O-RAN WG11 Security Specification
Cryptography, Protocols, PKI

O-RAN WG11 Security Specification ORANWG11-3: Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

Implement cryptography + protocol security + PKI per O-RAN WG11 Security Requirements covering TLS + SSH + IPsec + certificate lifecycle. TLS implementation must (a) use TLS 1.2 minimum + TLS 1.3 preferred + with WG11-approved cipher suites + Perfect Forward Secrecy + certificate verification, (b) enforce minimum key sizes per WG11 cryptographic profile (RSA 2048 minimum + ECDSA P-256 minimum + ECDHE for key exchange), (c) implement OCSP stapling + or CRL checking with documented fallback, (d) protect TLS termination points against attack including downgrade + cipher manipulation + protocol negotiation abuse. SSH implementation must (a) use SSHv2 with WG11-approved cipher suites + KEX algorithms + MAC algorithms, (b) enforce strong authentication (certificate-based + or strong key-based + with multi-factor where applicable to administrative access), (c) restrict SSH access via network segregation + jump host + PAM. IPsec implementation must (a) use IKEv2 + with WG11-approved ESP/AH parameters, (b) implement secure tunnel lifecycle including rekeying + DPD + Perfect Forward Secrecy. PKI and certificate lifecycle management must (a) define certificate hierarchy + Certificate Authority (CA) selection (operator-managed CA + or industry-trusted CA) + certificate policy + CPS, (b) implement automated certificate enrollment (CMP + EST + ACME where applicable) + renewal + revocation, (c) maintain key custody + HSM where appropriate + key rotation per WG11 cryptographic lifecycle requirements, (d) integrate with monitoring for certificate expiry + revocation + anomalous issuance.

What else in your programme already covers this

This control maps to 279 controls across 122 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 5 controls

ISO/SAE 21434 · 5 controls

ISO/IEC 27011:2024 · 4 controls

ISO/IEC 27400:2022 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

OWASP ASVS · 4 controls

OWASP MASVS · 4 controls

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO 22320:2018 · 3 controls

ISO 27017 · 3 controls

ISO 27018 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

NIST SP 800-190 · 3 controls

OWASP Top 10:2025 · 3 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)

South Korea ISMS-P · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training

BSI IT-Grundschutz · 2 controls

  • BSI-01 Account management and provisioning
  • BSI-08 Cryptographic protection of data
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-09 Encryption and key management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO 13485 · 2 controls

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 27799 · 2 controls

ISO 56002 · 2 controls

ISO/IEC 27010:2015 · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

Open Banking Security · 2 controls

  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)
  • 4.4.1 Resources, Roles, Responsibility, and Authority

Bahrain PDPL · 1 control

COBIT 2019 · 1 control

FIDO2 / WebAuthn · 1 control

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 279 it maps to, and the evidence behind each claim, over MCP and REST.