Secure the RAN Intelligent Controller (RIC) + xApp / rApp lifecycle + AI/ML components per O-RAN WG11 Security Requirements. RIC architecture security must (a) protect Near-RT RIC (E2 control loops + xApp hosting) and Non-RT RIC (rApp hosting + policy management) with isolation between RIC functions + tenant separation in multi-vendor deployments, (b) authenticate and authorise all RIC API access + xApp/rApp management API access + with audit logging. xApp / rApp lifecycle security must (a) onboard xApps and rApps via vetted source + signed packaging + image scanning + vulnerability assessment, (b) sandbox xApps and rApps using container security best practices + namespace isolation + resource limits + capability restrictions, (c) enforce least privilege for xApp / rApp access to RIC functions + E2 / A1 interfaces + RAN state, (d) operate runtime monitoring for xApp / rApp behaviour + anomalous resource use + policy violations, (e) maintain rApp / xApp deprovisioning + secret rotation + audit retention. AI/ML security must (a) protect training data + models + inference pipelines against poisoning + extraction + evasion + membership inference attacks, (b) ensure ML model provenance + versioning + signing + integrity verification at deployment, (c) monitor ML inference for drift + adversarial inputs + anomalous decision distributions, (d) align with O-RAN WG11 AI/ML security guidance and emerging NIST AI Risk Management Framework + EU AI Act high-risk system requirements for telecom decision systems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.