Framework overlap

Does 3GPP 5G Security Architecture (TS 33.501) cover DoD Zero Trust Reference Architecture?

You hold 3GPP 5G Security Architecture (TS 33.501) and have been told to do DoD Zero Trust Reference Architecture. Here is how much overlaps, control by control.

16% of DoD Zero Trust Reference Architecture you already have

3GPP 5G Security Architecture (TS 33.501) already covers about 16% of DoD Zero Trust Reference Architecture, leaving 38 of 45 controls as genuinely new work.

Already covered 0 Likely covered 7 New work 38

No control in 3GPP 5G Security Architecture (TS 33.501) maps directly to one in DoD Zero Trust Reference Architecture. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in 3GPP 5G Security Architecture (TS 33.501) reaches these. This is the list to scope.

DODZT-1.2
Conditional User Access
DODZT-1.5
Identity Federation and User Credentialing
DODZT-1.6
Behavioral, Contextual ID, and Biometrics
DODZT-1.8
Continuous Authentication
DODZT-1.9
Integrated ICAM Platform
DODZT-2.1
Device Inventory
DODZT-2.2
Device Detection and Compliance
DODZT-2.3
Device Authorization with Real-Time Inspection
DODZT-2.4
Remote Access
DODZT-2.5
Partially and Fully Automated Asset, Vulnerability and Patch Management
DODZT-2.6
Unified Endpoint Management and Mobile Device Management
DODZT-2.7
Endpoint and Extended Detection and Response
DODZT-3.1
Application Inventory
DODZT-3.2
Secure Software Development and Integration
DODZT-3.3
Software Risk Management
DODZT-3.4
Resource Authorization and Integration
DODZT-3.5
Continuous Monitoring and Ongoing Authorizations
DODZT-4.1
Data Catalog Risk Alignment
DODZT-4.2
DoD Enterprise Data Governance
DODZT-4.3
Data Labeling and Tagging
DODZT-4.4
Data Monitoring and Sensing
DODZT-4.5
Data Encryption and Rights Management
DODZT-4.6
Data Loss Prevention
DODZT-4.7
Data Access Control
DODZT-5.2
Software Defined Networking
DODZT-6.1
Policy Decision Point and Policy Orchestration
DODZT-6.2
Critical Process Automation
DODZT-6.3
Machine Learning
DODZT-6.4
Artificial Intelligence
DODZT-6.5
Security Orchestration, Automation and Response
DODZT-6.6
API Standardization
DODZT-6.7
Security Operations Center and Incident Response
DODZT-7.1
Log All Traffic
DODZT-7.2
Security Information and Event Management
DODZT-7.3
Common Security and Risk Analytics
DODZT-7.4
User and Entity Behavior Analytics
DODZT-7.5
Threat Intelligence Integration
DODZT-7.6
Automated Dynamic Policies
Show the 7 you already have
DODZT-1.1
User Inventory
DODZT-1.3
Multi-Factor Authentication
DODZT-1.4
Privileged Access Management
DODZT-1.7
Least Privileged Access
DODZT-5.1
Data Flow Mapping
DODZT-5.3
Macro Segmentation
DODZT-5.4
Micro Segmentation

How this is calculated

Already covered means a mapping runs from a control in 3GPP 5G Security Architecture (TS 33.501) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition