Foundational Principles¶
ORSM introduces eight Foundational Principles that extend conventional security thinking by recognising operational resilience, architectural quality and sustainability as essential characteristics of effective security architecture.
FP-01 --- Security Must Be Proportionate¶
Control strength should reflect business criticality, threat exposure and asset value --- not maximum assurance applied indiscriminately. The objective is the most appropriate controls, not the greatest number.
FP-02 --- Complexity Is a Measurable Risk¶
Every additional integration, dependency and process introduces new failure modes. Complexity should be treated as a finite organisational resource --- measured, justified, governed and periodically reduced.
FP-03 --- Availability Is a Security Outcome¶
Architectures that prevent legitimate users, administrators or responders from accessing critical services during failure have not fulfilled their purpose. Protection that cannot be sustained during disruption provides limited assurance.
FP-04 --- Recoverability Takes Precedence Over Theoretical Perfection¶
An architecture that can be restored quickly following failure provides greater resilience than one that is theoretically comprehensive but operationally unrecoverable. Recovery must be a primary design objective.
FP-05 --- People Are Part of the Architecture¶
Every control ultimately relies upon people. Controls that ignore realistic human behaviour generate workarounds, exceptions and shadow IT. Usability and operational workload are architectural design considerations.
FP-06 --- Every Control Must Justify Its Operational Cost¶
Controls consume engineering effort, administrative capacity and financial investment throughout their operational life. Where ongoing cost outweighs risk-reduction contribution, controls should be redesigned, consolidated or retired.
FP-07 --- Simplicity Improves Resilience¶
Simpler architectures are easier to understand, secure, recover and evolve. Simplification is an active security activity, not merely an optimisation exercise.
FP-08 --- Security Must Remain Sustainable¶
Architectures that exceed the organisation's capacity to operate, maintain and evolve will gradually lose effectiveness regardless of their initial design quality.
Security architecture should be evaluated not only by the strength of its controls, but by its ability to remain proportionate, understandable, recoverable, sustainable and operationally effective throughout its lifecycle.