with Britain wanting to retain its own sovereignty.

What is important which Britain does acknowledge very sincerely is participating in standardisation and working closely with European Telecommunications Standards Institute (ETSI). Britain's adoption of mobile ecommerce again aided by Britain being one of the most advance countries globally for mobile communications and using advanced evolved mobile networks, platforms and applications assist keeping ETSI informed. This association and work is complemented by Britain's involvement and work globally with the International Telecommunications Union (ITU). Apologies for repeating myself but, here again, this close and successful involvement has not and has nothing to with Britain retaining its own sovereignty, but everything to do with technology advancements and success that can benefit all.

Saturday, September 14, 2013

sim2usim


Examination and Evidence from SIM and USIM Cards. Now an open blog. 

http://sim2usim.blogspot.co.uk/


(U)SIM Examination (Physical) Pt2

(U)SIM Examination (Physical) Pt2

Before we can progress to consider various methods of (U)SIM physical examination there are more standards we need to be aware and there are reasons for that. Transitioning from GSM to 3GPP (*wcdma) standards required rewriting existing GSM standards to make the standards technology neutral to integrate GSM into future mobile developments under 3GPP global standards. Technology-wise, we know that GSM is a defined circuit-switched voice mobile communications system that has evolved with value-added data services (GPRS, HSCSD and EDGE). 3GPP (wcdma) as we know is a defined packet-switched technology and thus would be a pointless exercise to re-invent the wheel, so to speak, and introduce a new voice circuit-switched system and the matured installation base that went with it. That needs to be understood on many levels when dealing with mobile communications. Three examples of GSM and 3GPP working together:

(i) generally, we refer to Release 99 (R99) as a reference point whereby 3GPP could transition and re-write mobile communication technology standards with birthing-periods: GSM only before 3GPP Release 4 (Rel-4); GSM only (Rel-4 and later); 3GPP and beyond / GSM (R99 and later).  This enabled manufacturers, developers and operators and service providers to conintue with GSM standards in a pure GSM environment or evolve to a 3GPP environment but in the knowledge access and inter-connectivity to GSM would continue:

(ii) introduction of 3GPP (*wcdma) would take time and thus should avoid, as best possible, disruption to existing moble services;

(iii) GSM user/subscriber base was still growing at that time and has now reached over 3-billion users, from which we can draw a conclusion that GSM's importance in its relationship with 3GPP should not be under-estimated.GSM is by no means the junior partner.

In the mobile examination environment, we, as examiners, are exposed to multitude and multiple-layers of technical and technology standards many of which impact on (U)SIM, and particuarly so if the technical and technology generates a mobile communication outcome associated to/with a user/subscriber. 

(*) wcdma is one of a family of mobile technology standards under 3GPP and has been used for easy of reference. 

The scope of the tests and the requirements set down in GSM1117 were reproduced under the approved and adopted standard 3GPP TS51.017. In Pt1( usim-examination-physical-pt1.html ) reference was made to GSM11.11, however the approved and adopted standard (and the counterpart to GSM11.11) is 3GPP TS51.011:

PHY:    Physical characteristics - 3GPP TS 51.011 [1], clause 4.
ELEC:    Electronic signals and transmission protocols - 3GPP TS 51.011 [1], clause 5.
AFS:    Application and File structure - 3GPP TS 51.011 [1], clause 6.
SEC:    Security features - 3GPP TS 51.011 [1], clause 7.
CMD:    Description of the commands - 3GPP TS 51.011 [1], clause 9.
CEF:    Contents of the elementary files - 3GPP TS 51.011 [1], clause 10.
APP:    Application Protocol - 3GPP TS 51.011 [1], clause 11.

Whilst GSM11.17 standard is the starting point for ICC/SIM and 3GPP TS51.011 moved the technology to neutral ground to enable 3GPP to evolve 3G environment standards incorportating interconnectivity to and backward compatibility for ICC/UICC, the 3GPP evolution hasn't stopped there. There is, of course, 3GPP TS 31.120 the aim of which is to ensure interoperability between an UICC and a Terminal independently of the respective manufacturer, card issuer or operator. This is the expansion of the 3GPP domain going beyond specific limitations encumbent with a particular proprietory technology.

The run of standards doesn't end there. Attention and consideration should be given to:

ETSI standards
TS 102 230
TS 102 221

International standards
ISO/IEC 7816-pt1 to pt4

The standards referred to above are merely a starting point to identify the complexities involved in dealing with (U)SIM card and tasks involved in considering examination techniques that may not simply relate to recovery of data but other aspects and attributes of a card which may point to evidence. Readers should be prepared to delve into the standards above and release the huge number that haven't been mentioned. There are various analogies that may be used to imagine what I have in mind for this physical series, but I quite like the analogy about forensic vehicle tyre analysis. Evidentially, consideration is given to tyre size, tread, pressure, rubber, moulding, any wheel balacing and so on to assess a skid mark or tracks at the scene of a crime. It is equally possible to use an investigative and examination approach to SIM/USIM card materials, contacts, gold content, embossing etc to identify potential evidence.

