NIST SP 800-187
Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Architecture
Document the LTE network architecture including User Equipment, eNodeB, Evolved Packet Core elements (MME, SGW, PGW, HSS), and the interfaces connecting them. Identify the air interface, S1, S5, S6a, and SGi reference points used by the deployment.
- LTE architecture diagram with EPC components labeled
- interface matrix listing S1-MME, S1-U, S5, S6a, SGi, X2 endpoints
- vendor element inventory with software versions
- geographic deployment map of eNodeB sites
- diagrams omit roaming partner interconnects
- no version tracking for EPC software
- X2 interface relationships not documented between vendor cells
Authentication
Enforce mutual authentication between User Equipment and the network using the Evolved Packet System Authentication and Key Agreement protocol. Maintain a tamper resistant Universal Subscriber Identity Module that protects the long term key K and supports authentication vector generation at the HSS.
- EPS-AKA flow diagram with sequence numbers
- USIM provisioning standard operating procedure
- HSS authentication vector logs sampled monthly
- key separation derivation parameters documented
- fallback to GSM authentication permitted without rationale
- USIM personalization vendor audits not performed
- sequence number resynchronization events not monitored
Availability
Plan for denial of service conditions on signaling and user plane interfaces. Apply rate limiting on attach storms, dimension MME and SGW capacity headroom, and have a documented response for paging amplification attempts.
- attach storm rate limit configuration
- MME and SGW capacity headroom report
- incident playbook for signaling DoS
- tabletop exercise records covering signaling overload
- no rate limits configured for individual UE retry storms
- capacity headroom dropped below 30 percent without action
- playbook never exercised
Compliance
Implement lawful intercept capabilities required by jurisdiction while controlling access to the LI mediation function. Ensure only authorized personnel can provision intercepts and that all activity is logged to a separate audit chain.
- lawful intercept access role matrix
- warrant management workflow document
- tamper evident audit log of LI activations
- quarterly internal audit of LI usage
- LI logs stored alongside operational logs without separation
- no periodic review of dormant LI provisioning accounts
- training for LI handlers not refreshed annually
Cryptography
Enable encryption of user plane and control plane traffic over the radio link using approved EEA algorithms. Disable null ciphering except for emergency calls where local regulation permits, and document the algorithm preference order configured on the eNodeB.
- eNodeB security capability advertisement configuration
- algorithm priority list (EEA1, EEA2, EEA3) per region
- EEA0 (null cipher) usage exception register
- field measurement showing encrypted bearer establishment
- EEA0 permitted globally rather than for emergencies only
- no monitoring of algorithm downgrade attempts
- vendor algorithm support matrix not maintained
Apply EIA integrity algorithms to control plane signaling so that radio resource and non access stratum messages cannot be tampered with on the air interface. Treat integrity protection as mandatory for signaling and confirm operation during attach.
- EIA algorithm preference configuration on eNodeB and MME
- attach procedure trace showing Security Mode Command
- review of EIA0 usage limited to emergency call signaling
- annual penetration test report covering signaling integrity
- EIA0 enabled outside emergency scope
- no automated alerting on Security Mode Command failures
- vendor patches deferred that fix integrity algorithm bugs
Hardening
Harden Mobility Management Entity and Home Subscriber Server platforms following vendor and CIS guidance. Restrict OAM access to dedicated management networks and require multi factor authentication for administrators.
- MME and HSS hardening baseline aligned with vendor guide
- OAM network segmentation diagram
- administrator MFA enrollment records
- patch cycle log for EPC nodes
- OAM reachable from corporate IT network
- shared administrator accounts on EPC nodes
- patches lagging vendor advisories by more than 90 days
Apply physical tamper resistance and logical hardening to eNodeB platforms deployed in exposed locations. Disable unused services, enforce secure boot, and lock management ports so that an attacker with site access cannot extract keying material.
- eNodeB hardening baseline document
- secure boot attestation logs
- tamper switch alarm test records
- local console access policy and key control register
- default vendor credentials still active
- tamper alarms not monitored centrally
- secure boot disabled for diagnostic convenience
Treat operator deployed small cells and customer premises HeNB devices as untrusted endpoints. Authenticate them to the Security Gateway, isolate their backhaul, and apply remote attestation before granting EPC connectivity.
- HeNB gateway authentication policy
- remote attestation log samples
- subscriber group access control list configuration
- incident playbook for compromised HeNB
- HeNBs share trust posture with macro eNodeBs
- no attestation performed at boot
- compromised HeNB revocation procedure missing
Identity Management
Protect International Mobile Subscriber Identity values during attach and paging procedures. Use temporary identifiers (GUTI, S-TMSI) wherever feasible and refresh them on a defined cadence to limit subscriber tracking by passive observers.
- GUTI reallocation timer configuration on MME
- policy specifying when IMSI may be transmitted in cleartext
- logging of IMSI catcher detection events
- test results from passive air interface capture review
- GUTI reallocation timers left at vendor defaults
- no detection in place for IMSI catcher activity
- emergency call exceptions not documented
NIST SP 800-187: Access Control
Attacks targeting the evolved packet core elements that can affect mobility management, sessions, and subscriber data.
- Core infrastructure protection and monitoring
- Core compromise undetected
Attacks targeting the radio access network infrastructure, including eNodeBs, that can disrupt or compromise service.
- RAN infrastructure integrity monitoring
- RAN compromise undetected
Malware on mobile devices that can compromise the device, exfiltrate data, or launch attacks against the network.
- Mobile threat defense for UEs
- No mobile malware protection
Adversary-operated base stations and air-interface eavesdropping that can intercept, redirect, or degrade subscriber traffic.
- Rogue base station detection and air-interface protections
- No detection of rogue base stations/eavesdropping
Attacks exploiting signaling protocols (for example Diameter and GTP) to cause denial of service, fraud, or interception.
