O-RAN WG11 Security Specification
Supply Chain, SDLC, Privacy, Trust

O-RAN WG11 Security Specification ORANWG11-8: Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust

Operate supply chain security + secure development lifecycle (SDL) + privacy + multi-vendor trust per O-RAN WG11 Security Requirements + Open Fronthaul vendor profile + national telecom security regimes. Supply chain security must (a) qualify O-RAN vendors and suppliers per NIST SP 800-161 SCRM tailored to telecom (vendor cybersecurity maturity + product security incident response + secure development + provenance + SBOM availability + sub-component visibility + national security review where applicable), (b) embed cybersecurity requirements in procurement (RFPs + contracts + acceptance testing + warranty), (c) verify trusted source + tamper-evident packaging + integrity verification of received components + firmware + software, (d) align with national telecom supply chain security regulations (UK TSR + US CISA + EU 5G Toolbox + Japan + Australia + similar). Secure development lifecycle must (a) require vendors to operate SDL per WG11 SDL Requirements + ISO/IEC 27034 + or equivalent including threat modeling + secure coding + security testing + vulnerability disclosure + product security incident response (PSIRT), (b) demonstrate SDL conformance via attestation + third-party assessment + or certification (CC + SOC 2 + ISO 27001 + sectoral), (c) integrate vendor SDL with operator security programme via continuous communication + advisory consumption + joint exercises. Privacy must (a) handle user data per applicable telecom privacy regulation (GDPR + national telecom privacy + lawful intercept + data retention), (b) implement privacy by design across O-RAN components + interfaces, (c) document the privacy posture per deployment with cross-border data transfer considerations + subscriber data minimisation. Multi-vendor interoperability and trust must (a) define trust relationships between vendors in deployment + with documented trust boundaries + cryptographic enforcement, (b) maintain interoperability + security regression testing across vendor versions and releases, (c) coordinate vulnerability response across multi-vendor deployment with integrated communication and patching.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 20 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

APPI · 1 control

  • APPI-A31 Provision of Personally Referable Information

Bahrain PDPL · 1 control

  • BH-PDPL-18 Regular security testing and assessment
  • FFIEC-08 Application security controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)

ISO/IEC 27400:2022 · 1 control

  • 27400-6.3 Secure Update Mechanism
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • IM8-DSS.3 Secure Development Practices

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 20 it maps to, and the evidence behind each claim, over MCP and REST.