national-ciip-audit

🕵️ National CIIP Audit: Critical Infrastructure Protection

Field Security Audit // Node_Operational
Completion_Index0%

Section 1: Organizational & Policy Readiness (itu-d)

item_em-0

NCS Compliance: Does the operator have a formal incident response agreement with the National CIRT/CERT?

item_em-1

ISMS Certification: Has the operator implemented itu-t X.1051 (ISO 27001 for Telecom) controls?

item_em-2

Workforce Capacity: Are the security engineers certified in the the itu-d Cybersecurity Curriculum or equivalent?

item_em-3

Legal Compliance: Are the Lawful Interception (LI) gateways secured and isolated from the public internet?

Section 2: Technical Backbone Resilience (itu-t)

item_em-4

BGP Security: Are RPKI and BGP route-filtering implemented at the international gateway?

item_em-5

DDoS Mitigation: Is there an automated "Scrubbing Center" or DDoS-cleaning capacity?

item_em-6

Signaling Hardening: Are the SS7/Diameter firewalls configured with the latest X.1031 vulnerability signatures?

item_em-7

Physical Protection: Are the Undersea Cable landing stations and Satellite Gateways physically and electronically monitored?

Section 3: 5G Core & Future Readiness (Y.3101)

item_em-8

SBA Authorization: Is mandatory OAuth2/SEPP authentication active for all cross-domain Service Based Architecture queries?

item_em-9

Slice Isolation: Have the Network Slice Selection Function (NSSF) configurations been audited for cross-slice leakage?

item_m-10

SUPI/SUCI Privacy: Is the network configured to always use SUCI (Subscription Concealed Identifier) instead of the plain IMSI?

item_m-11

PQC Roadmap: Does the operator have a published plan for the Post-Quantum Cryptography (PQC) transition of the control plane?

Section 4: All-Timeline Vulnerability Patches (CVE-Telco)

item_m-12

2G/3G Fallback: Is the network configured to reject unauthenticated 2G/SS7 fallback requests?

item_m-13

High-Impact CVEs: Are all high-impact 2024-2026 AMF/UPF software vulnerabilities patched according to vendor advisories?

item_m-14

GTP-U Integrity: Is the User Plane (GTP-U) traffic monitored for header manipulation and IP spoofing?

Restricted Mission
You are in Read-Only mode. Sign in to save progress and synchronize audit results across your devices.
TELCOSEC INITIATIVEEST. 2026 // GLOBAL STANDARDS RESEARCH

Independent, non-affiliated security research project dedicated to hardening global telecommunications infrastructure through data-driven auditing.