Operational control you can demonstrate.

OSAF moves from the outcome the business needs to the capabilities, dependencies and evidence that determine whether a critical service remains governable.

Assessment-first · Service-level · Evidence-led

What operational sovereignty means.

The definition focuses on what the organization can do under a consequential loss of cooperation—not on provider nationality or data location alone.

“The demonstrable ability to continue, control, recover, change or exit a critical digital service when an external dependency cannot or will not cooperate.”

Four business outcomes.

The desired outcome establishes the consequence before the assessment prescribes a control or target posture.

01 / Outcome

Privacy & Compliance

02 / Outcome

Continuity & Resilience

03 / Outcome

Supplier Choice & Competition

04 / Outcome

Strategic Flexibility

Six operational capabilities.

Capabilities translate an outcome into consequential actions the organization must be able to exercise.

01

Decide & Govern

Set direction, approve exceptions and retain accountable decision rights.

02

Control & Operate

Administer the service, identities, configurations and operating controls.

03

Recover & Restore

Recover the service and its information within the required business timeframe.

04

Substitute & Exit

Move data, replace dependencies and execute a viable exit path.

05

Maintain & Adapt

Change, patch and evolve the service as requirements and threats change.

06

Assure & Verify

Observe, test and independently evaluate whether required controls work.

Ten control domains.

Each capability can cross several domains. Hover or focus a domain to see the dependency questions it opens.

01

Infrastructure & Hosting

Physical, virtual and facility operating paths.

02

Cloud Platform & Control Plane

Administrative APIs, tenancy and provider control.

03

Data & Cryptography

Access, portability, keys and recoverability.

04

Identity & Privileged Access

Authentication, authorization and break-glass control.

05

Applications & Middleware

Runtime, interfaces, licensing and portability.

06

AI Models / Compute / Deployment

Model access, inference, safeguards and substitutes.

07

Security / Monitoring / Response

Detection, containment and recovery evidence.

08

DevOps & Software Supply Chain

Source, build, artefact and deployment trust.

09

Network & Connectivity

Routes, diversity and out-of-band access.

10

Governance / Legal / Commercial

Rights, obligations, jurisdiction and accountability.

From assertion to assurance.

A control conclusion becomes stronger when it is implemented, observed and exercised against the scenario that matters.

Tested

The control has been exercised against a defined disruption scenario.

Evidence → posture → action.

The posture is a decision aid. It shows whether critical requirements are demonstrated and where the next intervention matters most.

01 / Input

Evidence

Current artefacts, operating records, monitoring and tests.

02 / Conclusion

Posture

The highest cumulative level whose critical gates are satisfied.

03 / Decision

Action

The gap between required and demonstrated operational control.

The unit of assessment is one bounded service, not the organization as a whole.

Start with Payroll Service. Trace its providers, identities, cloud controls, data interfaces and recovery paths. Then ask what must remain possible.