3GPP 5G Security Architecture (TS 33.501)
Authentication Procedures

3GPP 5G Security Architecture (TS 33.501) TS33.501-6.1: Authentication Framework

Primary authentication and key agreement based on EAP-AKA' and 5G-AKA protocols

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 72 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users)
  • NIST800-IA-4 IA-4 Identifier Management
  • NIST800-IA-7 IA-7 Cryptographic Module Authentication
  • NIST800-IA-8 IA-8 Identification and Authentication (Non-organizational Users)
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-SEC.4 Certificate Management
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • AMLCTF-35 Identity Verification Standard

BSI IT-Grundschutz · 1 control

  • BSI-03 Multi-factor authentication requirements
  • DSO-3 Data Access Management

ISO 27799:2025 · 1 control

  • ISO27799-12 Unique user identification and authentication

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27043:2015 · 1 control

  • ISO27043-13 Authentication and password management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/SAE 21434 · 1 control

  • ISO21434-13 Authentication and password management

NIST SP 800-187 · 1 control

NIST SP 800-190 · 1 control

  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization

South Korea ISMS-P · 1 control

  • ISMSP-AC-03 Authentication Mechanisms
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls
  • VP-2 Holder Binding

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Authentication Procedures

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.