Skip to content

O-RAN WG11 Evidence

Use the O-RAN WG11 report to review supporting runtime evidence for your Open RAN security assessment. It is not an O-RAN certification or a complete test of the specification.

The report requires the telecom Console mode and relevant telecom sensor coverage.

Open the report

  1. Open Reports > Compliance Reports > Control Evidence.
  2. Select O-RAN WG11.
  3. Choose a reporting period and confirm the scope.
  4. Open a control to read its evidence and required follow-up.

Evidence areas

Telovix groups the available evidence into nine checks:

AreaWhat to review
O1 Management Interface SecurityObserved management activity and related findings.
O2 Infrastructure Interface SecurityInfrastructure API activity and resource-management findings.
E2 Interface Peer VerificationObserved E2 peers and related process identity.
O-Cloud Time SynchronizationAvailable timing-service evidence and gaps.
Management Plane Access ControlManagement processes, access activity, and findings.
CU/DU Boundary and F1 InterfaceObserved RAN component and interface context.
xApp/rApp API SecurityApplication activity and related API findings.
KPM Measurement Data IntegrityAvailable measurement-related evidence and findings.
F1/E1 Interface Boundary EnforcementRelevant boundary observations and protection evidence.

These are Telovix evidence groupings. Their presence does not mean the complete corresponding requirement has been assessed.

Interpret a result

Use the same status meanings as Compliance Reports:

  • Evidence check met means the Telovix check has supporting evidence.
  • Partial evidence requires further assessment.
  • Needs review identifies evidence that warrants investigation.
  • Not assessed means the required evidence is missing or cannot establish a result.

No detected violation is not proof that an interface is authorized, encrypted, or correctly configured. A running time-synchronization process alone does not prove timing accuracy.

The O-RAN WG11 report with evidence checks and supporting observations.
Open each check to review its evidence and assessment limits. Click to enlarge

Follow the evidence

  • Open Telco > Network > O-RAN for observed O-RAN relationships and protocol activity.
  • Open Telco > Network > RAN for RAN interface and signaling evidence.
  • Use API Security to inspect captured request and response content.
  • Use Investigate for the corresponding recorded events and process context.

Check observation times and the selected network before comparing these views. Current topology and historical events describe different periods.

Prepare a review bundle

Open Reports > Compliance Reports > Evidence Bundles to generate and download the appropriate report snapshot. Review the included framework and evidence before sharing it.

Combine Telovix evidence with your configuration records, access reviews, organizational procedures, and test results. Ask the assessor which format and supporting material they require; a downloaded bundle is not automatically a certification submission.

Validate a detection

A controlled threat exercise can confirm that a selected detection produces evidence in your deployment. It does not validate an entire O-RAN requirement.

Agree on the test scope and maintenance window, record the expected result, run the exercise, and attach the resulting alert or investigation to your review. See Threat Exercises.

Released under the Telovix Commercial License.