O-RAN WG11 Security Specification ORANWG11-6: Security Test Specifications, Certification, and Conformance
Operate security test + certification + conformance per O-RAN WG11 Security Test Specifications and WG11 Test Specifications including Open Test and Integration Center (OTIC) testing. Security test specifications must cover (a) interface security test cases per E2 + A1 + O1 + O2 + Open Fronthaul testing the authentication + confidentiality + integrity + authorisation + replay protection + cryptographic conformance, (b) component security test cases per O-DU + O-CU + O-RU + Near-RT RIC + Non-RT RIC + SMO + O-Cloud with positive and negative test scenarios, (c) negative test cases probing for known attack vectors + fuzzing + protocol abuse + boundary conditions, (d) penetration testing of integrated multi-vendor deployments. Certification must (a) align with O-RAN OTIC certification program + with vendor self-attestation + third-party assessment as deployment risk profile warrants, (b) align with 3GPP SECAM/SCAS certification for shared components, (c) align with national telecom security certification schemes where applicable (UK TSR + EU 5G Cybersecurity Toolbox + US CISA Secure by Design + similar). Conformance evidence must (a) demonstrate adherence to applicable WG11 specifications with traceability per requirement, (b) be maintained through release lifecycle of products + with regression testing on changes, (c) be available for operator audit + regulator inspection + customer due diligence.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 151 controls across 89 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties