Skip to content

ORSM Assurance Questions

Before a significant security architecture decision is approved, ORSM asks seven questions.

1. Purpose

Why does this control exist? Can its protection objective be clearly demonstrated?

2. Proportionality

Is the control proportionate to the business risk, or does it introduce unnecessary complexity for marginal gain?

3. Complexity

What complexity does this introduce? Can the same outcome be achieved more simply?

4. Resilience

If this fails tomorrow, can the organisation continue operating?

5. Recoverability

Can we recover this capability quickly and predictably?

6. Sustainability

Can we realistically operate this for the next five years?

7. Human Impact

Will people actually use this as intended, or will they work around it?


An ORSM assessment should answer these questions with evidence rather than assertion.