Skip to content

Evidence request lists

NIST SP 800-187

Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Architecture

SP800-187-3.1
LTE Architecture Overview

Document the LTE network architecture including User Equipment, eNodeB, Evolved Packet Core elements (MME, SGW, PGW, HSS), and the interfaces connecting them. Identify the air interface, S1, S5, S6a, and SGi reference points used by the deployment.

Artefacts an auditor will ask for
  • LTE architecture diagram with EPC components labeled
  • interface matrix listing S1-MME, S1-U, S5, S6a, SGi, X2 endpoints
  • vendor element inventory with software versions
  • geographic deployment map of eNodeB sites
Where this commonly fails
  • diagrams omit roaming partner interconnects
  • no version tracking for EPC software
  • X2 interface relationships not documented between vendor cells

Authentication

SP800-187-3.3
Mutual Authentication via EPS-AKA

Enforce mutual authentication between User Equipment and the network using the Evolved Packet System Authentication and Key Agreement protocol. Maintain a tamper resistant Universal Subscriber Identity Module that protects the long term key K and supports authentication vector generation at the HSS.

Artefacts an auditor will ask for
  • EPS-AKA flow diagram with sequence numbers
  • USIM provisioning standard operating procedure
  • HSS authentication vector logs sampled monthly
  • key separation derivation parameters documented
Where this commonly fails
  • fallback to GSM authentication permitted without rationale
  • USIM personalization vendor audits not performed
  • sequence number resynchronization events not monitored

Availability

SP800-187-3.14
Denial of Service Mitigation

Plan for denial of service conditions on signaling and user plane interfaces. Apply rate limiting on attach storms, dimension MME and SGW capacity headroom, and have a documented response for paging amplification attempts.

Artefacts an auditor will ask for
  • attach storm rate limit configuration
  • MME and SGW capacity headroom report
  • incident playbook for signaling DoS
  • tabletop exercise records covering signaling overload
Where this commonly fails
  • no rate limits configured for individual UE retry storms
  • capacity headroom dropped below 30 percent without action
  • playbook never exercised

Compliance

SP800-187-3.12
Lawful Intercept Controls

Implement lawful intercept capabilities required by jurisdiction while controlling access to the LI mediation function. Ensure only authorized personnel can provision intercepts and that all activity is logged to a separate audit chain.

Artefacts an auditor will ask for
  • lawful intercept access role matrix
  • warrant management workflow document
  • tamper evident audit log of LI activations
  • quarterly internal audit of LI usage
Where this commonly fails
  • LI logs stored alongside operational logs without separation
  • no periodic review of dormant LI provisioning accounts
  • training for LI handlers not refreshed annually

Cryptography

SP800-187-3.4
Air Interface Confidentiality

Enable encryption of user plane and control plane traffic over the radio link using approved EEA algorithms. Disable null ciphering except for emergency calls where local regulation permits, and document the algorithm preference order configured on the eNodeB.

Artefacts an auditor will ask for
  • eNodeB security capability advertisement configuration
  • algorithm priority list (EEA1, EEA2, EEA3) per region
  • EEA0 (null cipher) usage exception register
  • field measurement showing encrypted bearer establishment
Where this commonly fails
  • EEA0 permitted globally rather than for emergencies only
  • no monitoring of algorithm downgrade attempts
  • vendor algorithm support matrix not maintained
SP800-187-3.5
Air Interface Integrity Protection

Apply EIA integrity algorithms to control plane signaling so that radio resource and non access stratum messages cannot be tampered with on the air interface. Treat integrity protection as mandatory for signaling and confirm operation during attach.

Artefacts an auditor will ask for
  • EIA algorithm preference configuration on eNodeB and MME
  • attach procedure trace showing Security Mode Command
  • review of EIA0 usage limited to emergency call signaling
  • annual penetration test report covering signaling integrity
Where this commonly fails
  • EIA0 enabled outside emergency scope
  • no automated alerting on Security Mode Command failures
  • vendor patches deferred that fix integrity algorithm bugs

Hardening

SP800-187-3.11
MME and HSS Hardening

Harden Mobility Management Entity and Home Subscriber Server platforms following vendor and CIS guidance. Restrict OAM access to dedicated management networks and require multi factor authentication for administrators.

Artefacts an auditor will ask for
  • MME and HSS hardening baseline aligned with vendor guide
  • OAM network segmentation diagram
  • administrator MFA enrollment records
  • patch cycle log for EPC nodes
Where this commonly fails
  • OAM reachable from corporate IT network
  • shared administrator accounts on EPC nodes
  • patches lagging vendor advisories by more than 90 days
SP800-187-3.7
eNodeB Physical and Logical Hardening

Apply physical tamper resistance and logical hardening to eNodeB platforms deployed in exposed locations. Disable unused services, enforce secure boot, and lock management ports so that an attacker with site access cannot extract keying material.

Artefacts an auditor will ask for
  • eNodeB hardening baseline document
  • secure boot attestation logs
  • tamper switch alarm test records
  • local console access policy and key control register
Where this commonly fails
  • default vendor credentials still active
  • tamper alarms not monitored centrally
  • secure boot disabled for diagnostic convenience
SP800-187-3.8
Femtocell and Small Cell Controls

Treat operator deployed small cells and customer premises HeNB devices as untrusted endpoints. Authenticate them to the Security Gateway, isolate their backhaul, and apply remote attestation before granting EPC connectivity.

Artefacts an auditor will ask for
  • HeNB gateway authentication policy
  • remote attestation log samples
  • subscriber group access control list configuration
  • incident playbook for compromised HeNB
Where this commonly fails
  • HeNBs share trust posture with macro eNodeBs
  • no attestation performed at boot
  • compromised HeNB revocation procedure missing

Identity Management

SP800-187-3.2
User Equipment Identity Protection

Protect International Mobile Subscriber Identity values during attach and paging procedures. Use temporary identifiers (GUTI, S-TMSI) wherever feasible and refresh them on a defined cadence to limit subscriber tracking by passive observers.

Artefacts an auditor will ask for
  • GUTI reallocation timer configuration on MME
  • policy specifying when IMSI may be transmitted in cleartext
  • logging of IMSI catcher detection events
  • test results from passive air interface capture review
Where this commonly fails
  • GUTI reallocation timers left at vendor defaults
  • no detection in place for IMSI catcher activity
  • emergency call exceptions not documented

NIST SP 800-187: Access Control

SP800-187-THR-MALWARE-CORE
Threat: Malware Impacting Core Infrastructure

Attacks targeting the evolved packet core elements that can affect mobility management, sessions, and subscriber data.

Artefacts an auditor will ask for
  • Core infrastructure protection and monitoring
Where this commonly fails
  • Core compromise undetected
SP800-187-THR-MALWARE-RAN
Threat: Malware Impacting RAN Infrastructure

Attacks targeting the radio access network infrastructure, including eNodeBs, that can disrupt or compromise service.

Artefacts an auditor will ask for
  • RAN infrastructure integrity monitoring
Where this commonly fails
  • RAN compromise undetected
SP800-187-THR-MALWARE-UE
Threat: Malware Attacks on UEs

Malware on mobile devices that can compromise the device, exfiltrate data, or launch attacks against the network.

Artefacts an auditor will ask for
  • Mobile threat defense for UEs
Where this commonly fails
  • No mobile malware protection
SP800-187-THR-ROGUE-BS
Threat: Rogue Base Stations and Eavesdropping

Adversary-operated base stations and air-interface eavesdropping that can intercept, redirect, or degrade subscriber traffic.

Artefacts an auditor will ask for
  • Rogue base station detection and air-interface protections
Where this commonly fails
  • No detection of rogue base stations/eavesdropping
SP800-187-THR-SIGNALING
Threat: Signaling and Protocol Attacks

Attacks exploiting signaling protocols (for example Diameter and GTP) to cause denial of service, fraud, or interception.

