ITU-T X.805 - Security Architecture for End-to-End Communications
Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
X.805 Scope + Architecture
ITU-T Recommendation X.805 (10/2003) Security architecture for systems providing end-to-end communications is a foundational network security architecture standard published by the International Telecommunication Union Telecommunication Standardization Sector (ITU-T) in October 2003. The Recommendation defines a comprehensive systematic approach to network security covering both telecommunication networks (Public Switched Telephone Network + Public Land Mobile Network + Public Data Network) and converged networks (Next Generation Networks + IP-based networks). (1) Architecture Overview: X.805 establishes a 3-dimensional security architecture providing 72 distinct security perspectives via the orthogonal combination of (a) 3 Security Layers (Infrastructure + Services + Applications) - which together describe the hierarchical decomposition of network capability; (b) 3 Security Planes (Mana
- X.805 architecture adopted + documented + records + per network/service
- 72-cell matrix + assessment + records + per Layer x Plane x Dimension intersection
- 5 threats + risk assessment + countermeasures + records + per threat
- X.800-Series heritage + compatibility + records + per Recommendation
- Cross-framework mapping + ISO 27001 + NIST CSF + ISO 27033 + records + per crosswalk
- X.805 architecture not adopted (network security ad hoc)
- 72-cell matrix never assessed (security gaps unknown)
- Threats and Dimensions not systematically linked
- X.800-Series heritage ignored (legacy gaps)
- Cross-framework mapping absent (audit gaps)
X.805 Security Dimension 1 - Access Control
Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + information flows + services + and applications. In addition Role-Based Access Control (RBAC) provides different access levels to guarantee that individuals and devices can only gain access to and perform operations on network elements + stored information + and information flows for which they are authorised. (1) Access Control Sub-Categories per X.805 and related frameworks: (a) Discretionary Access Control (DAC) - resource owner discretion + Access Control Lists (ACLs); (b) Mandatory Access Control (MAC) - system-enforced labels + classification levels + Bell-LaPadula + Biba; (c) Role-Based Access Control (RBAC) - per ISO/IEC 10181-3
- RBAC/ABAC + per Layer x Plane + records + per resource + per identity
- PAM + JIT + JEA + records + per privileged role + per session
- Zero Trust + continuous verification + records + per session + per resource
- Network Access Control + 802.1X + ZTNA + records + per network segment
- Threats countermeasure mapping + per threat + records + per cell
- RBAC implemented only at app layer (Infrastructure ungoverned)
- Privileged Access standing rather than JIT
- Zero Trust not adopted (perimeter still trusted)
- Network Access Control absent at edge
- Threats not mapped to Access Control countermeasures
X.805 Security Dimension 2 - Authentication
Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g. person + device + service or application) and provides assurance that an entity is not attempting a masquerade or unauthorized replay of a previous communication. (1) Authentication Categories per X.805 + X.800 + X.811 framework: (a) Peer Entity Authentication - mutual + unilateral + verifying communicating parties; (b) Data Origin Authentication - verifying source of received data; (c) Authentication of the User + Device + Service + Application + Process. (2) Authentication Factors per NIST SP 800-63: (a) Something you know - password + PIN + passphrase; (b) Something you have - smart card + token + hardware key + mobile device; (c) Something you are - biometric (fingerprint + face + iris + voice + behavioural); (d)
- MFA implementation + 2+ factors + records + per user + per access
- PKI/X.509 + FIDO2/WebAuthn + SAML/OAuth + records + per system
- Peer entity + data origin authentication + records + per connection
- Authentication per Layer (Infra/Svc/App) + Plane (Mgmt/Ctrl/User) + records
- Threats (Corruption/Disclosure/Interruption) + countermeasure mapping + records
- MFA limited to user portal (admin + service-to-service single-factor)
- Strong auth absent (passwords + SMS only)
- Data origin authentication absent (data trusted by source IP)
- Layer/Plane auth gaps (Control + User Plane auth weak)
- Threats not mapped to Authentication countermeasures
X.805 Security Dimension 3 - Non-Repudiation
Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g. proof of obligation + intent + or commitment + proof of data origin + proof of ownership + proof of resource use). It ensures the availability of evidence that can be presented to a third party and used to prove that some kind of event or action has taken place. (1) Non-Repudiation Categories per X.805 + X.813: (a) Non-Repudiation of Origin (NRO) - prevents the sender from denying having sent a message; (b) Non-Repudiation of Delivery (NRD) - prevents the recipient from denying having received a message; (c) Non-Repudiation of Submission (NRS) - proves submission to delivery agent; (d) Non-Repudiation of Transport (NRT) - proves m
- Digital signatures + PKI + certificates + records + per transaction
- RFC 3161 TSA + trusted time-stamping + records + per signature
- Tamper-evident logs + WORM + immutable + records + audit-ready
- eIDAS/ESIGN compliance + per jurisdiction + records + per signature class
- Long-term validation + archive-grade preservation + records + per document
- Digital signatures absent (parties can repudiate)
- Time-stamping informal (when challenged not authoritative)
- Audit logs mutable (logs can be denied)
- Legal framework mismatch (signature not accepted in court)
- Long-term validation absent (signature expires + becomes invalid)
X.805 Security Dimension 6 - Data Integrity
Security Dimension 6 Data Integrity per X.805 Clause 6.6: Data Integrity ensures the correctness or accuracy of data. The data is protected against unauthorized modification + deletion + creation + replication and provides an indication of these unauthorized activities. Data Integrity covers both data at rest and data in transit ensuring the data remains accurate + complete + and unaltered except by authorized parties using authorized means. (1) Integrity Categories: (a) Connection-Oriented Integrity - integrity verified per connection + sequence numbers prevent replay + reorder; (b) Connectionless Integrity - integrity per message + each independently verifiable; (c) Selective Field Integrity - per field rather than per message; (d) Recovery vs Detection-Only - some mechanisms detect + others can restore via redundancy. (2) Cryptographic Integrity Mechanisms: (a) Hash Functions (SHA-256
- SHA-256 + HMAC + AEAD + records + per data class + per channel
- FIM + Tripwire/AIDE + baseline + alerting + records + per system
- Signed config + code signing + SBOM + records + per artefact
- Replication + WORM + immutable + records + per asset class
- Supply chain + SLSA + in-toto + Sigstore + records + per build
- Legacy hash (MD5/SHA-1) still in use
- FIM absent or alerts ignored
- Configuration unsigned (silent tampering possible)
- Backups mutable (ransomware can encrypt backups)
- Supply chain integrity not assured (no SBOM + no SLSA)
X.805 Security Dimension 7 - Availability
Security Dimension 7 Availability per X.805 Clause 6.7: Availability ensures that there is no denial of authorized access to network elements + stored information + information flows + services and applications due to events impacting the network. Availability protects against any factor that may interrupt or disrupt the legitimate use of network resources including human-caused threats + natural disasters + system failures + and accidental events. (1) Availability Categories: (a) Service Availability (uptime as percentage); (b) Network Element Availability; (c) Information Availability; (d) Workload Availability (recovery time objective RTO + recovery point objective RPO); (e) Connectivity Availability. (2) Availability Threats: (a) Denial of Service (DoS); (b) Distributed DoS (DDoS) - Volumetric + Protocol + Application Layer; (c) Hardware failures; (d) Software bugs + crashes; (e) Nat
- Service availability + 5-9s + records + per service + per quarter
- Redundancy + HA + load balancing + multi-region + records + per architecture
- DR Plan + BC + RTO/RPO + records + per application + tested annually
- DDoS mitigation + scrubbing + records + per incident + post-mortem
- Chaos engineering + resilience testing + records + per quarter + lessons learned
- Single point of failure unidentified (silent SPOFs)
- Active-passive with manual failover (RTO too long)
- DR Plan untested (theoretical only)
- DDoS protection only at app layer (network L3/4 unprotected)
- Chaos engineering absent (resilience unverified)
X.805 Security Dimension 8 - Privacy
Security Dimension 8 Privacy per X.805 Clause 6.8: Privacy provides protection of information that might be derived from the observation of network activities. Examples include websites visited by users + their geographic location + the IP addresses + DNS names of devices in a service provider network. Privacy is distinct from Data Confidentiality (Dim 4) which protects the data content itself - Privacy protects the metadata + identification + and observation of network activity. (1) Privacy Categories: (a) Anonymity - inability to determine the identity of the user; (b) Pseudonymity - use of an alias decoupling identity from real-world; (c) Unobservability - inability to determine whether activity has occurred; (d) Unlinkability - inability to determine whether two activities are related; (e) Plausible Deniability; (f) Minimal Disclosure. (2) Privacy by Design (PbD) per Ann Cavoukian 7
- Privacy by Design + GDPR Art 25 + records + per system + per phase
- Data minimisation + purpose limitation + records + per data flow + per field
- Anonymisation + K-Anonymity + Differential Privacy + records + per dataset
- Subscriber identifier + 5G SUCI + IMSI concealment + records + per network
- Cross-border + SCCs + BCRs + EU-US DPF + records + per transfer
- Privacy retrofitted (Privacy by Design absent at design phase)
- Data hoarding (minimisation not enforced)
- Anonymisation weak (re-identification possible)
- 5G SUCI not implemented (IMSI exposed)
- Cross-border transfers without lawful basis
X.805 Security Dimensions 4-5 - Confidentiality + Communication Security
Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities. Encryption + Access Control + File Permissions + Communication Path Protection all contribute. (2) Communication Security (Dim 5) ensures that information flows ONLY between the authorized endpoints (the information is not diverted or intercepted while flowing between these endpoints) - protects the information path itself + including against masquerade of endpoints. The two Dimensions together cover all aspects of information secrecy from data-at-rest through communication-in-transit. (1) Encryption Categories: (a) Symmetric Encryption (block + stream) - AES-128/192/256 + ChaCha20 + 3DES (legacy + deprecated for new); (b) Asymmetric Encryption (RSA-2048/307
- Encryption at-rest + full disk + DB TDE + KMS + records + per data store
- Encryption in-transit + TLS 1.3 + IPSec + MACsec + records + per channel
- Encryption in-use + TEE + Confidential Computing + records + per workload
- Key management + HSM FIPS 140-3 + rotation + records + per key lifecycle
- PQC roadmap + crypto-agility + inventory + hybrid + records + per algorithm
- Legacy encryption (TLS 1.0/1.1 + SSL + 3DES + RC4)
- Keys stored in app code or config files (no HSM/KMS)
- Encryption in-use not addressed (cloud workloads vulnerable)
- Key rotation absent (long-lived keys + key sprawl)
- PQC roadmap absent (Q-Day exposure unmanaged)
X.805 Security Layer 1 - Infrastructure
Security Layer 1 Infrastructure per X.805 Clause 7.1: The Infrastructure Security Layer consists of network facilities (transmission facilities and network elements) protected by the security measures. The Infrastructure Security Layer represents the fundamental building blocks of telecommunication networks - the things over which information flows. (1) Infrastructure Layer Components: (a) Transmission Facilities - copper + fibre optic + wireless including microwave + satellite + cellular + Wi-Fi + DOCSIS cable + DSL + Ethernet; (b) Network Elements - routers + switches + load balancers + firewalls + IDS/IPS + WAN accelerators + CDNs + SDN controllers; (c) Aggregation/Distribution - DSLAMs + OLTs + BNG Broadband Network Gateway + 5G UPF + MME + SAE-GW + GGSN/PGW; (d) Access Network - BTS Base Transceiver Station + NodeB/eNodeB/gNodeB + AAA + RNC; (e) Core Network - PSTN + ISDN + IP backb
- Physical security + tier + TIA-942 + records + per datacenter + per site
- Network element hardening + SCAS/NESAS + records + per device + per release
- Link encryption + MACsec/IPSec/OTNsec + records + per link + per path
- Cloud infrastructure + hypervisor/container + records + per host + per cluster
- IoT edge + EN 303 645 + records + per device class + per deployment
- Physical security at HQ but field sites under-protected
- Network elements default config (no SCAS/NESAS hardening)
- Management traffic unencrypted (Layer 2 exposed)
- Cloud infrastructure on shared tenancy without isolation
- IoT devices unhardened (default credentials + no updates)
X.805 Security Layer 2 - Services
Security Layer 2 Services per X.805 Clause 7.2: The Services Security Layer is concerned with security of network services that service providers offer to their customers - encompasses the protection of the basic network connectivity services + supplementary value-added services. (1) Services Layer Components: (a) Basic Connectivity Services - dedicated line + dial-up + DSL + cable broadband + FTTH; Frame Relay + ATM + MPLS; IP VPN + Layer 2 VPN + Layer 3 VPN + SD-WAN; (b) Mobile Services - 2G GSM + 3G UMTS + 4G LTE + 5G NSA/SA + Voice over LTE (VoLTE) + SMS + Mobile data; (c) Voice Services - PSTN + ISDN + SIP Trunking + Hosted PBX + Voice over IP (VoIP) + WebRTC; (d) Quality of Service (QoS) services + tiered service level; (e) Value-Added Services - Toll-Free (800/888) + Calling Card + International Direct Dial + Premium Rate; (f) Messaging Services - SMS + MMS + RCS + IM + Email + Pu
- Service auth + AAA + 5G AKA + records + per service + per subscriber
- IMS/SIP/SRTP + DTLS + records + per service class + per session
- DNSSEC + DoH/DoT/ECH + RPZ + records + per domain + per zone
- VPN + IPSec/WireGuard + SD-WAN/SASE + records + per tenant + per tunnel
