Operate logging + monitoring + incident response + DoS resilience per O-RAN WG11 Security Log Management Specifications and incident response specifications. Logging must (a) collect security-relevant events from all O-RAN components + interfaces + management functions including authentication events + authorisation decisions + configuration changes + cryptographic operations + administrative actions + xApp / rApp lifecycle events, (b) include required event content per WG11 (timestamp + source + event type + principal + outcome + correlation identifier), (c) protect log integrity + confidentiality + availability via WG11-approved transport + storage + access control, (d) retain logs per operator policy + national regulatory requirements (which vary materially by jurisdiction). Monitoring must (a) implement security monitoring across O-RAN architecture with correlation across components and interfaces, (b) baseline normal O-RAN traffic patterns + RIC decision distributions + management activity + and detect anomalies indicating attack or misconfiguration, (c) integrate with telecom SOC capability with O-RAN-aware analyst skills. Incident response must (a) maintain O-RAN-aware IR plan covering O-RAN-specific scenarios (rogue xApp + interface compromise + RIC compromise + Open Fronthaul tap + supply chain compromise + management plane compromise), (b) coordinate with vendors + operator security operations + national regulator where required, (c) maintain forensic readiness for O-RAN components + interfaces + RIC state + xApp / rApp execution evidence. DoS resilience must (a) implement DoS protection at interfaces and components including rate limiting + congestion control + selective admission control, (b) test resilience under DoS simulation scenarios, (c) maintain operational continuity procedures for DoS events including degraded-mode operation.
This control maps to 34 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.