Artefacts an auditor will ask for
  • Diameter/GTP signaling security controls
Where this commonly fails
  • Signaling attacks (fraud, DoS, interception) unmitigated

NIST SP 800-187: Asset Management

SP800-187-SEC-AIRINTERFACE
Air Interface Security

Protection of the radio link between the UE and E-UTRAN, including encryption and integrity protection of control and user plane traffic.

Artefacts an auditor will ask for
  • Encryption and integrity protection of radio link
Where this commonly fails
  • Control/user plane not integrity protected
SP800-187-SEC-BACKHAUL
Backhaul Security

Protection of the backhaul links connecting E-UTRAN to the core network, typically using IPsec to secure traffic over untrusted transport.

Artefacts an auditor will ask for
  • IPsec configuration for backhaul links
Where this commonly fails
  • Backhaul traffic unprotected over untrusted transport
SP800-187-SEC-CORE
Core Network Security

Security of the Evolved Packet Core, including signaling protection, interconnection security, and protection of subscriber data in the HSS.

Artefacts an auditor will ask for
  • Signaling protection and HSS subscriber data protection
Where this commonly fails
  • Interconnect/signaling unprotected
SP800-187-SEC-EUTRAN
E-UTRAN Security

Security considerations for eNodeB base stations, including their exposure and the protection of keys held at the edge.

Artefacts an auditor will ask for
  • Key handling and protection at eNodeBs
Where this commonly fails
  • Keys exposed at the network edge
SP800-187-SEC-UEAUTH
UE Authentication

Mutual authentication between the user equipment and the network using the EPS Authentication and Key Agreement (EPS-AKA) procedure.

Artefacts an auditor will ask for
  • Mutual EPS-AKA authentication configuration
Where this commonly fails
  • One-way authentication
  • Downgrade attacks possible

NIST SP 800-187: Information Security Policies

SP800-187-ARCH-EPC
LTE Component: Evolved Packet Core (EPC)

The core network elements (MME, S-GW, P-GW, HSS) that manage mobility, sessions, and authentication in LTE.

Artefacts an auditor will ask for
  • Core element (MME/S-GW/P-GW/HSS) security config
Where this commonly fails
  • Core elements lack hardening/segmentation
SP800-187-ARCH-EUTRAN
LTE Component: E-UTRAN

The Evolved Universal Terrestrial Radio Access Network, comprising the eNodeB base stations that provide the radio interface to user equipment.

Artefacts an auditor will ask for
  • eNodeB hardening and physical security
Where this commonly fails
  • Edge base stations physically/logically exposed
SP800-187-ARCH-UE
LTE Component: Mobile Devices (UE)

User Equipment, including the mobile device and the Universal Integrated Circuit Card (UICC), and its role and security in the LTE architecture.

Artefacts an auditor will ask for
  • UE/UICC security configuration and credential protection
Where this commonly fails
  • UICC credentials inadequately protected
SP800-187-SEC-CRYPTO
Cryptographic Overview

The cryptographic algorithms and key hierarchy (EPS-AKA) used in LTE to provide confidentiality and integrity.

Artefacts an auditor will ask for
  • EPS-AKA key hierarchy and algorithm configuration
Where this commonly fails
  • Weak or null ciphers permitted
SP800-187-SEC-HARDWARE
Hardware Security

Hardware-based security mechanisms including the UICC and tamper resistance that anchor LTE subscriber credentials.

Artefacts an auditor will ask for
  • UICC/tamper-resistance attestation
Where this commonly fails
  • No hardware anchoring of credentials

Network Security

SP800-187-3.10
SS7 Interworking Risk Mitigation

Even on an LTE network, SS7 interworking with legacy 2G and 3G partners can expose subscribers to tracking and interception. Deploy an SS7 firewall, restrict global title routing, and monitor MAP messages for known attack signatures.

