Skip to main content

Security governance

Understand the security and privacy risks you need to consider and how to assess and mitigate them.

Overview

The purpose of security and privacy governance is twofold:

  • To present a high-level assessment of the security and privacy risks that developers need to think about when implementing elements of the Open Digital Architecture (ODA) ecosystem.
  • To provide guidance and a clear starting point for the detailed risk assessment and mitigations required to implement and deploy ODA components and agents.

Why is it important?

While traditional, monolithic OSS/BSS systems can be security hardened at their physical boundaries, AI enabled solutions require a shift to a model-driven, component-based method that increases the attack surface. To mitigate this risk, TM Forum and its members are creating a security and privacy governance framework based on DevOps principles and practices, zero-trust principles and software-defined security perimeters.