Monday, May 06, 2013

(U)SIM Examination (Physical) Pt2

(U)SIM Examination (Physical) Pt2

Before we can progress to consider various methods of (U)SIM physical examination there are more standards we need to be aware and there are reasons for that. Transitioning from GSM to 3GPP (*wcdma) standards required rewriting existing GSM standards to make the standards technology neutral to integrate GSM into future mobile developments under 3GPP global standards. Technology-wise, we know that GSM is a defined circuit-switched voice mobile communications system that has evolved with value-added data services (GPRS, HSCSD and EDGE). 3GPP (wcdma) as we know is a defined packet-switched technology and thus would be a pointless exercise to re-invent the wheel, so to speak, and introduce a new voice circuit-switched system and the matured installation base that went with it. That needs to be understood on many levels when dealing with mobile communications. Three examples of GSM and 3GPP working together:

(i) generally, we refer to Release 99 (R99) as a reference point whereby 3GPP could transition and re-write mobile communication technology standards with birthing-periods: GSM only before 3GPP Release 4 (Rel-4); GSM only (Rel-4 and later); 3GPP and beyond / GSM (R99 and later).  This enabled manufacturers, developers and operators and service providers to conintue with GSM standards in a pure GSM environment or evolve to a 3GPP environment but in the knowledge access and inter-connectivity to GSM would continue:

(ii) introduction of 3GPP (*wcdma) would take time and thus should avoid, as best possible, disruption to existing moble services;

(iii) GSM user/subscriber base was still growing at that time and has now reached over 3-billion users, from which we can draw a conclusion that GSM's importance in its relationship with 3GPP should not be under-estimated.GSM is by no means the junior partner.

In the mobile examination environment, we, as examiners, are exposed to multitude and multiple-layers of technical and technology standards many of which impact on (U)SIM, and particuarly so if the technical and technology generates a mobile communication outcome associated to/with a user/subscriber. 

(*) wcdma is one of a family of mobile technology standards under 3GPP and has been used for easy of reference. 

The scope of the tests and the requirements set down in GSM1117 were reproduced under the approved and adopted standard 3GPP TS51.017. In Pt1( usim-examination-physical-pt1.html ) reference was made to GSM11.11, however the approved and adopted standard (and the counterpart to GSM11.11) is 3GPP TS51.011:

PHY:    Physical characteristics - 3GPP TS 51.011 [1], clause 4.
ELEC:    Electronic signals and transmission protocols - 3GPP TS 51.011 [1], clause 5.
AFS:    Application and File structure - 3GPP TS 51.011 [1], clause 6.
SEC:    Security features - 3GPP TS 51.011 [1], clause 7.
CMD:    Description of the commands - 3GPP TS 51.011 [1], clause 9.
CEF:    Contents of the elementary files - 3GPP TS 51.011 [1], clause 10.
APP:    Application Protocol - 3GPP TS 51.011 [1], clause 11.

Whilst GSM11.17 standard is the starting point for ICC/SIM and 3GPP TS51.011 moved the technology to neutral ground to enable 3GPP to evolve 3G environment standards incorportating interconnectivity to and backward compatibility for ICC/UICC, the 3GPP evolution hasn't stopped there. There is, of course, 3GPP TS 31.120 the aim of which is to ensure interoperability between an UICC and a Terminal independently of the respective manufacturer, card issuer or operator. This is the expansion of the 3GPP domain going beyond specific limitations encumbent with a particular proprietory technology.

The run of standards doesn't end there. Attention and consideration should be given to:

ETSI standards
TS 102 230
TS 102 221

International standards
ISO/IEC 7816-pt1 to pt4

The standards referred to above are merely a starting point to identify the complexities involved in dealing with (U)SIM card and tasks involved in considering examination techniques that may not simply relate to recovery of data but other aspects and attributes of a card which may point to evidence. Readers should be prepared to delve into the standards above and release the huge number that haven't been mentioned. There are various analogies that may be used to imagine what I have in mind for this physical series, but I quite like the analogy about forensic vehicle tyre analysis. Evidentially, consideration is given to tyre size, tread, pressure, rubber, moulding, any wheel balacing and so on to assess a skid mark or tracks at the scene of a crime. It is equally possible to use an investigative and examination approach to SIM/USIM card materials, contacts, gold content, embossing etc to identify potential evidence.

