Skip to content

Home

Operational Resilience Security Model
Security architecture that survives contact with reality.
ORSM is an architectural assurance framework for evaluating whether security controls continue to provide effective protection without creating disproportionate operational risk.
The problem

Security can become a source of operational risk

Modern security programmes have become increasingly capable, interconnected and heavily governed.

Yet individually justified controls can combine to produce architectures that are difficult to operate, expensive to maintain, dependent upon a small number of strategic platforms and challenging to recover when those platforms fail.

ORSM calls this the Operational Security Paradox.

The governing question

Does this control improve security outcomes without creating disproportionate operational risk?

ORSM does not ask organisations to weaken security.

It asks whether security remains proportionate, sustainable, recoverable and operationally resilient once controls become part of a living enterprise architecture.

07 domains

Operational Assessment Domains

ORSM evaluates architectural quality across seven dimensions.

01
Protection Intent
Does every capability exist for a clear and continuing business purpose?
02
Complexity Management
Is architectural complexity understood, justified and actively controlled?
03
Operational Sustainability
Can the organisation realistically operate and maintain the architecture?
04
Operational Resilience
Can critical services continue when security capabilities fail?
05
Recovery Engineering
Can security capability be restored rapidly, repeatably and predictably?
06
Human Factors
Do controls align with realistic human and operational behaviour?
07
Dependency Resilience
Does concentration on platforms, vendors or services create systemic risk?
The model

Assurance beyond control presence

Traditional security assurance commonly asks whether expected controls have been implemented.

ORSM asks whether those controls continue to deliver meaningful protection without degrading the organisation's ability to operate and recover.

The framework combines:

  • eight Foundational Principles;
  • five Assurance Tests;
  • seven Operational Assessment Domains;
  • evidence-based assessment;
  • architectural decision outcomes;
  • measurable operational indicators; and
  • a five-level capability maturity model.
Relationship to existing frameworks

Complement, not replacement

ORSM is designed to sit alongside established approaches including:

NIST CSF 2.0 · ISO/IEC 27001 · NCSC Secure by Design · SABSA · Zero Trust

These approaches establish important security capabilities, governance and design principles.

ORSM evaluates the resulting architecture through an additional operational lens:

Is it sustainable? Is it recoverable? Is it proportionate? Can the organisation still operate when it fails?

Security is not measured by the controls we deploy. It is measured by the architecture we can continue to operate.

Operational security is proven through survivability.