ITU-T X.805 - Security Architecture for End-to-End Communications
X.805 Security Dimension 2 - Authentication

ITU-T X.805 - Security Architecture for End-to-End Communications X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication: ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication

Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication confirms that each party to a communication (for example a person, device, service or application) really is who it claims to be, and gives assurance that no party is impersonating another or replaying an earlier exchange without authorization. (1) Authentication Categories per X.805 + X.800 + X.811 framework: (a) Peer Entity Authentication - mutual + unilateral + verifying communicating parties; (b) Data Origin Authentication - verifying source of received data; (c) Authentication of the User + Device + Service + Application + Process. (2) Authentication Factors per NIST SP 800-63: (a) Something you know - password + PIN + passphrase; (b) Something you have - smart card + token + hardware key + mobile device; (c) Something you are - biometric (fingerprint + face + iris + voice + behavioural); (d) Somewhere you are - geolocation + IP + device fingerprint; (e) Something you do - behavioural biometrics + typing pattern. Multi-Factor Authentication (MFA) combines 2+ factors from different categories. (3) Strong Authentication Mechanisms: (a) Public Key Infrastructure (PKI) + X.509 Certificates; (b) Kerberos (TGT + service tickets); (c) FIDO2 + WebAuthn + Passkeys; (d) OAuth 2.0 + OpenID Connect + JWT tokens; (e) SAML 2.0 SSO; (f) Time-Based One-Time Password (TOTP) + RFC 6238; (g) HMAC-Based OTP (HOTP) + RFC 4226; (h) Out-of-Band + push notification + SMS (deprecated by NIST); (i) Biometric authentication (FIDO biometrics + Apple Face ID + Touch ID + Windows Hello); (j) Hardware tokens (YubiKey + RSA SecurID + Google Titan); (k) Smart cards + PIV + CAC + national eID. (4) Authentication per Security Layer: (a) Infrastructure - device authentication + 802.1X + MACsec mutual auth + physical port authentication + IPSec IKEv2 mutual; (b) Services - service-level auth + IMS AKA + 5G AKA + Diameter authentication + RADIUS + TACACS+; (c) Applications - application user auth + email + web + directory + file transfer + IM. (5) Authentication per Security Plane: (a) Management - administrator authentication + multi-factor mandatory + privileged access; (b) Control - signalling node authentication + BGP MD5/RPKI + OSPF MD5/HMAC + IS-IS MD5 + IKE; (c) End-User - subscriber + user authentication + SIM + EAP-SIM/AKA + WPA2-Enterprise EAP-TLS. (6) Threats Mitigated per X.805 Table 1: (a) Corruption (Y) - prevents unauthorized changes by impostors; (b) Disclosure (Y) - prevents impostor obtaining information; (c) Interruption (Y) - prevents impostor service disruption. (7) Standards: (a) ISO/IEC 27001 A.9.2 + A.9.4 (2013) / A.5.16 + A.8.5 (2022); (b) NIST SP 800-53 IA family; (c) NIST SP 800-63A/B/C Digital Identity; (d) ITU-T X.509 PKI; (e) ITU-T X.811 Authentication Framework; (f) 3GPP TS 33.501 5G Auth + 33.220 GBA; (g) IETF RFC 4226/6238 OTP + RFC 8252 OAuth Native Apps + RFC 6749 OAuth 2.0; (h) FIDO Alliance specifications; (i) ICAO Doc 9303 Machine Readable Travel Documents; (j) GSMA Mobile Connect; (k) eIDAS Regulation (EU); (l) ENISA Trust Services and eIDAS. (8) Modern Evolution: (a) Passwordless authentication via FIDO2/WebAuthn/Passkeys; (b) Continuous Authentication via behavioural biometrics; (c) Risk-Based Authentication (RBA) with context; (d) Decentralised Identity (DID) + Verifiable Credentials (VCs); (e) Self-Sovereign Identity (SSI); (f) Zero Trust Identity verification continuous; (g) Adaptive MFA; (h) Workload Identity (SPIFFE/SPIRE); (i) Post-Quantum Cryptography (PQC) for authentication keys. Coordinates with ITU-T X.509 PKI + X.811 Authentication Framework + X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Corruption/Disclosure/Interruption + Security Dimension 1 Access Control + ISO/IEC 27001 + NIST SP 800-53 + NIST SP 800-63 + FIDO Alliance + 3GPP 5G AKA + GSMA Mobile Connect + IETF OAuth + eIDAS. ITU-T X.805 Security Dimension 2 Authentication applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 119 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats

NIST SP 800-53 Rev 5 · 3 controls

  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-SEC.4 Certificate Management
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

MARS-E · 2 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures
  • VP-2 Holder Binding
  • W3CVCDM-4 Accessibility, Internationalization, Security
  • AMLCTF-35 Identity Verification Standard

BSI IT-Grundschutz · 1 control

  • BSI-03 Multi-factor authentication requirements
  • DSO-3 Data Access Management

ISO 27799:2025 · 1 control

  • ISO27799-12 Unique user identification and authentication

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27043:2015 · 1 control

  • ISO27043-13 Authentication and password management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/SAE 21434 · 1 control

  • ISO21434-13 Authentication and password management
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • OWASPAPI-2 Broken Authentication and Token Management

OWASP ASVS · 1 control

  • OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4)
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice
  • SHAREASSESS-2 Access Control, Identity, Authentication

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization

SWIFT CSCF · 1 control

  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea ISMS-P · 1 control

  • ISMSP-AC-03 Authentication Mechanisms
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 119 it maps to, and the evidence behind each claim, over MCP and REST.