27011-4 | Structure of this document | 2 |
27011-5.1 | Policies for Information Security in Telecoms | 3 |
27011-5.10 | Acceptable Use of Customer Data | 0 |
27011-5.15 | Access Control for Network Elements | 1 |
27011-5.2 | Information Security Roles in Telecoms | 110 |
27011-5.22 | Monitoring of Supplier Services | 0 |
27011-5.23 | Cloud and Hosted Telecoms Services | 0 |
27011-5.3 | Segregation of duties | 128 |
27011-5.30 | ICT Readiness for Continuity | 1 |
27011-5.4 | Threat intelligence for telecom | 18 |
27011-5.5 | Information security in project management | 0 |
27011-5.6 | Supplier relationships and telecom supply chain | 76 |
27011-5.7 | Threat Intelligence for Telecoms | 0 |
27011-6.1 | Screening of Telecoms Personnel | 0 |
27011-6.2 | Terms and conditions of employment | 1 |
27011-6.3 | Awareness and Training | 169 |
27011-6.4 | Remote working | 2 |
27011-7.1 | Physical security perimeters | 29 |
27011-7.10 | Storage Media Handling in Telecoms | 1 |
27011-7.2 | Physical entry and securing offices | 1 |
27011-7.3 | Equipment protection | 27 |
27011-7.4 | Physical Security of Network Sites | 6 |
27011-8.1 | User Endpoint Devices | 156 |
27011-8.12 | Data Leakage Prevention for Telecoms | 1 |
27011-8.15 | Logging of Network and Service Events | 0 |
27011-8.16 | Monitoring Activities | 1 |
27011-8.2 | Network security and segregation | 64 |
27011-8.20 | Network Security for Telecoms Core | 0 |
27011-8.21 | Security of Network Services | 1 |
27011-8.22 | Segregation of Networks | 1 |
27011-8.24 | Use of Cryptography | 1 |
27011-8.27 | Secure System Architecture | 1 |
27011-8.3 | Cryptography and key management | 142 |
27011-8.32 | Change Management for Network | 2 |
27011-8.4 | Logging and monitoring | 68 |
27011-8.5 | Vulnerability and malware management | 82 |
27011-8.6 | Data protection and backup | 175 |
27011-8.7 | Protection Against Malware | 0 |
1-3 | Scope, normative references, definitions and abbreviations | 0 |
4.1 | Structure of this Recommendation | International Standard | 0 |
4.2.1-2 | Goal, and the kinds of telecommunications organization | 0 |
4.2.3 | Information security considerations in telecommunications | 0 |
4.2.5.1 | How to establish information security requirements | 0 |
4.2.5.2 | Assessing information security risks | 0 |
4.2.5.3 | Selecting information security controls | 0 |
5 | Organizational controls | 0 |
5.12 | Classification of information | 0 |
5.15 | Access control | 0 |
5.19 | Information security in supplier relationships | 0 |
5.2 | Information security roles and responsibilities | 0 |
5.20 | Addressing information security within supplier agreements | 0 |
5.21 | Managing information security in the ICT supply chain | 0 |
5.24 | Information security incident management planning and preparation | 0 |
5.25 | Assessment and decision on information security events | 0 |
5.26 | Response to information security incidents | 0 |
5.27 | Learning from information security incidents | 0 |
5.30 | ICT readiness for business continuity | 0 |
5.37 | Documented operating procedures | 0 |
5.38 | TEL: Interconnected telecommunications services | 0 |
5.39 | TEL: Security management of telecommunications services delivery | 0 |
5.40 | TEL: Response to spam | 0 |
5.41 | TEL: Response to DoS/DDoS attacks | 0 |
5.42 | TEL: Non-disclosure of communications | 0 |
5.43 | TEL: Essential communications | 0 |
5.44 | TEL: Legality of emergency actions | 0 |
5.45 | TEL: Coordination for information security incident management | 0 |
5.5 | Contact with authorities | 0 |
5.9 | Inventory of information and other associated assets | 0 |
6 | People controls | 0 |
6.1 | Screening | 0 |
6.2 | Terms and conditions of employment | 0 |
7 | Physical controls | 0 |
7.1 | Physical security perimeter | 0 |
7.11 | Supporting utilities | 0 |
7.12 | Cabling security | 0 |
7.15 | TEL: Securing communication centres | 0 |
7.16 | TEL: Securing telecommunications equipment room | 0 |
7.17 | TEL: Securing physically isolated operation areas | 0 |
7.18 | TEL: Equipment sited in other carriers' premises | 0 |
7.19 | TEL: Equipment sited in user premises | 0 |
7.2 | Physical entry | 0 |
7.8 | Equipment siting and protection | 0 |
8 | Technological controls | 0 |
8.14 | Redundancy of information processing facilities | 0 |
8.15 | Logging | 0 |
8.19 | Installation of software on operational systems | 0 |
8.21 | Security of network services | 0 |
8.22 | Segregation of networks | 0 |
8.31 | Separation of development, test and production environments | 0 |
8.32 | Change management | 0 |
8.35 | TEL: Telecommunications carrier identification and authentication by users | 0 |
A | Annex A: additional guidance for network security | 0 |
A.1.1 | Protection against network attack | 0 |
A.1.2 | Drawing the attention of users | 0 |
A.2.1 | Gathering information on the causes of congestion | 0 |
A.2.2 | Measures against network congestion | 0 |