PAI-SF / 7 / PAI-SF-TEL-003

Coverage Validation Against the Threat Model

Objective

Ensure telemetry actually captures the signals needed to detect the specific threats in the Section 5 threat catalog, rather than collecting data volume without detection relevance.

Control / requirement

Periodic validation injecting known threat patterns (simulated sensor spoofing, simulated actuator anomaly) and confirming telemetry would have surfaced them.

Applicability

All physical AI systems with a defined threat model.

Expected evidence

Coverage test records mapped to specific threat-catalog entries. [T3]

Assurance expectation

Evidence that coverage validation is repeated as the threat catalog is updated, not a one-time exercise.

Dependencies

Section 5 threat and hazard catalog (this control is only as good as the catalog it's validated against).

Exclusions

Not applicable to threat categories explicitly out of scope for the deployed system class.

Maturity / conformance relevance

Expected at Operational and High-Assurance levels.

Ecosystem relationship

This is the control that most directly proves Domain 7 is not merely a service function for other domains — it is an audit of the collection system's own fitness for purpose.

Domain

Domain 7. Runtime Monitoring and Telemetry

Download full Control Catalogue ↓