Decision domainsOT defense operating domains
The domain library organizes consequences that can share a system but require different evidence, expertise, owners, and decision criteria. It prevents one synthetic score from concealing materially different questions.
3 linked authority recordsThe maintained operating record for each OT asset's identity, role, location, owner, criticality, communications, dependencies, versions, configuration, support state, exposure, and recovery relevance.
Open the domain record →3 linked authority recordsThe design and maintained evidence for security zones, conduits, trust boundaries, routable paths, industrial DMZs, enforcement points, fail states, and allowed communication supporting physical operations.
Open the domain record →3 linked authority recordsThe operating process that connects a device, product, component, vulnerability, exploit context, exposure path, process consequence, compensating control, vendor guidance, maintenance window, decision, and retained evidence.
Open the domain record →3 linked authority recordsThe connected defensive workflow from approved telemetry and detection content through triage, process-context review, evidence preservation, incident decision, engineering coordination, containment, recovery, and learning.
Open the domain record →3 linked authority recordsThe operating domain governing who can reach which industrial resource, for which approved task, through which path, with which credential, privilege, device, time window, supervision, file flow, emergency process, and retained session evidence.
Open the domain record →3 linked authority recordsThe controls and evidence for protecting constrained industrial endpoints and moving software, files, updates, logs, and operational data across security boundaries.
Open the domain record →4 linked authority recordsThe lifecycle evidence connecting industrial product design, components, firmware, provenance, secure development, vulnerabilities, updates, support, suppliers, integrators, customers, and end-of-life responsibilities.
Open the domain record →3 linked authority recordsThe integration of cybersecurity with physical mission, safety, reliability, design, spares, configuration baselines, backups, manual capability, tested restoration, and recovery decision authority.
Open the domain record →4 linked authority recordsThe system for identifying applicable authorities and commitments, assigning accountable roles, translating requirements into controls, collecting evidence, testing effectiveness, managing exceptions, reporting risk, and preserving change history.
Open the domain record →3 linked authority recordsThe decision boundary connecting cyber defense with process safety, functional safety, reliability, operations, maintenance, engineering change, and physical consequence.
Open the domain record →