Skip to content

Disclaimer

The Operational Resilience Security Model (ORSM) is an independent architectural assurance and decision-support framework.

It is intended to support structured consideration of security architecture, operational resilience, complexity, recoverability, sustainability, human factors and dependency risk.

No Guarantee of Security

Use of ORSM does not guarantee that an organisation, architecture, system, product or service is secure, compliant, resilient or free from operational risk.

Security outcomes depend upon many factors including architecture, implementation quality, threat environment, organisational capability, operational processes, people, technology dependencies and ongoing governance.

ORSM should therefore be used as one source of architectural assurance rather than as a substitute for appropriate security engineering, testing, threat modelling or risk management.

Professional Judgement

ORSM assessments require professional judgement and appropriate supporting evidence.

Scores, maturity levels, metrics, patterns, anti-patterns and assessment outcomes should not be treated as definitive statements of security or resilience when considered in isolation.

Assessment conclusions should be interpreted within the context of:

  • business criticality;
  • credible threat scenarios;
  • architecture and dependency structure;
  • operational capability;
  • recovery requirements;
  • regulatory obligations; and
  • available evidence.

No Certification or Accreditation

Unless explicitly stated otherwise, an ORSM assessment does not constitute formal certification, accreditation or regulatory approval.

Use of the framework does not imply that a system or organisation has been certified, approved or endorsed by the author of ORSM.

ORSM does not constitute legal, regulatory, financial, compliance or other professional advice.

Organisations remain responsible for identifying and meeting the laws, regulations, contractual obligations, policies, standards and assurance requirements applicable to their environment.

Third-Party Frameworks and Organisations

ORSM references established frameworks, standards and organisations for comparison, integration and explanatory purposes.

References to NIST, NCSC, ISO, SABSA, Zero Trust approaches, vendors, products or other organisations do not imply affiliation, sponsorship, approval or endorsement unless explicitly stated.

Public Draft Material

Where ORSM is identified as a Public Draft, the framework remains subject to refinement.

Users should identify the version applied to an assessment and consider whether later revisions materially affect interpretation.

Limitation of Responsibility

Responsibility for architectural, security, operational and risk decisions remains with the organisation or individual applying the framework.

ORSM provides a structured method for asking better assurance questions. It does not remove the need for accountable decision-making.