O-RAN WG11 Security Specification
Threat Model and Risk Management

O-RAN WG11 Security Specification ORANWG11-1: O-RAN Threat Model, Risk Management, and Security Architecture

Maintain the O-RAN threat model and risk management per O-RAN Alliance WG11 Security Threat Model and Risk Assessment specifications. The threat model must (a) enumerate threat actors targeting O-RAN deployments (nation-state attackers + criminal organisations targeting telecom + insiders with operator or vendor access + compromised vendors + supply-chain attackers), (b) catalogue attack surfaces specific to O-RAN architecture (RAN Intelligent Controller (RIC) + xApps/rApps + open interfaces (E2 + A1 + O1 + O2 + Open Fronthaul) + O-Cloud platform + multi-vendor integration boundaries + AI/ML decision points + SMO + management plane), (c) maintain attack scenarios covering rogue xApp / rApp + interface protocol abuse + supply chain compromise + RIC compromise enabling RAN policy manipulation + management interface compromise + Open Fronthaul tap or man-in-the-middle, (d) integrate threat intelligence from sectoral channels (CISA + telecom ISAC + GSMA + national CERT) and from O-RAN security focus groups. Risk management must operate per O-RAN WG11 risk methodology aligned with NIST SP 800-30 + ISO 27005 + 3GPP TS 33.117 + 33.512 + 33.513 SECAM/SCAS profiles where applicable. Security architecture must implement WG11 Security Architecture specification including the high-level reference architecture + security functions placement + trust zones + secure interconnects.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 121 controls across 59 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CAT-D1-2 Risk management
  • CAT-D2-1 Threat intelligence
  • CAT-D2-2 Monitoring and analyzing
  • CAT-D3-3 Corrective controls
  • CAT-IRP-5 External threats
  • CAT-ML-2 Evolving
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources

NIST SP 800-53 Rev 5 · 5 controls

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach

BSI IT-Grundschutz · 2 controls

  • BSI-14 Vulnerability scanning and management
  • BSI-16 Threat intelligence integration
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.4 Threat intelligence for telecom
  • 27011-8.5 Vulnerability and malware management

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 2 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-SYS-04 Vulnerability Management
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • ACQS-8-4 Risk Management
  • CPG-5.A Vulnerability Disclosure Program
  • CJIS-19 Supply Chain Risk Management
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/IEC 27400:2022 · 1 control

  • 27400-5.1 IoT Security and Privacy Governance

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management

NIST SP 1800-32 · 1 control

NIST SP 800-190 · 1 control

  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates

OWASP Top 10:2025 · 1 control

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • CRM-3 Risk Management Framework
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 121 it maps to, and the evidence behind each claim, over MCP and REST.