Secure the O-Cloud platform + containers + secure configuration + patching per O-RAN WG11 Security Requirements + O-Cloud security profile. O-Cloud security must (a) implement secure cloud platform per CNCF + Kubernetes hardening + supply chain controls + image scanning + runtime detection, (b) protect O-Cloud management plane (O2 interface) + workload orchestration + tenant isolation, (c) enforce platform integrity via measured boot + attestation + verified images where supported, (d) operate platform monitoring + drift detection + automatic remediation. Container security must (a) use minimal base images + scan images for vulnerabilities + sign images + verify signatures at deployment, (b) enforce pod security standards + network policies + service mesh authentication + secrets management, (c) operate runtime security (Falco + similar) + monitor for container escape + privilege escalation. Secure configuration baselines must (a) define hardened configuration baselines per O-RAN component (O-DU + O-CU + O-RU + Near-RT RIC + Non-RT RIC + SMO + O-Cloud platform), (b) align with WG11 hardening guidance + 3GPP SECAM/SCAS profiles where applicable + CIS Benchmarks + vendor hardening guidance, (c) enforce baselines via continuous compliance scanning + drift alerting + automated remediation. Patching must (a) consume vulnerability advisories from O-RAN security focus groups + vendor advisories + CISA KEV + sector ISAC, (b) test patches in pre-production environments matching production topology + safety-critical timing constraints, (c) deploy patches per risk-based prioritisation + with documented compensating controls for unpatched systems + with telecom-specific change windows + service continuity considerations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.