Brazil’s ANATEL Resolution 740/2020, the Cyber Security Regulation Applied to the Telecommunications Sector, enters into force today, with a 180-day adaptation period for providers.
Key points
- Telecoms providers must adopt a cyber security policy.
- Providers must carry out cyber security risk management.
- Relevant incidents must be reported to ANATEL.
- Providers must assess the security of their suppliers.
UK suppliers of network equipment and services to Brazilian operators should expect security questionnaires and contractual requirements flowing from the regulation. Providers are also expected to follow recognised good practice, such as ISO/IEC 27001, when designing their security controls and supplier assessments.
Source: ANATEL Resolution No. 740/2020 (ANATEL)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.