Overview
EN ISO/IEC 27011:2020 (ISO/IEC 27011:2016) is a sector-specific code of practice that adapts ISO/IEC 27002 information security controls for telecommunications organizations. Endorsed by CEN as EN ISO/IEC 27011:2020, the standard provides interpretation guidelines to help telecom operators, service providers and system integrators implement and manage security controls that protect confidentiality, integrity and availability across complex, shared and interconnected telecommunication environments.
Key topics and technical requirements
The standard maps ISO/IEC 27002 controls to telecom-specific risks and operational realities. Major topics include:
- Information security policies tailored to telecommunications services and infrastructure.
- Organization of security, including internal roles, contractor access and teleworking/mobile device considerations.
- Human resource security (pre-employment, during employment, termination/change).
- Asset management, information classification and media handling for network equipment and customer data.
- Access control and user/system access management specific to network elements and OSS/BSS systems.
- Cryptography guidance for protecting communications and sensitive data.
- Physical & environmental security for radio sites, exchanges, cable routes and shared facilities.
- Operations security: procedures, malware protection, logging/monitoring, backups and vulnerability management.
- Communications & network security with additional guidance for network attacks and congestion mitigation (Annex B).
- System acquisition, development & maintenance security requirements for telecom systems.
- Supplier relationships and service delivery management for shared/outsourced network functions.
- Incident management and response tailored to telecom service availability and subscriber impact.
- Business continuity & redundancy focusing on sustaining telecommunications services.
- Compliance obligations and documentation.
The standard includes an Annex A (telecommunications extended control set) and Annex B (network security guidance), and aligns with ITU‑T Recommendation X.1051.
Practical applications - who uses it
EN ISO/IEC 27011:2020 is used by:
- Telecom operators, mobile network operators and ISPs implementing an ISMS.
- Network architects and security engineers designing secure network topologies.
- Information security managers and CISOs aligning controls with ISO/IEC 27002.
- Procurement, supplier and vendor managers enforcing security in contracts.
- Auditors and regulators assessing compliance and service reliability.
- Consultants and integrators tailoring security for wired, wireless and broadband services.
Practical uses include control selection and implementation, risk assessments for network services, supplier security clauses, incident response playbooks, and continuity planning for critical telecom infrastructure.
Related standards
- ISO/IEC 27002 - baseline controls and best practices for information security.
- ISO/IEC 27001 - requirements for an information security management system (ISMS).
- ITU‑T X.1051 - identical text and guidance for telecommunications security.