Monday, June 04, 2012

CSA - R&TTE Directive

R&TTE Directive applies to telecommunications and radio equipment and therefore is applicable to examiners and advisors involved with forensics and evidence:

Directive 1999/5/EC of the European Parliament and of the Council of 9 March 1999 on radio equipment and telecommunications terminal equipment and the mutual recognition of their conformity....
[Official Journal L 091 , 07/04/1999 P. 0010 - 0028]
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31999L0005:EN:HTML

In fact it is inescapable, thus unavoidable, that an examiner / advsior could not at some stage make reference to R&TTE given the scope of the work involved in CSA (cell site analysis).


The Directive sets out the Essential Requirements, which members states should follow and in turns places obligations incumbent on network operators and manufacturers placing or using equipment in a member state governed by the principles in [the] Directive.  

Article 3
Essential requirements
1. The following essential requirements are applicable to all apparatus:
(a) the protection of the health and the safety of the user and any other person, including the objectives with respect to safety requirements contained in Directive 73/23/EEC, but with no voltage limit applying;
(b) the protection requirements with respect to electromagnetic compatibility contained in Directive 89/336/EEC.
2. In addition, radio equipment shall be so constructed that it effectively uses the spectrum allocated to terrestrial/space radio communication and orbital resources so as to avoid harmful interference.
3. In accordance with the procedure laid down in Article 15, the Commission may decide that apparatus within certain equipment classes or apparatus of particular types shall be so constructed that:
(a) it interworks via networks with other apparatus and that it can be connected to interfaces of the appropriate type throughout the Community; and/or that
(b) it does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service; and/or that
(c) it incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected; and/or that
(d) it supports certain features ensuring avoidance of fraud; and/or that
(e) it supports certain features ensuring access to emergency services; and/or that
(f) it supports certain features in order to facilitate its use by users with a disability.

The connection to CSA initially comes by way of harmonised standards (ENs) defining the radio requirements that are required to conform across EEC (EU) members states. That is conformance is intended to act as an enabler to ensure EEC (EU) principles to be achieved and succeed relating to the free movement of goods and the reduction and removal of trade barriers brought about by mandatory regulation.

Such an example can be immediately demonstrated by reference to:
*The Radio Equipment and Telecommunications Terminal Equipment Regulations 2000 No. 730 PART II
http://www.legislation.gov.uk/uksi/2000/730/part/II/made
http://www.legislation.gov.uk/uksi/2000/730/pdfs/uksi_20000730_en.pdf

*It should be noted that this UK Regulation applies a different numbering sequence when referencing the Essential Requirements

The European Telecommunication Standards Institute (ETSI) has translated the Essential Requirements in the Directive and modularised them in order to assist and enable standards to be produced that create a level playing field for conformance but, at the same time, allowing for innovation and variation in function and technqiue in achievement of the conformance.



In practice the modularised structure (c) ETSI 2000-2003 defines those modules against which standards have been produced. Clearly 3.2 is immediately discernable as having relevance to CSA, thus applicable to examiners to have awareness about the module when performing CSA. Of course the other modules play an important part in varying aspects of CSA and mobile phone investigations, too. The focus though of this discussion is on CSA and making use of the illustration without being verbose on every subject that the illustration refers. The relevance, then, to CSA is that is were device conformance to the standards not to be achieved and not pass technical scrutiny and assessment wireless devices would be unlikely to be allowed to make and receive mobile communications (V/D/F).

To this extent, the spectrum module and its standards associated with it directly relates to defining the use of aspects of the laws of physics, in radio terms, and through setting requirements for radio signalling allow real world realisation of the commodities that that can bring, such as voice and data communications. The standards, underpinned by conformance tests, actually define voice and data communications and the expectation of their performance. If that wasn't possible translating activity in the ether to the physical world would not allow interconnecion; the use of SS7; mobile SCCP; and a very primary form of evidence noted by the mobile academic author (Heine, G), illustrates (c) 1998 in his illustrated model realting to CaPD and CdPD (calling party address and called party address) as seen in the image below. That interconnecion record of a call or, at minimum, an attempt of a call (0-second duration etc) is vitally important for CSA and mobile investigations.


Finally, the above merely discusses a grain of sand relating to technical realisation and end-point evidence and applying the same focus above to other aspects that can (for forensics, evidence and mobile phone investigation) uncover a rich seam of material that can equally be applied to discernng how events may have occurred such as (unlawful) interception, in the course of transmission, signal jamming, voicemail hacking, fake and bogus mobile communications, mobile location tracing etc etc etc, that could be profiled and traced due to having an understanding of what is happening when making use of radio signals in mobile communications and its impact on the sending/receiving device.