Skip to content

About ORSM

The Operational Resilience Security Model (ORSM) is an independent architectural assurance framework developed to help organisations evaluate whether security controls continue to provide effective protection without introducing disproportionate operational risk.

ORSM focuses on the operational characteristics of security architecture, including:

  • proportionality;
  • complexity;
  • sustainability;
  • resilience;
  • recovery;
  • human factors; and
  • dependency resilience.

ORSM complements established security and risk frameworks rather than replacing them.

Current Publication

Version: ORSM 2.1
Status: Public Draft

ORSM is currently being developed as an openly published framework.

The Public Draft designation indicates that the core model is sufficiently mature for review and practical evaluation, while supporting guidance, evidence models, assessment methods and worked examples may continue to evolve.

The ORSM Governing Question

Does this control improve security outcomes without creating disproportionate operational risk?

Author

ORSM was developed by Stefan Garczynski.

About the Author

Stefan Garczynski is a security architect with more than three decades of experience across technology, security architecture and operational environments.

His work has included enterprise security architecture, secure and high-assurance environments, ICS/OT, Critical National Infrastructure and the built environment, alongside broader architecture, transformation and technology programmes.

ORSM developed from a recurring architectural observation: security controls that are individually reasonable can, when combined, create complexity, operational dependency and recovery challenges that are not always visible through conventional control-based assurance.

The framework reflects practical experience of assessing security not simply as a collection of controls, but as an operational system that must remain proportionate, supportable, recoverable and resilient.

Independent Framework

ORSM is independently developed and is not affiliated with, sponsored by or endorsed by NIST, NCSC, ISO, The SABSA Institute or vendors and organisations referenced within the framework.

Framework Philosophy

ORSM is based on a simple premise:

Security is not measured by the controls we deploy. It is measured by the architecture we can continue to operate.

Operational security is proven through survivability.