Skip to content

Apply ORSM

ORSM is designed to support practical architectural assessment, not simply describe principles.

The assessment process examines whether security controls continue to provide meaningful protection without creating disproportionate operational risk.

When to Use an ORSM Assessment

ORSM may be applied during:

  • enterprise architecture review;
  • design authority review;
  • significant technology change;
  • security control lifecycle review;
  • procurement decisions;
  • operational resilience assessment;
  • post-incident review; and
  • architectural simplification or transformation.

Assessment Lifecycle

A typical ORSM assessment follows six stages:

  1. Define Scope
  2. Understand the Architecture
  3. Evaluate the Seven Domains
  4. Assess Operational Risk
  5. Determine Architectural Quality
  6. Recommend Improvement

View the Assessment Methodology →

Evidence-Based Assurance

ORSM assessments should be supported by evidence rather than assertion.

Relevant evidence may include:

  • architecture documentation;
  • threat modelling;
  • dependency analysis;
  • operational metrics;
  • recovery testing;
  • incident analysis;
  • exception data; and
  • observed operational behaviour.

Explore the Evidence Model →

Assessment Questions

Before a significant architectural decision is approved, ORSM asks whether the architecture can demonstrate:

  • purpose;
  • proportionality;
  • manageable complexity;
  • resilience;
  • recoverability;
  • sustainability; and
  • acceptable human impact.

View the ORSM Assurance Questions →

Scoring and Architectural Judgement

ORSM can use scoring to support consistency and trend analysis.

However, a score is an indicator, not the assurance outcome.

A high aggregate score should never conceal a material weakness in an individual domain.

Explore ORSM Scoring →

Assessment Outcomes

ORSM assessment may lead to four broad directions:

Retain — the capability remains justified and operationally proportionate.

Improve — the capability remains justified but requires optimisation.

Redesign — the protection objective remains valid but the architecture introduces unacceptable operational risk.

Retire — the control no longer provides sufficient value to justify its operational cost.

See ORSM in Practice

The In Practice section demonstrates how these questions can be applied to fictionalised, technology-neutral architectural scenarios.

Explore ORSM in Practice →