Telemetry Independence from the Monitored System
Objective
Ensure a compromise of the primary AI/control stack cannot simultaneously blind the monitoring system observing it.
Control / requirement
Monitoring runs on architecturally separate compute (and power domain, where feasible) from the system it observes.
Applicability
Systems where monitoring is relied upon for safety or security assurance, particularly where compute compromise is a credible threat.
Expected evidence
Architecture documentation showing separation; test records demonstrating monitoring survives simulated primary-system compromise. [T3]
Assurance expectation
Test evidence specifically covering the compromise scenario, not only independent-power-loss scenarios.
Dependencies
PAI-SF-SAF-003 (compute-compromise independence) — same architectural pattern applied to observation rather than action.
Exclusions
May be proportionally simplified for systems with negligible consequence from a blinded-monitoring scenario.
Maturity / conformance relevance
Expected at High-Assurance level; Operational level may accept logical (not physical) separation.
Ecosystem relationship
Directly supports AI-IRF™'s ability to investigate an incident where the primary system itself is the suspected compromised party.