Reference Control Architecture

Risk → Control → Evidence

A reference model for connecting business risk to control layers, telemetry, operations, and evidence.

Security specialists using a working document to review evidence
ICS / OPERATIONAL EVIDENCEEvaluate how each technology component reduces risk and supports real operating decisions.
Security specialists using a working document to review evidence
ICS / OPERATIONAL CONTEXTEvaluate how each technology component reduces risk and supports real operating decisions.
Security specialists using a working document to review evidence
ICS / OPERATIONAL CONTEXT

Reference Control Architecture

Evaluate how each technology component reduces risk and supports real operating decisions.

RiskDescribe the scenario, affected asset, impact, owner, and business dependency.
ControlMap prevention, detection, response, and recovery into the existing architecture.
TelemetryDefine source, quality, retention, access, and operational use.
CONTROL AND EVIDENCE

What the first scoped conversation should clarify.

Use these areas to confirm fit, dependencies, ownership, and the evidence required for acceptance.

01

Risk

Describe the scenario, affected asset, impact, owner, and business dependency.

02

Control

Map prevention, detection, response, and recovery into the existing architecture.

03

Telemetry

Define source, quality, retention, access, and operational use.

04

Evidence

Specify reports, tests, logs, runbooks, and decisions that must be retained.

Evaluate how each technology component reduces risk and supports real operating decisions.

A reference model for connecting business risk to control layers, telemetry, operations, and evidence.

Discuss this scope