What is ORSM?¶
The Operational Resilience Security Model (ORSM) is an architectural assurance framework concerned with the operational quality of security architecture throughout its lifecycle.
Traditional assurance commonly establishes whether appropriate controls exist and whether they have been implemented correctly. ORSM asks a further question: what happens to the organisation once those controls are operating as part of a complex enterprise architecture?
ORSM examines whether controls remain:
- proportionate to the business risk;
- understandable and supportable;
- operationally sustainable;
- resilient when dependencies fail;
- recoverable under realistic conditions; and
- compatible with the people and processes that must operate them.
Purpose¶
ORSM is intended to help security architects, design authorities, risk functions and operational teams identify situations where individually reasonable security decisions combine to create fragile, expensive or difficult-to-recover architectures.
It is designed for use during:
- enterprise architecture reviews;
- design authority assurance;
- major change programmes;
- procurement and technology decisions;
- control lifecycle reviews; and
- post-incident review.
A Note on Intent¶
ORSM does not challenge the legitimacy of established security frameworks, standards or security controls.
These provide essential structures for managing cyber risk, defining security outcomes and establishing appropriate protection.
ORSM focuses instead on implementation and operational consequence.
Security controls that are individually justified and correctly selected may, when implemented or combined within complex environments, create unintended operational effects.
These may include:
- increased architectural complexity;
- concentrated dependencies;
- administrative burden;
- engineering workload;
- recovery constraints;
- operational friction; and
- sustained demands upon technical and operational teams.
These effects do not necessarily represent a failure of the security control itself.
They may instead indicate a challenge in:
- architectural integration;
- proportionality;
- implementation;
- operational design;
- dependency management; or
- lifecycle management.
ORSM therefore asks whether the resulting security architecture remains effective, understandable, supportable and recoverable within its intended risk and operational context.
The control may be right. The architecture around it may not be.
ORSM is therefore control-neutral.
It does not begin from the assumption that there are too many controls, that strong security is undesirable, or that complexity should always be removed.
Strong controls and complex architectures may be entirely justified by threat, consequence, regulation, safety, mission or business need.
ORSM asks whether that complexity is understood, intentional, proportionate and sustainable.
The governing question¶
Does this control improve security outcomes without creating disproportionate operational risk?
Where this cannot be demonstrated through evidence, measurement or operational experience, the control should be reviewed, improved, redesigned, simplified or retired.
What ORSM is not¶
ORSM is not a replacement for security governance, risk management, compliance frameworks or established security architecture methods.
It is an operational assurance layer that complements them by evaluating whether the architecture they produce remains effective in the real world.