O-RAN WG11 Security Specification
Cryptography, Protocols, PKI

O-RAN WG11 Security Specification ORANWG11-3: Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

Implement cryptography + protocol security + PKI per O-RAN WG11 Security Requirements covering TLS + SSH + IPsec + certificate lifecycle. TLS implementation must (a) use TLS 1.2 minimum + TLS 1.3 preferred + with WG11-approved cipher suites + Perfect Forward Secrecy + certificate verification, (b) enforce minimum key sizes per WG11 cryptographic profile (RSA 2048 minimum + ECDSA P-256 minimum + ECDHE for key exchange), (c) implement OCSP stapling + or CRL checking with documented fallback, (d) protect TLS termination points against attack including downgrade + cipher manipulation + protocol negotiation abuse. SSH implementation must (a) use SSHv2 with WG11-approved cipher suites + KEX algorithms + MAC algorithms, (b) enforce strong authentication (certificate-based + or strong key-based + with multi-factor where applicable to administrative access), (c) restrict SSH access via network segregation + jump host + PAM. IPsec implementation must (a) use IKEv2 + with WG11-approved ESP/AH parameters, (b) implement secure tunnel lifecycle including rekeying + DPD + Perfect Forward Secrecy. PKI and certificate lifecycle management must (a) define certificate hierarchy + Certificate Authority (CA) selection (operator-managed CA + or industry-trusted CA) + certificate policy + CPS, (b) implement automated certificate enrollment (CMP + EST + ACME where applicable) + renewal + revocation, (c) maintain key custody + HSM where appropriate + key rotation per WG11 cryptographic lifecycle requirements, (d) integrate with monitoring for certificate expiry + revocation + anomalous issuance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 236 controls across 108 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP Rev 5 · 5 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-12 User access management and provisioning
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 5 controls

  • ISO21434-04 Roles and responsibilities definition
  • ISO21434-12 User access management and provisioning
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-19 Certificate management
  • AWWA-1.1 Security Policy and Governance
  • AWWA-2.3 Account Management
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

ISO/IEC 23837:2023 · 4 controls

  • 23837-1.1 Scope
  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

NIST SP 800-53 Rev 5 · 4 controls

OWASP ASVS · 4 controls

OWASP MASVS · 4 controls

  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-8.3 Cryptography and key management
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

NIST SP 800-190 · 3 controls

OWASP Top 10:2025 · 3 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)

South Korea ISMS-P · 3 controls

  • ISMSP-AC-02 User Account Management
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-04 Vulnerability Management
  • OB-OPS.2 Performance Standards
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • 58.1 Scope
  • 58.3 Definitions
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training

BSI IT-Grundschutz · 2 controls

  • BSI-01 Account management and provisioning
  • BSI-08 Cryptographic protection of data
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-09 Encryption and key management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • 62351-2 Glossary of terms
  • 62351-9 Cyber security key management
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27010:2015 · 2 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-9.2 Authentication of Sources

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.2 Device Identity and Authentication
  • 29115-3 Terms and definitions
  • 29115-7.4 Level of Assurance 4 (LoA4)

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

Open Banking Security · 2 controls

  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • IM8-CLD.2 Cloud Security Controls
  • IM8-RES.2 Disaster Recovery
  • CFR211-A-3 Section 211.3 - Definitions

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AZ-DPA-2 Article 2 - Basic Concepts

Bahrain PDPL · 1 control

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions

FIDO2 / WebAuthn · 1 control

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition
  • ISO28001-PI-01 Personnel Security Screening

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions
  • BIPA-SEC5-1 Biometric Identifier Definition
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 236 it maps to, and the evidence behind each claim, over MCP and REST.