ISO/IEC 27001:2022 → GSMA FS.11
Most operators hold ISO 27001 certification for their ISMS. This crosswalk shows how Annex A controls map to FS.11 signalling security requirements so certification evidence can be reused.
Scope: ISO 27001:2022 Annex A (93 controls). Focused on network and communications controls.
| Category | ISO/IEC 27001:2022 | GSMA FS.11 | Notes |
|---|---|---|---|
| Network security | A.8.20 Networks security | FS.11 §4 Filtering | Network segmentation includes SS7 interconnect border. |
| Network services | A.8.21 Security of network services | FS.11 §5 Roaming | SLA and security terms in IPX contracts. |
| Logging | A.8.15 Logging | FS.11 §7 Monitoring | Signalling firewall logs feed SIEM. |
| Monitoring | A.8.16 Monitoring activities | FS.11 §7 | Continuous anomaly detection on interconnect. |
| Threat intel | A.5.7 Threat intelligence | FS.11 §3 | Category-based threat model refresh cycle. |
| Supplier security | A.5.19 Information security in supplier relationships | FS.11 §5 | Applies to IPX carriers and roaming hubs. |
Gaps
- ISO 27001 is management-system focused; FS.11 is technical baseline. Both are needed.
- FS.11 has no direct equivalent for A.5.24 information security incident management planning.
Key takeaways
- ISO 27001 certification does not cover signalling-plane technical controls — FS.11 fills the gap.
- A.8.20/A.8.21 evidence can reference FS.11 firewall deployment.
- Combined, the two provide auditable management-system + technical evidence.