International (3GPP)

3GPP 5G Security Architecture (TS 33.501)

43 controls. 70 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

43 controls 70 frameworks share controls with it International (3GPP) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

3GPP TS 33.501 5G Security Evidence & Implementation Kit

43 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
33.501-10Security for Interworking with EPS1
33.501-11Security Aspects of IMS1
33.501-13.1Service-Based Architecture Security (TLS)1
33.501-13.2Network Function Service Authorization (OAuth 2.0)1
33.501-13.4SEPP and Inter-PLMN Security (N32)2
33.501-14Network Slicing Security1
33.501-15Steering of Roaming Security1
33.501-16Security for User Plane Integrity Protection2
33.501-17Privacy and Pseudonymization1
33.501-4.2Security Domains and Trust Model2
33.501-5.1Subscription Permanent Identifier Protection1
33.501-6.1Primary Authentication (5G AKA / EAP-AKA')2
33.501-6.2Key Hierarchy2
33.501-6.4NAS Security2
33.501-6.5AS Security (RRC and User Plane)2
33.501-6.7Security Mode Command Procedures1
33.501-8Security Aspects of UDM/UDR2
33.501-9Security for Non-3GPP Access1
33.501-Annex-DCryptographic Algorithms2
33.501-OAMManagement Plane Security1
TS33.501-13.1NF Registration and Discovery Security33
TS33.501-13.2NF Service Authorization47
TS33.501-13.3N32 Interconnect Security1
TS33.501-13.4OAuth 2.0 Authorization Framework33
TS33.501-14.1Security for Network Slicing1
TS33.501-14.2Security for Edge Computing1
TS33.501-14.3Security for URLLC Services1
TS33.501-14.4Security for IAB1
TS33.501-4.15G Security Architecture Overview2
TS33.501-4.2Security Feature Groups1
TS33.501-4.3Security Domains and Stratum1
TS33.501-4.4Network Functions in the Security Architecture1
TS33.501-6.1Authentication Framework35
TS33.501-6.2Key Hierarchy and Derivation2
TS33.501-6.3EAP-AKA' Authentication2
TS33.501-6.4NAS Security2
TS33.501-6.5AS Security and PDCP Protection2
TS33.501-6.6AS Security39
TS33.501-6.7Security Key Hierarchy2
TS33.501-6.8Security in Handover1
TS33.501-7.1Untrusted Non-3GPP Access Security1
TS33.501-7.2Security Visibility and Configurability1
TS33.501-7.3Wireline Access Security1

Tell me when 3GPP 5G Security Architecture (TS 33.501) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Role definitions
  • Privileged access management records
  • Separation of duty matrices
  • Periodic privilege reviews
  • Privileged account list
  • Access review records for change tools
  • Access control matrices
  • KMS configuration
  • Encryption coverage report
  • Key rotation records

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for 3GPP 5G Security Architecture (TS 33.501), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition