Telecommunications networks have evolved through distinct architectural generations. 4G introduced network functions virtualization (NFV) and software-defined networking (SDN), moving away from hardware-centric, proprietary appliances toward software running on commodity servers. 5G takes this further, adopting cloud-native principles where network functions are containerized, horizontally scalable, and deployed on Kubernetes. Each step in this evolution has delivered greater agility and scale, and each step has also added new layers of complexity and risk.
A 4G or 5G network now comprises multiple stacked layers of infrastructure: physical servers, a hypervisor, virtual machines, container runtimes, Kubernetes clusters. And on top of those, the network functions themselves are supplied by a broad ecosystem of application vendors. Each layer is a potential point of exposure. A vulnerability at the hypervisor level can undermine every workload above it. A misconfigured Kubernetes admission policy can allow a privileged container to run unchecked across the cluster. Risks introduced by one application vendor’s Cloud-Native Network Function (CNF can propagate across shared infrastructure to affect workloads owned by others.
Telecommunications infrastructure is also critical national infrastructure. Advanced persistent threats, ransomware, and supply chain attacks increasingly target the infrastructure layer directly, not just the applications running on it. Securing the IaaS foundation is therefore a precondition for operating a reliable, trustworthy network.
This blog covers how Broadcom’s Telco Cloud Platform, built on VMware Cloud Foundation (VCF), addresses these security requirements.
VCF 9.1 Platform Security: Read the Full Detail
VCF 9.1 delivers platform security improvements across five areas: threat detection and prevention, workload resilience, data encryption, auditing and monitoring, and identity and access.
For the full VCF 9.1 platform security feature detail, read the Broadcom blog:
Strengthen Zero Trust Security and Resilience with VCF 9.1
In addition to these platform capabilities, Broadcom has published specific guidance for Telco regulatory compliance and Kubernetes policy governance, covering how the Telco Cloud Platform maps to the security frameworks that Communication service providers (CSPs) are required to meet.
Regulatory Compliance
CSPs operating across major markets face specific, enforceable security mandates. Broadcom has published Product Applicability Guides for each of the frameworks below, mapping Telco Cloud Platform capabilities directly to regulatory controls.
NIST
Broadcom has released a Product Applicability Guide for NIST 800-53 Revision 5, the result of an independent evaluation by Tevora [1]. The guide maps VMware product capabilities to NIST controls and is designed to help CSPs align their Telco Cloud deployments with established security and privacy controls as they transition toward 5G standalone and beyond.
For the full mapping, refer to: Supporting NIST Compliance and Security Excellence with VMware Telco Cloud Platform
EU NIS2
The telecom sector is designated as an Essential Entity under NIS2, bringing the highest level of regulatory scrutiny, including proactive oversight, mandatory audits, and stringent risk-management documentation requirements [2]. The guide maps VMware product capabilities to the NIS2 directive, covering how the platform supports the ten key measures of Article 21 and evaluates the platform against eleven security lenses [2].
For the full mapping, refer to: Build a NIS2-compliant secure telco cloud using VMware Telco Cloud Platform
UK Telecommunications Security Act (UK TSA)
The Telecommunications Security Code of Practice implements the Telecommunications (Security) Act 2021 and the Electronic Communications (Security Measures) Regulations 2022. It establishes mandatory security outcomes for public telecommunications providers, differentiating between Tier 1 and Tier 2 entities [3]. The Code covers required security outcomes relating to network architecture, supply chain monitoring, and data protection. Providers may adopt alternative technical solutions, but must demonstrate to Ofcom that those alternatives achieve equivalent security standards [3].
Broadcom has published a companion guide mapping Telco Cloud Platform 5.1 and Cloud Foundation 9.0 controls to the UK TSA Code of Practice requirements.
For the full mapping, refer to: UK TSA CoP Companion Guide for Telco Cloud Platform and Cloud Foundation
Kubernetes Policy Governance
The shift to cloud-native 5G network functions places Kubernetes at the centre of the Telco Cloud Platform. Core network functions including Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), and Unified Data Management (UDM) are deployed as containerized workloads across Kubernetes clusters, often spanning central data centres and distributed edge nodes. In large Telco deployments, this may mean hundreds of clusters across geographically distributed sites, with CNFs supplied by multiple application vendors sharing the same underlying infrastructure.
Enforcing consistent security policy across this environment manually is not feasible. The Telco Cloud Platform leverages its Kubernetes Policy Manager to meet the security governance standards and hardening recommendations established by the NSA and CISA [4]. The Kubernetes Policy Manager uses Open Policy Agent (OPA) and Gatekeeper to provide a standardized framework for policy-driven orchestration and governance [4].
This approach means security policy is applied preventatively before a workload runs. The Kubernetes Policy Manager also tracks CNFs deployed before policy enforcement that are found to violate security constraints. These violations, termed audit-time violations, do not result in immediate eviction of the CNF; however, while the security violation persists, the Kubernetes Policy Manager prevents any subsequent lifecycle management operations from being performed on that CNF [4].
Note** While this prevents day-2 drift, it also effectively “freezes” the CNF, allowing governance guardrails by necessitating well-defined remediation workflows to avoid operational outages.
Every policy enforcement action and every policy evaluation is logged and auditable, providing a verifiable record of security posture to demonstrate adherence to regulatory and industry compliance requirements [4].
The Kubernetes Policy Manager’s alignment with NSA and CISA Kubernetes Hardening Guidance[5] addresses the three primary threat categories identified in that publication: supply chain risks, malicious threat actors, and insider threats. The guidance recommends admission controller-based policy enforcement, RBAC with least-privilege principles, etcd encryption, API server audit logging, and control plane network policy as core controls.
For the full details, refer to: Implementing Proactive Security and Governance for Telco Networks using VMware Telco Cloud Platform
Note** Performance-related security features, such as latency sensitivity and NUMA alignment, are configurable performance tuning parameters that require specific Day 0/1 environment setup at the tenant level for each xNF, rather than implicit system-wide behaviors.
Learn More
For security hardening guides, compliance mappings, and feature-specific documentation, visit https://brcm.tech/vcf-security or contact your Broadcom account team.
Other Resources
[1] Supporting NIST Compliance and Security Excellence with VMware Telco Cloud… (blogs.vmware.com)
[2] Build a NIS2-compliant secure telco cloud using VMware Telco Cloud Platfor… (blogs.vmware.com)
[3] vcf-security-and-compliance-guidelines/regulatory-compliance/cloud-foundat… (brcm.tech)
[4] Implementing Proactive Security and Governance for Telco Networks using VM… (blogs.vmware.com)
[5] [PDF] Kubernetes Hardening Guide (media.defense.gov)
Discover more from VMware Telco Cloud Blog
Subscribe to get the latest posts sent to your email.