ITU-T Recommendation X.805 (10/2003) Security architecture for systems providing end-to-end communications is a foundational network security architecture standard published by the International Telecommunication Union Telecommunication Standardization Sector (ITU-T) in October 2003. The Recommendation defines a comprehensive systematic approach to network security covering both telecommunication networks (Public Switched Telephone Network + Public Land Mobile Network + Public Data Network) and converged networks (Next Generation Networks + IP-based networks). (1) Architecture Overview: X.805 establishes a 3-dimensional security architecture providing 72 distinct security perspectives via the orthogonal combination of (a) 3 Security Layers (Infrastructure + Services + Applications) - which together describe the hierarchical decomposition of network capability; (b) 3 Security Planes (Management + Control + End-User) - which together describe the orthogonal types of activity at each Layer; (c) 8 Security Dimensions (Access Control + Authentication + Non-repudiation + Data Confidentiality + Communication Security + Data Integrity + Availability + Privacy) - which together describe the measures applied to each Layer-Plane intersection. The 3 x 3 = 9 Security Perspectives (Module Modules) each measured against the 8 Security Dimensions yields 72 distinct security perspectives. The 72 cells of the X.805 matrix each describe what security measures must be present + assessed + and verified. (2) Five Security Threat Categories per Recommendation X.800 + X.805 Clause 8: (a) Destruction of information and/or other resources - permanent removal or rendering of resources or data; (b) Corruption or modification of information - improper alteration; (c) Removal or loss of information and/or other resources - misappropriation + theft; (d) Disclosure of information - unauthorised observation or access; (e) Interruption of services - making services or resources unavailable. Each Threat is countered by specific Security Dimensions per Table 1 of X.805. (3) Origin and Lineage: X.805 builds on the foundational X.800 Series Recommendations including (a) Recommendation X.800 (1991) Security architecture for Open Systems Interconnection (OSI) for CCITT applications - defined fundamental security services + mechanisms for OSI; (b) Recommendation X.803 (1994) Open Systems Interconnection - Upper layers security model; (c) Recommendation X.811 (1995) Authentication framework; (d) Recommendation X.812 (1995) Access control framework; (e) Recommendation X.813 (1996) Non-repudiation framework; (f) Recommendation X.814 (1995) Confidentiality framework; (g) Recommendation X.815 (1995) Integrity framework; (h) Recommendation X.816 (1995) Security audit and alarm framework. X.805 extends the X.800 Series specifically to end-to-end network security across all access points - Customer Premises Equipment + Service Provider Network + Interconnection Points. (4) Scope: X.805 applies to (a) carrier networks + service providers + private networks + enterprise networks; (b) any network architecture - PSTN + PLMN + IP + ATM + Frame Relay + ISDN + Ethernet + WLAN + WIMAX + IMS + NGN + 5G + IoT; (c) any service + application running over the network; (d) the lifecycle of security including security policy + risk assessment + implementation + operation + monitoring + audit + incident response. (5) Distinct Features: X.805 distinct from other security architectures including (a) explicit Layer-Plane intersection forming Security Perspectives; (b) 8 Security Dimensions including Privacy + Non-Repudiation + Availability that are often missing from earlier architectures; (c) explicit treatment of Telecommunication network specifics (signalling + management + subscriber data); (d) Threats and Countermeasures Matrix linking each Threat to each Dimension; (e) systematic application to each of the 72 cells. (6) Practical Applications + Adoption: X.805 has been widely adopted in (a) Telecom Industry security baseline (NTT + Vodafone + Verizon + AT and T + Deutsche Telekom + Telefonica + Orange + BT + KT + China Mobile + Bharti Airtel + many carriers); (b) GSMA Mobile Network Security (3GPP TS 33-Series); (c) NIST Cybersecurity Framework (CSF) crosswalks; (d) Bell Labs Security Framework (Bell Labs was a key contributor + developed the BSF Bell Labs Security Framework precursor); (e) ISO/IEC 27033 series Network Security (X.805 is principal reference); (f) ITU-T X.1051 + X.1052 + X.1500 family cybersecurity recommendations cite X.805 architecture. (7) Implementation Standards Derived: ITU-T derived from X.805: (a) ITU-T X.1051 Information security management guidelines for telecommunications - mapping to ISO/IEC 27011; (b) ITU-T X.1500-series cybersecurity information exchange; (c) ITU-T Y.2701 + Y.2704 NGN security; (d) ITU-T M.3016 TMN security management; (e) ITU-T X.1303 + X.1311 sensor network security; (f) ITU-T X.1311 Future networks security. (8) X.805 vs Other Frameworks: (a) ISO/IEC 27001 ISMS - X.805 provides security architecture detail to support ISMS; (b) NIST CSF - X.805 maps to Identify + Protect + Detect + Respond + Recover; (c) MITRE ATT and CK - X.805 Threat Categories align with MITRE Tactics; (d) Zero Trust - X.805 8 Dimensions support Zero Trust Pillars; (e) STRIDE Threat Model - X.805 5 Threats parallel STRIDE Threats; (f) ISO 27033 Network Security - X.805 is principal foundation. Coordinates with ITU-T Study Group 17 Security + Recommendation X.800 + X.803 + X.811-816 + X.1051 + X.1052 + X.1500 + Y.2701 + Y.2704 + ISO/IEC 27001 + 27002 + 27011 + 27033 + 27035 + NIST CSF 2.0 + NIST SP 800-53 Rev 5 + NIST SP 800-160 + NIST SP 800-207 Zero Trust + MITRE ATT and CK + STRIDE + 3GPP TS 33-Series + GSMA Mobile Network Security + Bell Labs Security Framework + Telcordia + ETSI TC CYBER + ENISA. ITU-T X.805 Scope + Architecture Overview applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.