CORE MANDATE // ARTICLE 21.2
Entities must implement a minimum set of security measures covering at least ten specific areas, appropriately scaled to their risk profile and size.
a
Risk Analysis & InfoSec Policies
Establish comprehensive policies for risk analysis and information system security.
Telecom Impact: Mapping network assets to specific 5G/Core risk profiles.
c
Business Continuity
Management of backups, disaster recovery, and crisis management procedures.
Telecom Impact: Ensuring 99.999% availability for critical signaling nodes.
e
Supply Chain Security
Security aspects concerning the relationship between each entity and its direct suppliers.
Telecom Impact: Mandatory audits for RAN and Core vendors to detect HRV risks.
g
Cyber Hygiene & Training
Basic cybersecurity practices and hygiene, and cybersecurity training.
Telecom Impact: Specialized training for SOC teams on SS7/Diameter threat hunting.
i
Multi-factor Authentication
Use of MFA or continuous authentication where appropriate.
Telecom Impact: Mandatory MFA for all privileged access to the HLR/HSS and AMF.