Skip to content

Evidence request lists

ISO/IEC 27011:2024

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Clause 1-4: Introduction and Framework

27011-1
Scope

Defines applicability to telecommunications organizations for baseline information security management

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-2
Normative references

References to ISO/IEC 27001, ISO/IEC 27002:2022, and telecommunications standards

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-3
Terms and definitions

Telecommunications-specific information security terminology

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-4
Structure of this document

Organization of telecom-specific controls aligned with ISO/IEC 27002:2022 structure

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27400-1
Scope

Guidelines on risks, principles, and controls for security and privacy of IoT solutions

Artefacts an auditor will ask for
  • IoT scope statement
  • IoT glossary
  • Concept reference
  • Stakeholder map
Where this commonly fails
  • Scope vague
  • Glossary inconsistent
  • Concepts not internalized
  • Stakeholders missing
27400-3
Terms and definitions

IoT-specific security and privacy terminology

Artefacts an auditor will ask for
  • IoT scope statement
  • IoT glossary
  • Concept reference
  • Stakeholder map
Where this commonly fails
  • Scope vague
  • Glossary inconsistent
  • Concepts not internalized
  • Stakeholders missing
27400-4
IoT overview and concepts

Summary of characteristics, stakeholders, life cycles, and risk sources of IoT systems

Artefacts an auditor will ask for
  • IoT scope statement
  • IoT glossary
  • Concept reference
  • Stakeholder map
Where this commonly fails
  • Scope vague
  • Glossary inconsistent
  • Concepts not internalized
  • Stakeholders missing

Clause 5: Organizational Controls for Telecommunications

27011-5.3
Segregation of duties

Controls for separation of duties in telecommunications operations and service delivery

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-5.4
Threat intelligence for telecom

Telecom-specific threat intelligence including network-based threats and signaling attacks

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-5.5
Information security in project management

Security controls for telecommunications infrastructure and service delivery projects

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-5.6
Supplier relationships and telecom supply chain

Managing supplier security in telecommunications supply chains and interconnections

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal

Clause 6: People Controls for Telecommunications

27011-6.1
Screening of Telecoms Personnel

Screen personnel handling customer data, lawful interception or critical network operations.

Artefacts an auditor will ask for
  • Background check records
  • Sensitive role list
  • Renewal schedule
Where this commonly fails
  • No renewal
  • Sensitive roles unflagged
27011-6.2
Terms and conditions of employment

Information security obligations for telecom employees including confidentiality of customer data

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-6.3
Awareness and Training

Train staff on telecoms specific threats including SIM swap, social engineering and signalling abuse.

Artefacts an auditor will ask for
  • Training curriculum
  • Attendance logs
  • Phishing simulation results
Where this commonly fails
  • SIM swap not covered
  • No simulations
27011-6.4
Remote working

Controls for remote access to telecommunications management and operations systems

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal

Clause 7: Physical Controls for Telecommunications

27011-7.1
Physical security perimeters

Physical security for telecommunications facilities including exchanges, data centers, and cell sites

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-7.2
Physical entry and securing offices

Entry controls and monitoring for telecom facilities and equipment rooms

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-7.3
Equipment protection

Protection of telecommunications equipment including cabling, power supply, and environmental controls

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-7.4
Physical Security of Network Sites

Secure exchanges, data centres, base stations and street cabinets against physical attack and tampering.

Artefacts an auditor will ask for
  • Site security plans
  • Tamper logs
  • Inspection records
Where this commonly fails
  • Street cabinets unmonitored
  • Inspections irregular

Clause 8: Technological Controls for Telecommunications

27011-8.2
Network security and segregation

Telecom network security including signaling security, VPN tunnels, and network segmentation

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-8.3
Cryptography and key management

Cryptographic controls for telecommunications signaling, customer data, and inter-carrier communication

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-8.4
Logging and monitoring

Telecom-specific logging, monitoring, and security event management for network operations

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-8.5
Vulnerability and malware management

Vulnerability management and malware protection for telecommunications infrastructure and services

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-8.6
Data protection and backup

Data protection controls including customer data, call detail records, and service continuity backups

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal

Organisational

27011-5.1
Policies for Information Security in Telecoms

Define telecoms specific information security policies including service continuity and customer confidentiality.

Artefacts an auditor will ask for
  • Telecoms security policy
  • Approval records
  • Customer confidentiality statement
Where this commonly fails
  • Generic policy reused
  • No customer focus
27011-5.10
Acceptable Use of Customer Data

Define acceptable use of customer communications metadata, content and location data.

Artefacts an auditor will ask for
  • Acceptable use policy
  • Training records
  • Audit findings
Where this commonly fails
  • Metadata misuse
  • No staff training
27011-5.15
Access Control for Network Elements

Control privileged access to switches, base stations, OSS and BSS systems with strong authentication.

Artefacts an auditor will ask for
  • Access matrix
  • Privileged session logs
  • Reviews
Where this commonly fails
  • Shared admin accounts
  • No session recording
27011-5.2
Information Security Roles in Telecoms

Assign roles for network operations, lawful interception, fraud and customer data with clear authorities.

