O-RAN WG11 Security Specification
The O‑RAN Alliance Working Group 11 (WG11) defines the Security Specification for Open Radio Access Networks. It addresses threat modeling, security domains, security functions, and security controls for O‑RU, O‑DU, O‑CU, Near‑RT RIC, Non‑RT RIC, and SMO components, and provides guidance on authentication, integrity, confidentiality, and secure lifecycle management.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
AI Security
| Code | Title |
|---|---|
| WG11-AI-001 | Security of AI and ML in RIC |
Application Security
| Code | Title |
|---|---|
| WG11-XAPP-001 | xApp and rApp Lifecycle Security |
Architecture
| Code | Title |
|---|---|
| WG11-ZTA-001 | Zero Trust Principles Across O-RAN |
Assurance
| Code | Title |
|---|---|
| WG11-TEST-001 | Security Test and Certification |
Cloud Platform
| Code | Title |
|---|---|
| WG11-O2-001 | O2 Interface and O-Cloud Security |
Configuration Management
| Code | Title |
|---|---|
| WG11-CONFIG-001 | Secure Configuration Baselines |
Conformance
| Code | Title |
|---|---|
| WG11-CONFORM-001 | Conformance Evidence Against WG11 Specifications |
Cryptography
| Code | Title |
|---|---|
| WG11-PKI-001 | PKI and Certificate Lifecycle Management |
Data and Application Security
| Code | Title |
|---|---|
| ORAN-SEC-5.1 | Secure Data Deletion |
| ORAN-SEC-5.2 | Application Security |
Detection and Response
| Code | Title |
|---|---|
| WG11-LOG-001 | Security Logging and Monitoring |
Incident Response
| Code | Title |
|---|---|
| WG11-INCIDENT-001 | Incident Response for O-RAN Specific Threats |
Interface Security
| Code | Title |
|---|---|
| WG11-A1-001 | A1 Interface Security |
| WG11-E2-001 | E2 Interface Authentication and Confidentiality |
| WG11-FH-001 | Open Fronthaul Interface Security |
Management Plane
| Code | Title |
|---|---|
| WG11-O1-001 | O1 Management Interface Security |
Multi-Vendor
| Code | Title |
|---|---|
| WG11-INTEROP-001 | Interoperability and Multi-Vendor Trust |
Privacy
| Code | Title |
|---|---|
| WG11-PRIV-001 | Privacy and User Data Handling |
Resilience
| Code | Title |
|---|---|
| WG11-DENIAL-001 | Denial of Service Resilience |
Secure Development
| Code | Title |
|---|---|
| WG11-SECDEV-001 | Secure Development Lifecycle for O-RAN Products |
Security Protocols (O-RAN.WG11 Pillar 3)
| Code | Title |
|---|---|
| ORAN-SEC-3.1 | TLS Implementation |
| ORAN-SEC-3.2 | SSH and IPSec Protocols |
| ORAN-SEC-3.3 | Certificate Management |
Security Requirements (O-RAN.WG11 Pillar 2 - O-R003)
| Code | Title |
|---|---|
| ORAN-SEC-2.1 | Interface Security Requirements |
| ORAN-SEC-2.2 | Confidentiality, Integrity, Availability |
| ORAN-SEC-2.3 | Least Privilege and Zero Trust |
| ORAN-SEC-2.4 | Cross-Platform Security Requirements |
Security Testing (O-RAN.WG11 Pillar 4)
| Code | Title |
|---|---|
| ORAN-SEC-4.1 | Security Test Specifications |
| ORAN-SEC-4.2 | Security Log Management |
Security Threat Modeling (O-RAN.WG11 Pillar 1)
| Code | Title |
|---|---|
| ORAN-SEC-1.1 | Threat Modeling and Remediation |
| ORAN-SEC-1.2 | Risk Management |
Supply Chain Security
| Code | Title |
|---|---|
| WG11-SUPPLY-001 | Supply Chain and Vendor Assurance |
Threat Modeling
| Code | Title |
|---|---|
| WG11-THREAT-001 | O-RAN Threat Model and Risk Assessment |
Vulnerability Management
| Code | Title |
|---|---|
| WG11-PATCH-001 | Vulnerability and Patch Management |
Your Compliance Coverage
If you comply with O-RAN WG11 Security Specification, you already cover:
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
26%
9 controls mapped
Compare →ASD Information Security Manual (ISM)
26%
9 controls mapped
Compare →TISAX - Trusted Information Security Assessment Exchange
26%
9 controls mapped
Compare →+ 628 more: ISO 27001:2022 (24%), CSA STAR (Security, Trust, Assurance, and Risk) (24%)
See all 631 mapped frameworks ↓Maps to 631 other frameworks
Frequently Asked Questions
What is O-RAN WG11 Security Specification?
O-RAN WG11 Security Specification is a compliance framework from International (O-RAN Alliance) with 24 domains and 34 controls. The O‑RAN Alliance Working Group 11 (WG11) defines the Security Specification for Open Radio Access Networks. It addresses threat modeling, security domains, security functions, and security controls for O‑RU, O‑DU, O‑CU, Near‑RT RIC, Non‑RT RIC, and SMO components, and provides guidance on authentication, integrity, confidentiality, and secure lifecycle management. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does O-RAN WG11 Security Specification have?
O-RAN WG11 Security Specification has 34 controls organised across 24 domains. The largest domains are Security Requirements (O-RAN.WG11 Pillar 2 - O-R003) (4 controls), Interface Security (3 controls), Security Protocols (O-RAN.WG11 Pillar 3) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does O-RAN WG11 Security Specification map to?
O-RAN WG11 Security Specification maps to 631 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (26% coverage), ASD Information Security Manual (ISM) (26% coverage), TISAX - Trusted Information Security Assessment Exchange (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with O-RAN WG11 Security Specification compliance?
Start your O-RAN WG11 Security Specification compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about O-RAN WG11 Security Specification requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required