The EU Agency for Cybersecurity (ENISA) continues its excellent effort on 5G security by issuing a report with suggested good practices for the secure deployment of Network Function Virtualisation (NFV) in 5G networks.

The report identifies some 60 security challenges for NFV, which it groups in seven categories:

  1. Virtualisation or containerisation;
  2. Orchestration and management;
  3. Administration and access control;
  4. New and legacy technologies;
  5. Adoption of open source or COTS;
  6. Supply chain;
  7. Lawful interception (LI).

It analyses the relevant security controls and recommends 55 best practices to address these challenges, across technical, policy and organisational facets.

Some of the main issues identified are ensuring the security of the virtualisation layer, to protect the rest of the network; avoiding breaches through server sharing; vulnerabilities from adopting open-source software; and increased security complexity through multi-vendor networks.

Like everything else from ENISA, the report is free. You don’t even have to enter your email address.

ENISA press release: Tackling Security Challenges in 5G Networks

ENISA NFV Security in 5G Report

marin@5g.security | Website | Other articles

Marin Ivezic is a Cybersecurity & Privacy Partner in PwC Canada focused on risks of emerging technologies.

ENISA NFV Security in 5G