O-RAN WG11 Security Specification
Logging, Monitoring, IR, DoS

O-RAN WG11 Security Specification ORANWG11-7: Logging, Monitoring, Incident Response, and Denial-of-Service Resilience

Operate logging + monitoring + incident response + DoS resilience per O-RAN WG11 Security Log Management Specifications and incident response specifications. Logging must (a) collect security-relevant events from all O-RAN components + interfaces + management functions including authentication events + authorisation decisions + configuration changes + cryptographic operations + administrative actions + xApp / rApp lifecycle events, (b) include required event content per WG11 (timestamp + source + event type + principal + outcome + correlation identifier), (c) protect log integrity + confidentiality + availability via WG11-approved transport + storage + access control, (d) retain logs per operator policy + national regulatory requirements (which vary materially by jurisdiction). Monitoring must (a) implement security monitoring across O-RAN architecture with correlation across components and interfaces, (b) baseline normal O-RAN traffic patterns + RIC decision distributions + management activity + and detect anomalies indicating attack or misconfiguration, (c) integrate with telecom SOC capability with O-RAN-aware analyst skills. Incident response must (a) maintain O-RAN-aware IR plan covering O-RAN-specific scenarios (rogue xApp + interface compromise + RIC compromise + Open Fronthaul tap + supply chain compromise + management plane compromise), (b) coordinate with vendors + operator security operations + national regulator where required, (c) maintain forensic readiness for O-RAN components + interfaces + RIC state + xApp / rApp execution evidence. DoS resilience must (a) implement DoS protection at interfaces and components including rate limiting + congestion control + selective admission control, (b) test resilience under DoS simulation scenarios, (c) maintain operational continuity procedures for DoS events including degraded-mode operation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 34 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

NIST SP 800-53 Rev 5 · 3 controls

  • CAT-D3-2 Detective controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • 62351-14 Cyber security event logging

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO-25012-4.11 Traceability

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring

ISO/IEC 27043:2015 · 1 control

  • ISO27043-24 Logging and monitoring

ISO/SAE 21434 · 1 control

  • ISO21434-24 Logging and monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

South Korea ISMS-P · 1 control

  • ISMSP-SYS-03 Security Monitoring and Log Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.