It becomes a governance problem when one team cannot clearly own operator relationships, profile lifecycle, and provisioning policy across fleets. In that situation, technical flexibility can hide dependency risk, make change control harder, and weaken accountability for service continuity. Organisations should treat connectivity architecture as part of device governance, not just telecom procurement.
Why This Matters for Security Teams
eSIM and RSP are often introduced as telecom efficiency upgrades, but they quickly become governance issues when identity, ownership, and change control blur across device fleets. The real risk is not just whether a profile can be downloaded, but who can approve it, revoke it, audit it, and prove it was tied to the right asset at the right time. NIST’s Cybersecurity Framework 2.0 frames this as an asset and access governance problem, not a carrier procurement detail.
That distinction matters because eSIM profiles can outlive the operational assumptions that created them. When devices are shipped globally, resold, refurbished, or reassigned, profile sprawl can create hidden dependencies that neither network teams nor security teams fully own. NHIMG’s Top 10 NHI Issues is relevant here because the same pattern appears in other machine-scale identity systems: weak lifecycle ownership turns a technical convenience into an audit and resilience gap. In practice, many security teams encounter profile drift only after a carrier change, incident, or fleet migration has already exposed the gap.
How It Works in Practice
The governance threshold is crossed when eSIM and RSP decisions affect who can provision connectivity, under what conditions, and with what evidence. At that point, the organisation needs a clear model for profile issuance, approval, inventory, revocation, and exception handling. The operational question becomes: is this profile tied to a known device, an approved purpose, and a defined owner, or is it simply being pushed wherever the fleet tooling allows?
Current best practice is to treat RSP as part of device identity and lifecycle management. That means mapping:
- asset owner and business purpose for each device class
- approved carriers, regions, and contingency profiles
- who can trigger downloads, swaps, and deletions
- how changes are logged, reviewed, and reverted
- how decommissioning removes lingering access paths
This is where the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs becomes useful as a governance analogue: if the lifecycle is not controlled, the identity becomes an unmanaged dependency. On the control side, NIST SP 800-53 Rev. 5 security and privacy controls support this model through configuration management, access enforcement, and audit logging expectations. For resilience planning, the Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a reminder that evidence of control is as important as the control itself.
Teams should also separate connectivity autonomy from uncontrolled flexibility. A valid governance design allows rapid provisioning for legitimate operations, but only through policy-backed approvals and traceable ownership. These controls tend to break down when global fleets mix local telecom exceptions, third-party device managers, and emergency provisioning paths because no single team can reconstruct the full change history.
Common Variations and Edge Cases
Tighter eSIM governance often increases operational overhead, requiring organisations to balance speed of provisioning against auditability and continuity. That tradeoff becomes sharper in environments with cross-border logistics, contractor devices, regulated assets, or frequent hardware refresh cycles.
There is no universal standard for this yet, so guidance is still evolving. Some organisations centralise all profile decisions in security or infrastructure teams, while others leave carrier operations with IT and require security sign-off only for exceptions. The right answer usually depends on the risk profile of the fleet, not the procurement model.
Edge cases are where governance failures hide. A device may be technically online but misaligned with policy if it is using an old profile after reassignment, a backup profile after a primary carrier failure, or a temporary provisioning path that was never retired. That is why eSIM and RSP should be reviewed alongside asset inventory, change management, and incident response rather than as a standalone telecom workflow. NHIMG’s Regulatory and Audit Perspectives section is particularly relevant when teams need to prove control ownership after the fact.
In practice, the problem becomes visible only when an organisation cannot answer a simple question quickly: which business owner can revoke connectivity for this device, today, without breaking the wrong service?
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-1 | eSIM and RSP governance depends on knowing what devices and profiles exist. |
| NIST SP 800-53 Rev 5 | CM-2 | Profile lifecycle changes need baseline control and change tracking. |
| NIST AI RMF | AI RMF governance logic maps well to deciding who owns fleet connectivity risk. |
Assign accountable owners, document risk decisions, and review exceptions as part of governance.
Related resources from NHI Mgmt Group
- When does privileged access in OT become a governance problem rather than an operations issue?
- Why do software licences become a governance problem rather than just a cost issue?
- When does tool sprawl become a governance problem rather than just an efficiency issue?
- When do AI supply chain risks become a governance problem rather than a data science issue?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org