Artefacts an auditor will ask for
  • SS7 firewall rule set aligned with GSMA FS.11
  • global title screening tables
  • MAP command code filter list
  • quarterly threat intelligence review for SS7
Where this commonly fails
  • category 2 MAP filters not deployed
  • GT screening at network edge only, not internal
  • no logging retention for SS7 events beyond 30 days
SP800-187-3.6
Backhaul Protection with IPsec

Protect the S1 interface between eNodeB and EPC using IPsec in tunnel mode where the backhaul traverses untrusted networks. Use certificate based authentication with a dedicated PKI and rotate credentials on a defined cadence.

Artefacts an auditor will ask for
  • S1 backhaul trust classification by site
  • IPsec policy template with IKEv2 parameters
  • Security Gateway certificate inventory and expiry tracking
  • tunnel uptime dashboard showing IPsec coverage
Where this commonly fails
  • macro sites considered trusted without documented basis
  • pre shared keys used instead of certificates
  • no automated alerting on IPsec tunnel down events
SP800-187-3.9
Diameter Signaling Protection

Protect Diameter signaling on S6a, S9, and roaming interfaces against spoofed authentication requests and subscriber profile theft. Deploy a Diameter Edge Agent or signaling firewall and filter on origin host, application identifier, and command code.

Artefacts an auditor will ask for
  • Diameter Edge Agent rule set
  • category 1, 2, and 3 signaling filter mapping per GSMA FS.19
  • monthly anomaly report from signaling SIEM
  • roaming partner allow list with origin realms
Where this commonly fails
  • category 2 filters not implemented
  • no anomaly detection on Update Location Request volume
  • stale roaming partners remain on allow list

Operations

SP800-187-3.17
Monitoring and Incident Response for LTE

Establish continuous monitoring of LTE specific risk indicators including authentication failure rates, integrity check failures, Diameter and SS7 anomalies, and unexpected algorithm downgrades. Tie alerts into the security operations centre with defined runbooks.

Artefacts an auditor will ask for
  • LTE monitoring rule library
  • SOC runbook set covering EPC, signaling, and radio events
  • monthly metrics report showing alert volume and disposition
  • post incident review records for LTE specific events
Where this commonly fails
  • no SOC visibility into eNodeB events
  • alerts on integrity failures not tuned, generating noise
  • runbooks missing for category 3 signaling attacks

Privacy

SP800-187-3.13
Subscriber Privacy Logging

Limit retention of subscriber identifiers and location information in operational logs to what is needed for fraud detection, troubleshooting, and regulatory obligations. Apply role based access controls to logs containing IMSI, IMEI, and Cell ID data.

Artefacts an auditor will ask for
  • log retention schedule with subscriber data fields
  • RBAC matrix for log query tools
  • data protection impact assessment for log stores
  • quarterly access review for subscriber log systems
Where this commonly fails
  • logs retained beyond regulatory minimum without justification
  • no masking of IMSI in non operational dashboards
  • DPIA never refreshed after system changes

Service Security

SP800-187-3.16
Voice over LTE Security

Where VoLTE is offered, protect the IMS core and SIP signaling using TLS or IPsec, and isolate the IMS access network from general data sessions. Verify that calls fall back to circuit switched bearers only when necessary and that fallback is logged.

Artefacts an auditor will ask for
  • IMS network segmentation diagram
  • SIP TLS and IPsec configuration on P-CSCF
  • circuit switched fallback policy
  • fraud monitoring rules for VoLTE
Where this commonly fails
  • SIP signaling unencrypted to handsets that support TLS
  • fallback to CS not logged
  • no fraud thresholds for international destinations

Third Party

SP800-187-3.15
Roaming Security Agreements

Formalize the security expectations imposed on roaming partners covering Diameter and SS7 signaling, IPX interconnection, and incident notification. Require partners to implement signaling firewalling and to report subscriber affecting events within defined timelines.

Artefacts an auditor will ask for
  • roaming agreement template with security annex
  • partner self attestation collection schedule
  • incident notification timelines per partner
  • annual review log of partner posture
Where this commonly fails
  • partner agreements pre date GSMA FS.19 guidance
  • no escalation path for partner driven incidents
  • partner self attestations never validated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-187 framework page.