Artefacts an auditor will ask for
  • Role catalogue
  • Lawful interception team charter
  • Fraud unit charter
Where this commonly fails
  • Lawful interception roles undefined
  • Fraud roles informal
27011-5.22
Monitoring of Supplier Services

Monitor managed network and platform suppliers including service levels and security obligations.

Artefacts an auditor will ask for
  • SLA dashboards
  • Security review reports
  • Audit rights records
Where this commonly fails
  • No security reviews
  • Audit rights unused
27011-5.23
Cloud and Hosted Telecoms Services

Manage security of cloud and hosted telecoms services including NFV and virtualised network functions.

Artefacts an auditor will ask for
  • NFV security baseline
  • Cloud responsibility matrix
  • Configuration records
Where this commonly fails
  • NFV baseline missing
  • Shared responsibility unclear
27011-5.30
ICT Readiness for Continuity

Ensure telecoms ICT systems are ready to support continuity of critical services including emergency calls.

Artefacts an auditor will ask for
  • Continuity plan
  • Emergency call routing tests
  • Recovery time objectives
Where this commonly fails
  • Emergency call routing untested
  • RTO not validated
27011-5.7
Threat Intelligence for Telecoms

Collect and use telecoms threat intelligence including SS7, signalling, roaming, and customer fraud threats.

Artefacts an auditor will ask for
  • Threat feed subscriptions
  • Signalling threat reports
  • Intelligence sharing logs
Where this commonly fails
  • No signalling intelligence
  • Roaming threats ignored

Physical

27011-7.10
Storage Media Handling in Telecoms

Control storage media containing customer or lawful interception data including secure disposal.

Artefacts an auditor will ask for
  • Media inventory
  • Destruction certificates
  • Chain of custody logs
Where this commonly fails
  • Inventory incomplete
  • Destruction not certified

Technological

27011-8.1
User Endpoint Devices

Secure endpoints used by network operations and customer support including device hardening and MDM.

Artefacts an auditor will ask for
  • MDM policy
  • Hardening baselines
  • Compliance reports
Where this commonly fails
  • Personal devices uncontrolled
  • Baselines drift
27011-8.12
Data Leakage Prevention for Telecoms

Prevent leakage of customer call records, location data and lawful interception data.

Artefacts an auditor will ask for
  • DLP policy
  • Egress monitoring logs
  • Incident reports
Where this commonly fails
  • Lawful interception data unmonitored
  • No egress logging
27011-8.15
Logging of Network and Service Events

Log network element, signalling and service events with retention aligned to legal and operational needs.

Artefacts an auditor will ask for
  • Log policy
  • Retention schedule
  • SIEM coverage matrix
Where this commonly fails
  • Signalling logs missing
  • Retention non compliant
27011-8.16
Monitoring Activities

Monitor network and service activity for fraud, signalling abuse and unauthorised configuration changes.

Artefacts an auditor will ask for
  • Use case catalogue
  • Alert dashboards
  • Fraud detection reports
Where this commonly fails
  • No fraud use cases
  • Config change monitoring absent
27011-8.20
Network Security for Telecoms Core

Secure core network including signalling, transport, IMS and 5G core with documented controls.

Artefacts an auditor will ask for
  • Core architecture diagrams
  • Security baselines
  • Penetration test reports
Where this commonly fails
  • 5G core untested
  • Signalling controls weak
27011-8.21
Security of Network Services

Define security characteristics, SLAs and management of network services offered to customers.

Artefacts an auditor will ask for
  • Service catalogue
  • Security SLA terms
  • Customer reports
Where this commonly fails
  • No security SLAs
  • Service catalogue incomplete
27011-8.22
Segregation of Networks

Segregate customer, management, signalling, and lawful interception networks with controlled gateways.

Artefacts an auditor will ask for
  • Network diagrams
  • Firewall rules
  • Gateway test reports
Where this commonly fails
  • Management plane shared
  • Lawful interception path not isolated
27011-8.24
Use of Cryptography

Apply cryptography to subscriber identifiers, signalling protection and operator interconnects.

Artefacts an auditor will ask for
  • Cryptography policy
  • Algorithm inventory
  • Interconnect protection records
Where this commonly fails
  • Weak algorithms on interconnects
  • SUPI not protected
27011-8.27
Secure System Architecture

Apply secure architecture principles to OSS BSS, signalling, 5G and customer facing platforms.

Artefacts an auditor will ask for
  • Reference architectures
  • Architecture review records
  • Threat models
Where this commonly fails
  • No threat models
  • Architecture drift
27011-8.32
Change Management for Network

Manage changes to network elements, signalling and service platforms with risk and security review.

Artefacts an auditor will ask for
  • Change advisory board minutes
  • Risk assessments
  • Rollback plans
Where this commonly fails
  • Emergency changes unreviewed
  • No rollback tested
27011-8.7
Protection Against Malware

Protect telecoms IT and OSS BSS systems against malware including signalling firewall content.

Artefacts an auditor will ask for
  • AV coverage report
  • Signalling firewall config
  • Incident records
Where this commonly fails
  • Signalling firewall absent
  • AV coverage gaps
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.