Privacy & Compliance
Maintain lawful, governed access to sensitive information and the ability to demonstrate how data is protected across dependencies.
Framework
OSAF moves from the outcome the business needs to the capabilities, dependencies and evidence that determine whether a critical service remains governable.
Assessment-first · Service-level · Evidence-ledDefinition
The definition focuses on what the organization can do under a consequential loss of cooperation—not on provider nationality or data location alone.
“The demonstrable ability to continue, control, recover, change or exit a critical digital service when an external dependency cannot or will not cooperate.”
Why control is required
The desired outcome establishes the consequence before the assessment prescribes a control or target posture.
Maintain lawful, governed access to sensitive information and the ability to demonstrate how data is protected across dependencies.
Keep essential service outcomes available or recoverable through provider failure, constraint or loss of cooperation.
Preserve credible substitution and exit paths so dependency does not become irreversible lock-in.
Retain the ability to adapt architecture, operating models and providers as policy, technology and risk conditions change.
What must remain possible
Capabilities translate an outcome into consequential actions the organization must be able to exercise.
Set direction, approve exceptions and retain accountable decision rights.
Administer the service, identities, configurations and operating controls.
Recover the service and its information within the required business timeframe.
Move data, replace dependencies and execute a viable exit path.
Change, patch and evolve the service as requirements and threats change.
Observe, test and independently evaluate whether required controls work.
Where control is examined
Each capability can cross several domains. Hover or focus a domain to see the dependency questions it opens.
Physical, virtual and facility operating paths.
Administrative APIs, tenancy and provider control.
Access, portability, keys and recoverability.
Authentication, authorization and break-glass control.
Runtime, interfaces, licensing and portability.
Model access, inference, safeguards and substitutes.
Detection, containment and recovery evidence.
Source, build, artefact and deployment trust.
Routes, diversity and out-of-band access.
Rights, obligations, jurisdiction and accountability.
Evidence maturity
A control conclusion becomes stronger when it is implemented, observed and exercised against the scenario that matters.
The control has been exercised against a defined disruption scenario.
Assessment method
The posture is a decision aid. It shows whether critical requirements are demonstrated and where the next intervention matters most.
Current artefacts, operating records, monitoring and tests.
The highest cumulative level whose critical gates are satisfied.
The gap between required and demonstrated operational control.
The unit of assessment is one bounded service, not the organization as a whole.
Start with Payroll Service. Trace its providers, identities, cloud controls, data interfaces and recovery paths. Then ask what must remain possible.