O-RAN WG11 Security Specification
The O‑RAN Alliance Working Group 11 (WG11) defines the Security Specification for Open Radio Access Networks. It addresses threat modeling, security domains, security functions, and security controls for O‑RU, O‑DU, O‑CU, Near‑RT RIC, Non‑RT RIC, and SMO components, and provides guidance on authentication, integrity, confidentiality, and secure lifecycle management.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Cryptography, Protocols, PKI
| Code | Title |
|---|---|
| ORANWG11-3 | Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management |
Logging, Monitoring, IR, DoS
| Code | Title |
|---|---|
| ORANWG11-7 | Logging, Monitoring, Incident Response, and Denial-of-Service Resilience |
O-Cloud, Containers, Configuration, Patching
| Code | Title |
|---|---|
| ORANWG11-5 | O-Cloud, Container Security, Secure Configuration, Patching |
O-RAN Interface Security
| Code | Title |
|---|---|
| ORANWG11-2 | O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul |
RIC, xApps/rApps, AI/ML
| Code | Title |
|---|---|
| ORANWG11-4 | RIC, xApp/rApp Lifecycle, AI/ML Security |
Security Test and Certification
| Code | Title |
|---|---|
| ORANWG11-6 | Security Test Specifications, Certification, and Conformance |
Supply Chain, SDLC, Privacy, Trust
| Code | Title |
|---|---|
| ORANWG11-8 | Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust |
Threat Model and Risk Management
| Code | Title |
|---|---|
| ORANWG11-1 | O-RAN Threat Model, Risk Management, and Security Architecture |
Your Compliance Coverage
If you comply with O-RAN WG11 Security Specification, you already cover:
OWASP DevSecOps Maturity Model (DSOMM)
75%
6 controls mapped
Compare →FTC GLBA Safeguards Rule (16 CFR Part 314)
75%
6 controls mapped
Compare →Open Banking Security
63%
5 controls mapped
Compare →+ 149 more: APRA CPS 234 (63%), NIST Cybersecurity Framework 2.0 (63%)
See all 152 mapped frameworks ↓Maps to 152 other frameworks
Frequently Asked Questions
What is O-RAN WG11 Security Specification?
O-RAN WG11 Security Specification is a compliance framework from International (O-RAN Alliance) with 8 domains and 8 controls. The O‑RAN Alliance Working Group 11 (WG11) defines the Security Specification for Open Radio Access Networks. It addresses threat modeling, security domains, security functions, and security controls for O‑RU, O‑DU, O‑CU, Near‑RT RIC, Non‑RT RIC, and SMO components, and provides guidance on authentication, integrity, confidentiality, and secure lifecycle management. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does O-RAN WG11 Security Specification have?
O-RAN WG11 Security Specification has 8 controls organised across 8 domains. The largest domains are Cryptography, Protocols, PKI (1 controls), Logging, Monitoring, IR, DoS (1 controls), O-Cloud, Containers, Configuration, Patching (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does O-RAN WG11 Security Specification map to?
O-RAN WG11 Security Specification maps to 152 other compliance frameworks. The top mapping partners are OWASP DevSecOps Maturity Model (DSOMM) (75% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (75% coverage), Open Banking Security (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with O-RAN WG11 Security Specification compliance?
Start your O-RAN WG11 Security Specification compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about O-RAN WG11 Security Specification requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required