- Diameter/GTP signaling security controls
- Signaling attacks (fraud, DoS, interception) unmitigated
NIST SP 800-187: Asset Management
Protection of the radio link between the UE and E-UTRAN, including encryption and integrity protection of control and user plane traffic.
- Encryption and integrity protection of radio link
- Control/user plane not integrity protected
Protection of the backhaul links connecting E-UTRAN to the core network, typically using IPsec to secure traffic over untrusted transport.
- IPsec configuration for backhaul links
- Backhaul traffic unprotected over untrusted transport
Security of the Evolved Packet Core, including signaling protection, interconnection security, and protection of subscriber data in the HSS.
- Signaling protection and HSS subscriber data protection
- Interconnect/signaling unprotected
Security considerations for eNodeB base stations, including their exposure and the protection of keys held at the edge.
- Key handling and protection at eNodeBs
- Keys exposed at the network edge
Mutual authentication between the user equipment and the network using the EPS Authentication and Key Agreement (EPS-AKA) procedure.
- Mutual EPS-AKA authentication configuration
- One-way authentication
- Downgrade attacks possible
NIST SP 800-187: Information Security Policies
The core network elements (MME, S-GW, P-GW, HSS) that manage mobility, sessions, and authentication in LTE.
- Core element (MME/S-GW/P-GW/HSS) security config
- Core elements lack hardening/segmentation
The Evolved Universal Terrestrial Radio Access Network, comprising the eNodeB base stations that provide the radio interface to user equipment.
- eNodeB hardening and physical security
- Edge base stations physically/logically exposed
User Equipment, including the mobile device and the Universal Integrated Circuit Card (UICC), and its role and security in the LTE architecture.
- UE/UICC security configuration and credential protection
- UICC credentials inadequately protected
The cryptographic algorithms and key hierarchy (EPS-AKA) used in LTE to provide confidentiality and integrity.
- EPS-AKA key hierarchy and algorithm configuration
- Weak or null ciphers permitted
Hardware-based security mechanisms including the UICC and tamper resistance that anchor LTE subscriber credentials.
- UICC/tamper-resistance attestation
- No hardware anchoring of credentials
Network Security
Even on an LTE network, SS7 interworking with legacy 2G and 3G partners can expose subscribers to tracking and interception. Deploy an SS7 firewall, restrict global title routing, and monitor MAP messages for known attack signatures.
- SS7 firewall rule set aligned with GSMA FS.11
- global title screening tables
- MAP command code filter list
- quarterly threat intelligence review for SS7
- category 2 MAP filters not deployed
- GT screening at network edge only, not internal
- no logging retention for SS7 events beyond 30 days
Protect the S1 interface between eNodeB and EPC using IPsec in tunnel mode where the backhaul traverses untrusted networks. Use certificate based authentication with a dedicated PKI and rotate credentials on a defined cadence.
- S1 backhaul trust classification by site
- IPsec policy template with IKEv2 parameters
- Security Gateway certificate inventory and expiry tracking
- tunnel uptime dashboard showing IPsec coverage
- macro sites considered trusted without documented basis
- pre shared keys used instead of certificates
- no automated alerting on IPsec tunnel down events
Protect Diameter signaling on S6a, S9, and roaming interfaces against spoofed authentication requests and subscriber profile theft. Deploy a Diameter Edge Agent or signaling firewall and filter on origin host, application identifier, and command code.
- Diameter Edge Agent rule set
- category 1, 2, and 3 signaling filter mapping per GSMA FS.19
- monthly anomaly report from signaling SIEM
- roaming partner allow list with origin realms
- category 2 filters not implemented
- no anomaly detection on Update Location Request volume
- stale roaming partners remain on allow list
Operations
Establish continuous monitoring of LTE specific risk indicators including authentication failure rates, integrity check failures, Diameter and SS7 anomalies, and unexpected algorithm downgrades. Tie alerts into the security operations centre with defined runbooks.
- LTE monitoring rule library
- SOC runbook set covering EPC, signaling, and radio events
- monthly metrics report showing alert volume and disposition
- post incident review records for LTE specific events
- no SOC visibility into eNodeB events
- alerts on integrity failures not tuned, generating noise
- runbooks missing for category 3 signaling attacks
Privacy
Limit retention of subscriber identifiers and location information in operational logs to what is needed for fraud detection, troubleshooting, and regulatory obligations. Apply role based access controls to logs containing IMSI, IMEI, and Cell ID data.
- log retention schedule with subscriber data fields
- RBAC matrix for log query tools
- data protection impact assessment for log stores
- quarterly access review for subscriber log systems
- logs retained beyond regulatory minimum without justification
- no masking of IMSI in non operational dashboards
- DPIA never refreshed after system changes
Service Security
Where VoLTE is offered, protect the IMS core and SIP signaling using TLS or IPsec, and isolate the IMS access network from general data sessions. Verify that calls fall back to circuit switched bearers only when necessary and that fallback is logged.
- IMS network segmentation diagram
- SIP TLS and IPsec configuration on P-CSCF
- circuit switched fallback policy
- fraud monitoring rules for VoLTE
- SIP signaling unencrypted to handsets that support TLS
- fallback to CS not logged
- no fraud thresholds for international destinations
Third Party
Formalize the security expectations imposed on roaming partners covering Diameter and SS7 signaling, IPX interconnection, and incident notification. Require partners to implement signaling firewalling and to report subscriber affecting events within defined timelines.
- roaming agreement template with security annex
- partner self attestation collection schedule
- incident notification timelines per partner
- annual review log of partner posture
- partner agreements pre date GSMA FS.19 guidance
- no escalation path for partner driven incidents
- partner self attestations never validated
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-187 framework page.