ITU-T X.805 - Security Architecture for End-to-End Communications
X.805 Security Dimension 1 - Access Control

ITU-T X.805 - Security Architecture for End-to-End Communications X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications: ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control

Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control guards network resources against use without authorization, admitting only authorized staff or devices to services, applications, information flows, stored information and network elements. Role-Based Access Control (RBAC) adds graded levels of access, so people and devices can reach and act on only the information flows, stored information and network elements for which they hold authorisation. (1) Access Control Sub-Categories per X.805 and related frameworks: (a) Discretionary Access Control (DAC) - resource owner discretion + Access Control Lists (ACLs); (b) Mandatory Access Control (MAC) - system-enforced labels + classification levels + Bell-LaPadula + Biba; (c) Role-Based Access Control (RBAC) - per ISO/IEC 10181-3 + NIST RBAC + ANSI INCITS 359; (d) Attribute-Based Access Control (ABAC) - per NIST SP 800-162 + XACML; (e) Risk-Adaptive Access Control (RAdAC); (f) Capability-Based Access Control. (2) Implementation Mechanisms: (a) ACL Access Control Lists (network + filesystem); (b) Identity and Access Management (IAM) systems; (c) Privileged Access Management (PAM) for administrative accounts; (d) Single Sign-On (SSO) + SAML + OAuth 2.0 + OpenID Connect; (e) Multi-Factor Authentication (MFA) gating access; (f) Just-In-Time (JIT) access provisioning; (g) Just-Enough-Administration (JEA); (h) Zero Trust per NIST SP 800-207 - never trust always verify; (i) network access controls (802.1X + 802.1AE MACsec + NAC Network Access Control + ISE Identity Services Engine); (j) routing controls (BGP RPKI + route filtering); (k) firewall rules (stateful + stateless); (l) WAF Web Application Firewall + API Gateway access policies. (3) Access Control per Security Layer: (a) Infrastructure Layer - physical access controls + biometric + smart card + access to lines + routers + switches + datacenter; (b) Services Layer - service-level authorization + IP service authorization + DNS access + AAA Authentication Authorization Accounting + SS7 access + Mobile NSS + IMS HSS subscriber; (c) Applications Layer - application-level authorization + Email + Web + Directory + File Transfer authorization. (4) Access Control per Security Plane: (a) Management Plane - administrator access + OAM + Configuration; (b) Control Plane - inter-device signalling control + routing protocol authentication; (c) End-User Plane - subscriber + user access to services + content. (5) Threats Mitigated per X.805 Table 1: (a) Destruction (Y); (b) Corruption (Y); (c) Removal (Y); (d) Disclosure (Y); (e) Interruption (Y) - all 5 threats. (6) Standards Referenced: (a) ISO/IEC 27001 A.9 (now A.5.15-A.5.18 + A.8.2-A.8.5 in 2022) Access Control; (b) ISO/IEC 27002 + ISO/IEC 27033 Network Security; (c) NIST SP 800-53 Rev 5 AC family; (d) NIST SP 800-162 ABAC; (e) NIST SP 800-207 Zero Trust; (f) NIST SP 800-63 Digital Identity Guidelines; (g) 3GPP TS 33.310 NDS/AF + TS 33.501 5G Security; (h) GSMA NESAS Network Equipment Security Assurance Scheme; (i) PCI DSS Req 7 + 8; (j) HIPAA Security Rule Access Control. (7) Modern Evolution: (a) Zero Trust replaces perimeter Access Control with continuous verification; (b) SASE Secure Access Service Edge integrates ZTNA Zero Trust Network Access with SD-WAN; (c) Identity-First Security for cloud-native; (d) Just-In-Time provisioning replacing standing privileges; (e) CIEM Cloud Infrastructure Entitlement Management; (f) Workload Identity for K8s + service mesh + SPIFFE/SPIRE. Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Destruction/Corruption/Removal/Disclosure/Interruption + Security Dimension 2 Authentication (foundation for Access Control) + Security Dimension 6 Data Integrity (Access Control prevents unauthorized modification) + Security Dimension 8 Privacy (Access Control implements need-to-know). ITU-T X.805 Security Dimension 1 Access Control applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 180 controls across 100 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

MARS-E · 4 controls

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

MDS2 (Medical Device) · 3 controls

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
  • MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

MITRE ATT&CK · 2 controls

  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • 62351-8 Role-based access control (RBAC)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

Liechtenstein DPA · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Mauritius DPA · 1 control

  • MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training
  • MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

OWASP Top 10:2025 · 1 control

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SHAREASSESS-2 Access Control, Identity, Authentication

SOC 2 · 1 control

  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SA-PDPL-15 Access control for personal data
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-2 Consumer Rights

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • US-ITAR-EAR-DS-03 Access Controls

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 180 it maps to, and the evidence behind each claim, over MCP and REST.