- STIR/SHAKEN + signed caller ID + records + per call + per attestation
- AAA only at access (service-internal calls unauthenticated)
- IMS without TLS/IPSec (SIP exposed)
- DNS authoritative unsigned (DNSSEC absent)
- VPN concentrator single + no failover
- Caller ID unsigned (robocall victims)
X.805 Security Layer 3 - Applications
Security Layer 3 Applications per X.805 Clause 7.3: The Applications Security Layer addresses requirements of network-based applications accessed by service provider customers. These applications are enabled by the network services and include both consumer-facing applications and B2B applications running over the service provider network. (1) Application Layer Components: (a) Basic Applications - Email (SMTP + IMAP + POP3 + Exchange) + Web Browsing (HTTP + HTTPS) + File Transfer (FTP + SFTP + FTPS + WebDAV); (b) Directory Services - LDAP + Active Directory + DAP X.500; (c) Voice/Video - VoIP + Video Conferencing (Zoom + Teams + WebEx + Google Meet) + WebRTC; (d) Messaging Apps - IM + WhatsApp + Signal + Telegram + iMessage + Discord + Slack + Teams; (e) E-Commerce - Web stores + Payment processing + Subscription services + Auctions + Marketplaces; (f) Mobile Apps - iOS + Android + Hybri
- Application auth + SSO + OAuth/OIDC + MFA + records + per app + per user
- OWASP Top 10 + API Top 10 + records + per release + per scan
- SPF + DKIM + DMARC + BIMI + records + per domain + per report
- Secure SDLC + DevSecOps + SAST/DAST/SCA + records + per build + per finding
- API Gateway + rate limiting + WAF + records + per API + per request
- Application auth without MFA (account takeover)
- OWASP Top 10 only annual scan (no continuous)
- Email DMARC at p=none (not enforced)
- SDLC without security gates (shift-right pen test only)
- APIs without gateway + rate limiting (DDoS + scraping)
X.805 Security Planes
Security Planes per X.805 Clause 7.4: A Security Plane represents a certain type of network activity protected by Security Dimensions and applied across all 3 Security Layers. X.805 defines 3 Security Planes that represent the 3 types of protected activities on networks: (1) Management Plane per X.805 Clause 7.4.1: addresses Operations Administration Maintenance and Provisioning (OAM and P) functions of network elements + transmission facilities + back office systems (Operations Support Systems OSS + Business Support Systems BSS + and the like) + the data centers that house these systems. Management Plane activities include device configuration + network monitoring + statistics gathering + provisioning + accounting + activation + change management + fault detection + backup/restore. (a) Northbound interfaces - OSS/BSS to NEM Network Element Management Layer + Service Provider tools; (b)
- Plane separation + out-of-band mgmt + records + per site + per device
- CoPP + signalling firewall + SS7/Diameter/SIP/BGP filter + records
- Cross-plane lateral movement prevention + records + per architecture review
- 9-cell Layer x Plane matrix + records + per network + per component
- 72-cell Layer x Plane x Dimension + records + per architecture review
- Management Plane on in-band production network
- CoPP absent (control plane DDoS-able)
- Cross-plane lateral movement possible (no microsegmentation)
- 9-cell matrix never assessed (Plane gaps unknown)
- 72-cell evaluation absent (architecture review superficial)
X.805 Threats + Application
X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions. (1) The 5 X.805 Threat Categories per X.805 Clause 8 + X.800 + ISO/IEC 7498-2 Heritage: (a) DESTRUCTION of information and/or other resources - the targeted resource is permanently destroyed + cannot be recovered (without restoration mechanisms); examples - disk wipe + media destruction + nuke malware + Stuxnet + Shamoon + NotPetya + Olympic Destroyer + Wiper malware; (b) CORRUPTION or modification of information - the resource is altered + falsified + tampered with; examples - data tampering + log alteration + man-in-the-middle modification + BGP route manipulation + DNS cache poisoning + database update without authorization; (c) REMOVAL of information and/or other resources (e.g. theft) -
- 5 X.805 threats + risk assessment + records + per module + per quarter
- Threat-Dimension matrix + countermeasures + records + per architecture
- 72-cell threat assessment + records + per network + per review cycle
- Threat model + STRIDE/MITRE + records + per release + per major change
- Threat intelligence + STIX 2.1 + TAXII 2.1 + records + per quarter
- Threats considered annual exercise only (no continuous)
- Countermeasure matrix not used (gaps unknown)
- 72-cell assessment never done (architecture review superficial)
- Threat models per release absent (changes increase attack surface)
- Threat intel siloed (not fed to detection + response)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.