PAI-SF / 7 / PAI-SF-TEL-002

Telemetry Independence from the Monitored System

Objective

Ensure a compromise of the primary AI/control stack cannot simultaneously blind the monitoring system observing it.

Control / requirement

Monitoring runs on architecturally separate compute (and power domain, where feasible) from the system it observes.

Applicability

Systems where monitoring is relied upon for safety or security assurance, particularly where compute compromise is a credible threat.

Expected evidence

Architecture documentation showing separation; test records demonstrating monitoring survives simulated primary-system compromise. [T3]

Assurance expectation

Test evidence specifically covering the compromise scenario, not only independent-power-loss scenarios.

Dependencies

PAI-SF-SAF-003 (compute-compromise independence) — same architectural pattern applied to observation rather than action.

Exclusions

May be proportionally simplified for systems with negligible consequence from a blinded-monitoring scenario.

Maturity / conformance relevance

Expected at High-Assurance level; Operational level may accept logical (not physical) separation.

Ecosystem relationship

Directly supports AI-IRF™'s ability to investigate an incident where the primary system itself is the suspected compromised party.

Domain

Domain 7. Runtime Monitoring and Telemetry

Download full Control Catalogue ↓