Home
Or see how ORSM works In Practice →
Security can become a source of operational risk¶
Modern security programmes have become increasingly capable, interconnected and heavily governed.
Yet individually justified controls can combine to produce architectures that are difficult to operate, expensive to maintain, dependent upon a small number of strategic platforms and challenging to recover when those platforms fail.
ORSM calls this the Operational Security Paradox.
Does this control improve security outcomes without creating disproportionate operational risk?
ORSM does not ask organisations to weaken security.
It asks whether security remains proportionate, sustainable, recoverable and operationally resilient once controls become part of a living enterprise architecture.
Operational Assessment Domains¶
ORSM evaluates architectural quality across seven dimensions.
Assurance beyond control presence¶
Traditional security assurance commonly asks whether expected controls have been implemented.
ORSM asks whether those controls continue to deliver meaningful protection without degrading the organisation's ability to operate and recover.
The framework combines:
- eight Foundational Principles;
- five Assurance Tests;
- seven Operational Assessment Domains;
- evidence-based assessment;
- architectural decision outcomes;
- measurable operational indicators; and
- a five-level capability maturity model.
Complement, not replacement¶
ORSM is designed to sit alongside established approaches including:
NIST CSF 2.0 · ISO/IEC 27001 · NCSC Secure by Design · SABSA · Zero Trust
These approaches establish important security capabilities, governance and design principles.
ORSM evaluates the resulting architecture through an additional operational lens:
Is it sustainable? Is it recoverable? Is it proportionate? Can the organisation still operate when it fails?
Operational security is proven through survivability.