NIS2 Directive → GSMA FS.19 (Diameter Interconnect Security)
FS.19 is the GSMA baseline for Diameter interconnect security — the Diameter equivalent of FS.11. This crosswalk shows how NIS2 obligations for LTE roaming map to FS.19 controls, and where the two documents diverge.
Scope: Diameter S6a/S6d, S9, and Rx interfaces over IPX.
| Category | NIS2 Directive | GSMA FS.19 (Diameter Interconnect Security) | Notes |
|---|---|---|---|
| Risk analysis policy | NIS2 Art.21(2)(a) | FS.19 §3 – Diameter threat model | Categories 1-3 mirror FS.11; adds Diameter-specific attacks. |
| Incident handling | NIS2 Art.21(2)(b) | FS.19 §7 – Anomaly monitoring | DEA/DRA logs must be retained per national NRA rules. |
| Network security | NIS2 Art.21(2)(e) | FS.19 §4 – DEA filtering | Origin-Host validation, ULR/AIR rate limits, unexpected AVP drop. |
| Supply chain | NIS2 Art.21(2)(d) | FS.19 §5 – Roaming agreement obligations | Includes IPX carrier obligations under IR.88. |
| Cryptography | NIS2 Art.21(2)(h) | FS.19 §4.4 – DTLS/TLS transport | DTLS on SCTP recommended; rarely deployed end-to-end. |
| Vulnerability handling | NIS2 Art.21(2)(f) | FS.19 §6 – Testing | Annual Diameter pentest; test IDR/PUR abuse paths. |
Gaps
- FS.19 does not address 5G SBI — see FS.21 for SEPP crosswalk.
- NIS2 requires management liability; FS.19 is technical only.
Key takeaways
- FS.19 is the standard implementation of NIS2 network-security duties on Diameter.
- Origin-Host validation and Cat-1 AVP filtering are the highest-impact controls.
- IPX supply-chain vetting is a shared obligation with roaming partners.