Frameworks / O-RAN WG11 Security Specification / ORANWG11-3 O-RAN WG11 Security Specification
Cryptography, Protocols, PKI
O-RAN WG11 Security Specification ORANWG11-3: Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management Implement cryptography + protocol security + PKI per O-RAN WG11 Security Requirements covering TLS + SSH + IPsec + certificate lifecycle. TLS implementation must (a) use TLS 1.2 minimum + TLS 1.3 preferred + with WG11-approved cipher suites + Perfect Forward Secrecy + certificate verification, (b) enforce minimum key sizes per WG11 cryptographic profile (RSA 2048 minimum + ECDSA P-256 minimum + ECDHE for key exchange), (c) implement OCSP stapling + or CRL checking with documented fallback, (d) protect TLS termination points against attack including downgrade + cipher manipulation + protocol negotiation abuse. SSH implementation must (a) use SSHv2 with WG11-approved cipher suites + KEX algorithms + MAC algorithms, (b) enforce strong authentication (certificate-based + or strong key-based + with multi-factor where applicable to administrative access), (c) restrict SSH access via network segregation + jump host + PAM. IPsec implementation must (a) use IKEv2 + with WG11-approved ESP/AH parameters, (b) implement secure tunnel lifecycle including rekeying + DPD + Perfect Forward Secrecy. PKI and certificate lifecycle management must (a) define certificate hierarchy + Certificate Authority (CA) selection (operator-managed CA + or industry-trusted CA) + certificate policy + CPS, (b) implement automated certificate enrollment (CMP + EST + ACME where applicable) + renewal + revocation, (c) maintain key custody + HSM where appropriate + key rotation per WG11 cryptographic lifecycle requirements, (d) integrate with monitoring for certificate expiry + revocation + anomalous issuance.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 236 controls across 108 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
FEDRAMP-CM-6 Configuration Settings FEDRAMP-CP-9 System Backup FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity ISO27043-04 Roles and responsibilities definition ISO27043-12 User access management and provisioning ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-04 Roles and responsibilities definition ISO21434-12 User access management and provisioning ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-19 Certificate management AWWA-1.1 Security Policy and Governance AWWA-2.3 Account Management AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection 23837-1.1 Scope 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements IEC62304-5.2 Software Requirements Analysis IEC62304-5.3 Software Architectural Design IEC62304-7.2 Risk Control Measures ISO-15189-5.1 Legal entity ISO-15189-5.4 Structure and authority ISO-15189-6.7 Service agreements ISO-19650-1-4 Information management concepts ISO-19650-1-7 Common Data Environment (CDE) concept ISO-19650-3-5.3 Trigger events for information exchange ISO-22320-5.1 General process requirements ISO-22320-5.3 Incident management structure (command) ISO-22320-5.4 Roles and responsibilities ISO23894-1 Scope of AI Risk Management ISO23894-3 AI-Specific Terminology ISO23894-6.2 Scope, Context and Criteria 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 27011-1 Scope 27011-3 Terms and definitions 27011-8.3 Cryptography and key management 27557-1 Scope 27557-3 Terms and definitions 27557-6.2 Scope, context, and criteria for privacy 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) ISMSP-AC-02 User Account Management ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-04 Vulnerability Management OB-OPS.2 Performance Standards OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management 58.1 Scope 58.3 Definitions AL-DPA-1 Scope and Definitions AL-DPA-3 Lawful Basis for Processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training BSI-01 Account management and provisioning BSI-08 Cryptographic protection of data DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management CJIS-8 Media Protection CJIS-9 System and Communications Protection FFIEC-05 Roles and responsibilities definition FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements 62351-2 Glossary of terms 62351-9 Cyber security key management ISO-20400-4.2 Principles of sustainable procurement ISO-20400-7.2 Integrating sustainability into specifications ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption ISO-41001-4.1 Understanding the organization and its context ISO-41001-4.3 Determining the scope of the FM management system ISO-56002-4.3 Determining the scope of the innovation management system ISO-56002-8.3.4 Develop solutions ISO8000-DQM-02 Data Quality Dimensions ISO8000-MDG-03 Continuous Improvement ISO-17025-5.1 Legal entity ISO-17025-5.4 Personnel for the management system ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 27010-10.1 Cryptographic Protection 27010-9.2 Authentication of Sources 27014-1 Scope 27014-3 Terms and definitions 27400-3 Terms and definitions 27400-6.2 Device Identity and Authentication 29115-3 Terms and definitions 29115-7.4 Level of Assurance 4 (LoA4) 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope 30111-3 Terms and definitions 30111-5.1 Organizational policy STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training C1 Organizational Boundary C3 Scope 1 and 2 Coverage IM8-CLD.2 Cloud Security Controls IM8-RES.2 Disaster Recovery CFR211-A-3 Section 211.3 - Definitions APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) 4.4.1 Resources, Roles, Responsibility, and Authority AZ-DPA-2 Article 2 - Basic Concepts COBIT-BAI02 Managed requirements definition CA-9 Internal System Connections CA-9 Internal System Connections UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct ICP-1 Objectives, Powers and Responsibilities of the Supervisor IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality ISO-14064-1-5.1 Organizational boundaries ISO-26262-3-5 Item definition ISO28001-PI-01 Personnel Security Screening ISO27003-4.3 Determining the scope of the information security management system 27007-5.2 Audit Programme Objectives 27050-1.4 Terms and definitions 29134-3 Terms and definitions BIPA-SEC5-1 Biometric Identifier Definition NISTPF-5 Protect-P Access Control (PR.AC-P) OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs 2.2.2 2.2.2 Vendor default accounts managed NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control AUPRV-4 APP 10-11 Quality, Security of Personal Information NZPRV-2 IPP 5 Storage and Security of Personal Information PSPF24-1 Security Culture, Governance, Risk Management EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1) PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern USMCADIGITAL-1 Cross-Border Data Flows and Localisation VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 236 it maps to, and the evidence behind each claim, over MCP and REST.