O-RAN Alliance Security Specifications (O-RAN.WG11)
The O-RAN Alliance Working Group 11 (Security) develops security specifications for Open Radio Access Networks. O-RAN disaggregates traditional RAN into components (O-RU, O-DU, O-CU, Near-RT RIC, Non-RT RIC, SMO) with open interfaces, creating new security considerations. Key specifications include: O-RAN Security Requirements and Architecture (WG11), O-RAN Threat Model, security for open fronthaul (M-plane, C/U-plane), RIC security, and supply chain security. As O-RAN deployment grows globally (driven by operators including Deutsche Telekom, NTT DOCOMO, Vodafone, and Rakuten), these security requirements become critical for network integrity.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
AI Security
| Code | Title |
|---|---|
| WG11-AI-001 | Security of AI and ML in RIC |
Application Security
| Code | Title |
|---|---|
| WG11-XAPP-001 | xApp and rApp Lifecycle Security |
Architecture
| Code | Title |
|---|---|
| WG11-ZTA-001 | Zero Trust Principles Across O-RAN |
Assurance
| Code | Title |
|---|---|
| WG11-TEST-001 | Security Test and Certification |
Cloud Platform
| Code | Title |
|---|---|
| WG11-O2-001 | O2 Interface and O-Cloud Security |
Configuration Management
| Code | Title |
|---|---|
| WG11-CONFIG-001 | Secure Configuration Baselines |
Conformance
| Code | Title |
|---|---|
| WG11-CONFORM-001 | Conformance Evidence Against WG11 Specifications |
Cryptography
| Code | Title |
|---|---|
| WG11-PKI-001 | PKI and Certificate Lifecycle Management |
Data and Application Security
| Code | Title |
|---|---|
| ORAN-SEC-5.1 | Secure Data Deletion |
| ORAN-SEC-5.2 | Application Security |
Detection and Response
| Code | Title |
|---|---|
| WG11-LOG-001 | Security Logging and Monitoring |
Incident Response
| Code | Title |
|---|---|
| WG11-INCIDENT-001 | Incident Response for O-RAN Specific Threats |
Interface Security
| Code | Title |
|---|---|
| WG11-A1-001 | A1 Interface Security |
| WG11-E2-001 | E2 Interface Authentication and Confidentiality |
| WG11-FH-001 | Open Fronthaul Interface Security |
Management Plane
| Code | Title |
|---|---|
| WG11-O1-001 | O1 Management Interface Security |
Multi-Vendor
| Code | Title |
|---|---|
| WG11-INTEROP-001 | Interoperability and Multi-Vendor Trust |
Privacy
| Code | Title |
|---|---|
| WG11-PRIV-001 | Privacy and User Data Handling |
Resilience
| Code | Title |
|---|---|
| WG11-DENIAL-001 | Denial of Service Resilience |
Secure Development
| Code | Title |
|---|---|
| WG11-SECDEV-001 | Secure Development Lifecycle for O-RAN Products |
Security Protocols (O-RAN.WG11 Pillar 3)
| Code | Title |
|---|---|
| ORAN-SEC-3.1 | TLS Implementation |
| ORAN-SEC-3.2 | SSH and IPSec Protocols |
| ORAN-SEC-3.3 | Certificate Management |
Security Requirements (O-RAN.WG11 Pillar 2 - O-R003)
| Code | Title |
|---|---|
| ORAN-SEC-2.1 | Interface Security Requirements |
| ORAN-SEC-2.2 | Confidentiality, Integrity, Availability |
| ORAN-SEC-2.3 | Least Privilege and Zero Trust |
| ORAN-SEC-2.4 | Cross-Platform Security Requirements |
Security Testing (O-RAN.WG11 Pillar 4)
| Code | Title |
|---|---|
| ORAN-SEC-4.1 | Security Test Specifications |
| ORAN-SEC-4.2 | Security Log Management |
Security Threat Modeling (O-RAN.WG11 Pillar 1)
| Code | Title |
|---|---|
| ORAN-SEC-1.1 | Threat Modeling and Remediation |
| ORAN-SEC-1.2 | Risk Management |
Supply Chain Security
| Code | Title |
|---|---|
| WG11-SUPPLY-001 | Supply Chain and Vendor Assurance |
Threat Modeling
| Code | Title |
|---|---|
| WG11-THREAT-001 | O-RAN Threat Model and Risk Assessment |
Vulnerability Management
| Code | Title |
|---|---|
| WG11-PATCH-001 | Vulnerability and Patch Management |
Your Compliance Coverage
If you comply with O-RAN Alliance Security Specifications (O-RAN.WG11), you already cover:
CSA CCM v4
26%
9 controls mapped
Compare →ASD Information Security Manual (ISM)
26%
9 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
26%
9 controls mapped
Compare →+ 628 more: ISO 27001:2022 (24%), CSA STAR (Security, Trust, Assurance, and Risk) (24%)
See all 631 mapped frameworks ↓Maps to 631 other frameworks
Frequently Asked Questions
What is O-RAN Alliance Security Specifications (O-RAN.WG11)?
O-RAN Alliance Security Specifications (O-RAN.WG11) is a compliance framework from International (O-RAN Alliance) with 24 domains and 34 controls. The O-RAN Alliance Working Group 11 (Security) develops security specifications for Open Radio Access Networks. O-RAN disaggregates traditional RAN into components (O-RU, O-DU, O-CU, Near-RT RIC, Non-RT RIC, SMO) with open interfaces, creating new security considerations. Key specifications include: O-RAN Security Requirements and Architecture (WG11), O-RAN Threat Model, security for open fronthaul (M-plane, C/U-plane), RIC security, and supply chain security. As O-RAN deployment grows globally (driven by operators including Deutsche Telekom, NTT DOCOMO, Vodafone, and Rakuten), these security requirements become critical for network integrity. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does O-RAN Alliance Security Specifications (O-RAN.WG11) have?
O-RAN Alliance Security Specifications (O-RAN.WG11) has 34 controls organised across 24 domains. The largest domains are Security Requirements (O-RAN.WG11 Pillar 2 - O-R003) (4 controls), Interface Security (3 controls), Security Protocols (O-RAN.WG11 Pillar 3) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does O-RAN Alliance Security Specifications (O-RAN.WG11) map to?
O-RAN Alliance Security Specifications (O-RAN.WG11) maps to 631 other compliance frameworks. The top mapping partners are CSA CCM v4 (26% coverage), ASD Information Security Manual (ISM) (26% coverage), TISAX — Trusted Information Security Assessment Exchange (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with O-RAN Alliance Security Specifications (O-RAN.WG11) compliance?
Start your O-RAN Alliance Security Specifications (O-RAN.WG11) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about O-RAN Alliance Security Specifications (O-RAN.WG11) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required