ISO/IEC 27011:2024
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Clause 1-4: Introduction and Framework
Defines applicability to telecommunications organizations for baseline information security management
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
References to ISO/IEC 27001, ISO/IEC 27002:2022, and telecommunications standards
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Telecommunications-specific information security terminology
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Organization of telecom-specific controls aligned with ISO/IEC 27002:2022 structure
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Guidelines on risks, principles, and controls for security and privacy of IoT solutions
- IoT scope statement
- IoT glossary
- Concept reference
- Stakeholder map
- Scope vague
- Glossary inconsistent
- Concepts not internalized
- Stakeholders missing
IoT-specific security and privacy terminology
- IoT scope statement
- IoT glossary
- Concept reference
- Stakeholder map
- Scope vague
- Glossary inconsistent
- Concepts not internalized
- Stakeholders missing
Summary of characteristics, stakeholders, life cycles, and risk sources of IoT systems
- IoT scope statement
- IoT glossary
- Concept reference
- Stakeholder map
- Scope vague
- Glossary inconsistent
- Concepts not internalized
- Stakeholders missing
Clause 5: Organizational Controls for Telecommunications
Controls for separation of duties in telecommunications operations and service delivery
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Telecom-specific threat intelligence including network-based threats and signaling attacks
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Security controls for telecommunications infrastructure and service delivery projects
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Managing supplier security in telecommunications supply chains and interconnections
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Clause 6: People Controls for Telecommunications
Screen personnel handling customer data, lawful interception or critical network operations.
- Background check records
- Sensitive role list
- Renewal schedule
- No renewal
- Sensitive roles unflagged
Information security obligations for telecom employees including confidentiality of customer data
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Train staff on telecoms specific threats including SIM swap, social engineering and signalling abuse.
- Training curriculum
- Attendance logs
- Phishing simulation results
- SIM swap not covered
- No simulations
Controls for remote access to telecommunications management and operations systems
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Clause 7: Physical Controls for Telecommunications
Physical security for telecommunications facilities including exchanges, data centers, and cell sites
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Entry controls and monitoring for telecom facilities and equipment rooms
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Protection of telecommunications equipment including cabling, power supply, and environmental controls
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Secure exchanges, data centres, base stations and street cabinets against physical attack and tampering.
- Site security plans
- Tamper logs
- Inspection records
- Street cabinets unmonitored
- Inspections irregular
Clause 8: Technological Controls for Telecommunications
Telecom network security including signaling security, VPN tunnels, and network segmentation
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Cryptographic controls for telecommunications signaling, customer data, and inter-carrier communication
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Telecom-specific logging, monitoring, and security event management for network operations
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Vulnerability management and malware protection for telecommunications infrastructure and services
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Data protection controls including customer data, call detail records, and service continuity backups
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Organisational
Define telecoms specific information security policies including service continuity and customer confidentiality.
- Telecoms security policy
- Approval records
- Customer confidentiality statement
- Generic policy reused
- No customer focus
Define acceptable use of customer communications metadata, content and location data.
- Acceptable use policy
- Training records
- Audit findings
- Metadata misuse
- No staff training
Control privileged access to switches, base stations, OSS and BSS systems with strong authentication.
- Access matrix
- Privileged session logs
- Reviews
- Shared admin accounts
- No session recording
Assign roles for network operations, lawful interception, fraud and customer data with clear authorities.
- Role catalogue
- Lawful interception team charter
- Fraud unit charter
- Lawful interception roles undefined
- Fraud roles informal
Monitor managed network and platform suppliers including service levels and security obligations.
- SLA dashboards
- Security review reports
- Audit rights records
- No security reviews
- Audit rights unused
Manage security of cloud and hosted telecoms services including NFV and virtualised network functions.
- NFV security baseline
- Cloud responsibility matrix
- Configuration records
- NFV baseline missing
- Shared responsibility unclear
Ensure telecoms ICT systems are ready to support continuity of critical services including emergency calls.
- Continuity plan
- Emergency call routing tests
- Recovery time objectives
- Emergency call routing untested
- RTO not validated
Collect and use telecoms threat intelligence including SS7, signalling, roaming, and customer fraud threats.
- Threat feed subscriptions
- Signalling threat reports
- Intelligence sharing logs
- No signalling intelligence
- Roaming threats ignored
Physical
Control storage media containing customer or lawful interception data including secure disposal.
- Media inventory
- Destruction certificates
- Chain of custody logs
- Inventory incomplete
- Destruction not certified
Technological
Secure endpoints used by network operations and customer support including device hardening and MDM.
- MDM policy
- Hardening baselines
- Compliance reports
- Personal devices uncontrolled
- Baselines drift
Prevent leakage of customer call records, location data and lawful interception data.
- DLP policy
- Egress monitoring logs
- Incident reports
- Lawful interception data unmonitored
- No egress logging
Log network element, signalling and service events with retention aligned to legal and operational needs.
- Log policy
- Retention schedule
- SIEM coverage matrix
- Signalling logs missing
- Retention non compliant
Monitor network and service activity for fraud, signalling abuse and unauthorised configuration changes.
- Use case catalogue
- Alert dashboards
- Fraud detection reports
- No fraud use cases
- Config change monitoring absent
Secure core network including signalling, transport, IMS and 5G core with documented controls.
- Core architecture diagrams
- Security baselines
- Penetration test reports
- 5G core untested
- Signalling controls weak
Define security characteristics, SLAs and management of network services offered to customers.
- Service catalogue
- Security SLA terms
- Customer reports
- No security SLAs
- Service catalogue incomplete
Segregate customer, management, signalling, and lawful interception networks with controlled gateways.
- Network diagrams
- Firewall rules
- Gateway test reports
- Management plane shared
- Lawful interception path not isolated
Apply cryptography to subscriber identifiers, signalling protection and operator interconnects.
- Cryptography policy
- Algorithm inventory
- Interconnect protection records
- Weak algorithms on interconnects
- SUPI not protected
Apply secure architecture principles to OSS BSS, signalling, 5G and customer facing platforms.
- Reference architectures
- Architecture review records
- Threat models
- No threat models
- Architecture drift
Manage changes to network elements, signalling and service platforms with risk and security review.
- Change advisory board minutes
- Risk assessments
- Rollback plans
- Emergency changes unreviewed
- No rollback tested
Protect telecoms IT and OSS BSS systems against malware including signalling firewall content.
- AV coverage report
- Signalling firewall config
- Incident records
- Signalling firewall absent
- AV coverage gaps
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.