Frameworks / O-RAN WG11 Security Specification / ORANWG11-2 O-RAN WG11 Security Specification
O-RAN Interface Security
O-RAN WG11 Security Specification ORANWG11-2: O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul Secure O-RAN open interfaces per O-RAN Alliance WG11 Security Requirements Specifications covering E2 (Near-RT RIC to E2 Node) + A1 (Non-RT RIC to Near-RT RIC) + O1 (SMO to managed function) + O2 (SMO to O-Cloud) + Open Fronthaul (O-DU to O-RU). Interface security requirements per WG11 must address (a) authentication of all interface peers with mutual TLS (mTLS) + certificate-based + or equivalent strong authentication, (b) confidentiality via TLS 1.2/1.3 + IPsec + or equivalent for management and control traffic + with cryptographic suites per O-RAN WG11 cryptographic requirements, (c) integrity protection of interface messages and parameters, (d) replay protection via nonce + sequence numbers + or equivalent, (e) authorisation enforcement appropriate to interface (role-based access + scope tokens + OAuth2 for application-layer interfaces + 3GPP-style network function authorisation where applicable), (f) traffic separation between control + management + user planes with appropriate cryptographic isolation. Open Fronthaul-specific requirements must address (a) M-Plane authentication via NETCONF over SSH or TLS, (b) C-Plane + U-Plane confidentiality where required by deployment risk profile, (c) timing synchronisation security per PTP + Sync-E + GPS/GNSS protection. Implement and verify interface security continuously across multi-vendor deployments.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 381 controls across 130 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained AWWA-1.1 Security Policy and Governance AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.4 Physical Access Controls AWWA-3.1 Network Segmentation CPG-1.A Changing Default Passwords CPG-1.C Unique Credentials CPG-1.D Revoking Credentials for Departing Employees CPG-4.C Basic Cybersecurity Training CPG-6.B Supply Chain Incident Reporting CPG-8.A Network Segmentation 27011-1 Scope 27011-3 Terms and definitions 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.2 Network security and segregation ISO27043-04 Roles and responsibilities definition ISO27043-11 Access control policy and enforcement ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-27 Network security management ISO21434-04 Roles and responsibilities definition ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-27 Network security management IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing IM8-SEC.2 Access Control IM8-SEC.3 Network Security OB-API.4 MI Reporting Specification OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-OPS.1 API Availability Requirements OB-OPS.2 Performance Standards OB-SEC.4 Certificate Management ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-23 Protect authentication credentials (Excellent) ASD37-25 Software firewall - inbound (Very Good) FFIEC-05 Roles and responsibilities definition FFIEC-06 Network security and segmentation FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-13 Business Continuity and Recovery BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management DSO-2 Data Security DSO-3 Data Access Management CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-D5-4 Resilience planning and testing CAT-IRP-4 Organizational characteristics 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience 62351-2 Glossary of terms 62351-8 Role-based access control (RBAC) IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures IEC62443-13 Network security monitoring ISO-15189-5.1 Legal entity ISO-15189-5.4 Structure and authority ISO-15189-6.2 Personnel ISO-15189-6.7 Service agreements ISO-19650-1-4 Information management concepts ISO-19650-1-7 Common Data Environment (CDE) concept ISO-19650-2-5.7 Information model delivery ISO-19650-3-5.3 Trigger events for information exchange ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-17 Facility access controls ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27019-13 Network security monitoring 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-3 Terms and definitions NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-6 Protect-P Data Security (PR.DS-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM ISMSP-AC-01 Access Control Policy ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control ISMSP-SYS-04 Vulnerability Management 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) IEC62304-5.2 Software Requirements Analysis IEC62304-5.3 Software Architectural Design IEC62304-7.2 Risk Control Measures ISO-22320-5.1 General process requirements ISO-22320-5.3 Incident management structure (command) ISO-22320-5.4 Roles and responsibilities ISO23894-1 Scope of AI Risk Management ISO23894-3 AI-Specific Terminology ISO23894-6.2 Scope, Context and Criteria ISO-25012-4.13 Availability ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 27010-13.1 Communications Security 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27031-5.1 IRBC Policy 27031-8.1 Exercising and Testing 27031-B High availability embedded systems 27557-1 Scope 27557-3 Terms and definitions 27557-6.2 Scope, context, and criteria for privacy 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) PSPF24-1 Security Culture, Governance, Risk Management PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security 58.1 Scope 58.3 Definitions CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability AL-DPA-1 Scope and Definitions AL-DPA-3 Lawful Basis for Processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training COBIT-BAI02 Managed requirements definition COBIT-BAI04 Managed availability and capacity FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FEDRAMP-CM-6 Configuration Settings FEDRAMP-CP-9 System Backup IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements ISO-20400-4.2 Principles of sustainable procurement ISO-20400-7.2 Integrating sustainability into specifications ISO28001-PI-01 Personnel Security Screening ISO28001-PS-01 Facility Security ISO-41001-4.1 Understanding the organization and its context ISO-41001-4.3 Determining the scope of the FM management system ISO-56002-4.3 Determining the scope of the innovation management system ISO-56002-8.3.4 Develop solutions ISO8000-DQM-02 Data Quality Dimensions ISO8000-MDG-03 Continuous Improvement ISO-17025-5.1 Legal entity ISO-17025-5.4 Personnel for the management system ISO20000-03 Capacity and availability management ISO20000-15 Access management for services 23837-1.1 Scope 23837-1.7.3 Authentication and classical post-processing 27007-5.2 Audit Programme Objectives 27007-5.4 Establishing the Programme Resources 27014-1 Scope 27014-3 Terms and definitions 27400-3 Terms and definitions 27400-6.1 Secure Device Design 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope 30111-3 Terms and definitions 30111-5.1 Organizational policy ITIL4-03 Capacity and availability management ITIL4-15 Access management for services BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-5 Network, Endpoint, System Development, and Configuration Security ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) EHDSREG-6 Phased Application and Enforcement SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1) SWIFTCSCF-6 Detect Anomalous Activity (Objective 6) C1 Organizational Boundary C3 Scope 1 and 2 Coverage PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 CPSC-CS.1 Network Security for Connected Products CPSC-CS.2 Authentication and Access Controls CERT-1 RRA Certification to EPA USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection CFR211-A-3 Section 211.3 - Definitions AMLCTF-35 Identity Verification Standard APPI-A26 Report of Leakage to the Commission and Notification to the Person AZ-DPA-2 Article 2 - Basic Concepts BS65000-RM-03 Leadership and Culture CA-ITSG33-SC-01 Security Control Catalogue CA-9 Internal System Connections CA-9 Internal System Connections UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct ICP-1 Objectives, Powers and Responsibilities of the Supervisor ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO-14064-1-5.1 Organizational boundaries ISO-26262-3-5 Item definition ISO27003-4.3 Determining the scope of the information security management system 27050-1.4 Terms and definitions 29134-3 Terms and definitions OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices 2.2.2 2.2.2 Vendor default accounts managed NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control AUPRV-4 APP 10-11 Quality, Security of Personal Information NZPRV-2 IPP 5 Storage and Security of Personal Information RUSPD-2 Lawful Basis, Consent, Notice KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI) TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights ACE-CR-4 Cargo Release Authorization 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern CYB-2 Account Security Measures VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 381 it maps to, and the evidence behind each claim, over MCP and REST.