30% of 3GPP 5G Security Architecture (TS 33.501) you already have
DoD Zero Trust Reference Architecture already covers about 30% of 3GPP 5G Security Architecture (TS 33.501), leaving
30 of 43 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 30
No control in DoD Zero Trust Reference Architecture
maps directly to one in 3GPP 5G Security Architecture (TS 33.501). Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in DoD Zero Trust Reference Architecture reaches these. This is the list to scope.
33.501-10Security for Interworking with EPS
33.501-11Security Aspects of IMS
33.501-13.1Service-Based Architecture Security (TLS)
33.501-15Steering of Roaming Security
33.501-16Security for User Plane Integrity Protection
33.501-17Privacy and Pseudonymization
33.501-4.2Security Domains and Trust Model
33.501-5.1Subscription Permanent Identifier Protection
33.501-6.5AS Security (RRC and User Plane)
33.501-6.7Security Mode Command Procedures
33.501-8Security Aspects of UDM/UDR
33.501-9Security for Non-3GPP Access
33.501-Annex-DCryptographic Algorithms
33.501-OAMManagement Plane Security
TS33.501-13.2NF Service Authorization
TS33.501-4.15G Security Architecture Overview
TS33.501-4.2Security Feature Groups
TS33.501-4.3Security Domains and Stratum
TS33.501-4.4Network Functions in the Security Architecture
TS33.501-6.2Key Hierarchy and Derivation
TS33.501-6.5AS Security and PDCP Protection
TS33.501-6.7Security Key Hierarchy
TS33.501-6.8Security in Handover
TS33.501-7.1Untrusted Non-3GPP Access Security
TS33.501-7.2Security Visibility and Configurability
TS33.501-7.3Wireline Access Security
Show the 13 you already have
33.501-13.2Network Function Service Authorization (OAuth 2.0)
33.501-13.4SEPP and Inter-PLMN Security (N32)
33.501-14Network Slicing Security
33.501-6.1Primary Authentication (5G AKA / EAP-AKA')
TS33.501-13.1NF Registration and Discovery Security
TS33.501-13.3N32 Interconnect Security
TS33.501-13.4OAuth 2.0 Authorization Framework
TS33.501-14.1Security for Network Slicing
TS33.501-14.2Security for Edge Computing
TS33.501-14.3Security for URLLC Services
TS33.501-14.4Security for IAB
TS33.501-6.1Authentication Framework
TS33.501-6.3EAP-AKA' Authentication
How this is calculated
Already covered means a mapping runs from a control in DoD Zero Trust Reference Architecture to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition