Skip to content

Explore the ORSM Model

ORSM provides an operational assurance lens for evaluating whether security architecture remains proportionate, sustainable, recoverable and resilient throughout its lifecycle.

At the centre of the model is a simple governing question:

Does this control improve security outcomes without creating disproportionate operational risk?

The model combines principles, assurance tests, architectural decision criteria and seven operational assessment domains.

Start with the Principles

The Foundational Principles establish the philosophy behind ORSM.

They recognise that effective security architecture must remain proportionate, understandable, recoverable and sustainable — not simply comprehensive.

Explore the Foundational Principles →

Understand the Assurance Model

ORSM extends conventional assurance by examining how controls behave after implementation.

The Assurance Model evaluates:

  • security effectiveness;
  • operational cost;
  • operational survivability;
  • sustainability; and
  • human compatibility.

Explore the Assurance Model →

Architecture Design Principles

ORSM provides practical architectural principles covering:

  • protection intent;
  • complexity;
  • survivability;
  • proportionality; and
  • dependency resilience.

Explore the Architecture Design Principles →

Seven Operational Assessment Domains

ORSM evaluates architectural quality across seven connected domains:

  1. Protection Intent
  2. Complexity Management
  3. Operational Sustainability
  4. Operational Resilience
  5. Recovery Engineering
  6. Human Factors
  7. Dependency Resilience

No domain should be considered in isolation.

Explore the Seven Domains →

The ORSM Perspective

Traditional assurance commonly asks:

Are the required controls implemented?

ORSM adds:

What operational architecture has resulted from implementing them?

That distinction is central to the model.