transport-security-audit

📋 Audit Checklist: Transport & Optical Security

Field Security Audit // Node_Operational
Completion_Index0%

GPON Access Security (G.984)

item_em-0

Downstream Encryption (AES-128): Confirm that AES-128 encryption is enabled for all downstream GEM (GPON Encapsulation Method) ports. Audit the "Key Exchange" process (GEM port 0). Verify that keys are rotated every 15-60 mins.

item_em-1

ONU/ONT Authentication: Confirm that all ONUs (Optical Network Units) are authenticated using a serial number (SN) and an optional "Registration ID" password. Rogue ONT Detection: Is the OLT configured to automatically shut down or isolate any ONT that transmits at the "wrong time" (Continuous Mode Fault)?

item_em-2

Data Isolation (OMCI Security): Verify that management traffic (OMCI) is isolated from user traffic (VLANs/VRFs).

Optical Transport Network (OTN) (G.709)

item_em-3

Control Plane Isolation (ASON/GMPLS): Verify that the OTN control plane signaling is carried over an authenticated/secure Supervisory Channel (OSC).

item_em-4

Payload Transparency & Integrity: Confirm that client signals (Ethernet, FC) are mapped into ODU (Optical Data Unit) frames without unintended payload leakage between channels.

item_em-5

Optical Fragmentation Protection (OTU Security): Audit the configurations for "OTU-Level Protection" (O-SNCP). Verify failover times meet the <50ms requirement.

Smart Grid PLC Security (G.9903)

item_em-6

Data Encryption (MAC Layer): Confirm that AES-128 CCM (Counter with CBC-MAC) is enabled for all data payloads. Audit the Key Management: Are "Network Keys" rotated periodically using the 6LoWPAN/802.15.4 security framework?

item_em-7

Device Authentication: Verify that new Smart Meters (nodes) are authenticated using a EAP-PSK or certificate-based mechanism before joining the PLC mesh. Anti-Replay Protection: Is the Frame Counter (FC) check enabled for all incoming PLC frames?

Timing & Synchronization (G.8275 / G.8273)

item_em-8

PTP (IEEE 1588) Security: For Precisely Timed Networks (5G Sync), verify that PTP messages are authenticated and checked for "Time Spoofing".

item_em-9

Anti-Jamming (Synchronization Loss): Audit the "Holdover" capabilities of the Grandmaster clock. Is there a precise internal atomic clock (Rb/Cs) for sync stability during GPS/GNSS jammings?

Restricted Mission
You are in Read-Only mode. Sign in to save progress and synchronize audit results across your devices.
TELCOSEC INITIATIVEEST. 2026 // GLOBAL STANDARDS RESEARCH

Independent, non-affiliated security research project dedicated to hardening global telecommunications infrastructure through data-driven auditing.