Entities must implement a minimum set of security measures covering at least ten specific areas, appropriately scaled to their risk profile and size.

a

Risk Analysis & InfoSec Policies

Establish comprehensive policies for risk analysis and information system security.

Telecom Impact: Mapping network assets to specific 5G/Core risk profiles.
c

Business Continuity

Management of backups, disaster recovery, and crisis management procedures.

Telecom Impact: Ensuring 99.999% availability for critical signaling nodes.
e

Supply Chain Security

Security aspects concerning the relationship between each entity and its direct suppliers.

Telecom Impact: Mandatory audits for RAN and Core vendors to detect HRV risks.
g

Cyber Hygiene & Training

Basic cybersecurity practices and hygiene, and cybersecurity training.

Telecom Impact: Specialized training for SOC teams on SS7/Diameter threat hunting.
i

Multi-factor Authentication

Use of MFA or continuous authentication where appropriate.

Telecom Impact: Mandatory MFA for all privileged access to the HLR/HSS and AMF.