Explore the ORSM Model¶
ORSM provides an operational assurance lens for evaluating whether security architecture remains proportionate, sustainable, recoverable and resilient throughout its lifecycle.
At the centre of the model is a simple governing question:
Does this control improve security outcomes without creating disproportionate operational risk?
The model combines principles, assurance tests, architectural decision criteria and seven operational assessment domains.
Start with the Principles¶
The Foundational Principles establish the philosophy behind ORSM.
They recognise that effective security architecture must remain proportionate, understandable, recoverable and sustainable — not simply comprehensive.
Explore the Foundational Principles →
Understand the Assurance Model¶
ORSM extends conventional assurance by examining how controls behave after implementation.
The Assurance Model evaluates:
- security effectiveness;
- operational cost;
- operational survivability;
- sustainability; and
- human compatibility.
Architecture Design Principles¶
ORSM provides practical architectural principles covering:
- protection intent;
- complexity;
- survivability;
- proportionality; and
- dependency resilience.
Explore the Architecture Design Principles →
Seven Operational Assessment Domains¶
ORSM evaluates architectural quality across seven connected domains:
- Protection Intent
- Complexity Management
- Operational Sustainability
- Operational Resilience
- Recovery Engineering
- Human Factors
- Dependency Resilience
No domain should be considered in isolation.
The ORSM Perspective¶
Traditional assurance commonly asks:
Are the required controls implemented?
ORSM adds:
What operational architecture has resulted from implementing them?
That distinction is central to the model.