Telecommunications
42 regulations apply to this sector.
Written for this sector
DMATelecom operators offering core platform services are in scopeEAAElectronic communications services named as in-scope under EAAePrivacy DirectiveDirective written for electronic communications providers and telecom operators.EU Foreign Direct Investment Screening RegulationTelecom networks are listed critical infrastructure subject to FDI review.EUICS2Telecoms operators are central to EU critical sector cyber incident frameworksFCC Equipment AuthorizationTelecom devices and radio equipment must obtain FCC authorization before market entryGDPRTelecoms process customer personal data at scale under GDPR obligations.ISO 22301Telecoms are critical infrastructure requiring formal continuity management.ISO 22313Telecoms use the guidance to structure business continuity programmes.ISO 22322Telecoms provide the infrastructure for public warning and crisis alerts.ISO 27001Telecoms providers use ISO 27001 as a baseline for network security management.ISO 27033Directly applicable to telecoms network security architectureNIS2Telecom providers are named essential entities under NIS2.REDTelecoms equipment must meet RED essential requirements for market access.RED CyberTelecoms equipment must meet cybersecurity essential requirements.Singapore Cybersecurity Act 2018Telecoms identified as critical information infrastructure under the Act.Also applies
Budapest Convention on CybercrimeRequires telecom providers to support lawful interception and data preservationCCPA/CPRATelecoms collecting consumer data subject to CCPA/CPRACIRCIATelecom critical infrastructure must report significant cyber incidentsCISA Cross-Sector Cybersecurity Performance GoalsTelecom is a critical infrastructure sector under CPG scopeCRATelecoms equipment with digital elements falls under CRA scopeCyber Resilience ActTelecom equipment with digital elements falls under CRA product scope.DSATelecom companies offering internet access services are intermediariesEIDAS2Telcos involved in digital identity provision must comply with eIDAS2.EMC DirectiveTelecom equipment must comply with electromagnetic compatibility requirements.EMC Directive 2Telecom equipment subject to updated electromagnetic compatibility rules.India Information Technology Act, 2000Covers network intermediaries and telecom-delivered digital servicesISO 10002Telecoms use ISO 10002 for high-volume customer complaint managementISO 20000Telecoms apply ISO 20000 for managed service and support operationsISO 22317Telecoms apply BIA methodology to prioritise recovery of network services.ISO 22320Telecoms support emergency coordination through critical communications infrastructure.ISO 22361Telecoms executives apply crisis leadership during major network failures.ISO 27002Telecoms apply ISO 27002 controls to network and information security management.ISO 27005Telecoms apply it to manage information security risksISO 27017/27018Telecoms offering cloud services apply both standardsISO 27031Telecoms apply it to maintain continuity of communication servicesISO 27032Telecoms use it to manage security in interconnected cyberspaceISO 27035Telecoms apply it to handle security incidents across networksISO 27701Telecoms handle subscriber personal data requiring privacy managementISO 29100Telecoms apply privacy principles to subscriber data handling systemsISO 31700Telecoms embed privacy by design in network products and servicesUS State Privacy LawsTelecoms collect significant personal data subject to state privacy requirements.TRIZ for Telecommunications
Worked contradictions and resolutions for this sector.
Telecommunications TRIZ