Runtime Monitoring & Telemetry
Operational visibility into state, decisions, commands, anomalies and interventions.
Domain controls
The following identifiers, titles, objectives and implementation expectations reproduce the canonical public PAI-SF™ v1.0 Control Catalogue. Evidence requirements, assurance expectations, dependencies, exclusions and conformance relevance remain available in the full catalogue.
Objective: Ensure telemetry cannot be silently altered after collection, including by a compromised primary system attempting to conceal its own anomalous behavior. Requirement: Telemetry cryptographically signed or hash-chained at the point of collection; independent verification of the chain available during investigation.
Objective: Ensure a compromise of the primary AI/control stack cannot simultaneously blind the monitoring system observing it. Requirement: Monitoring runs on architecturally separate compute (and power domain, where feasible) from the system it observes.
Objective: Ensure telemetry actually captures the signals needed to detect the specific threats in the Section 5 threat catalog, rather than collecting data volume without detection relevance. Requirement: Periodic validation injecting known threat patterns (simulated sensor spoofing, simulated actuator anomaly) and confirming telemetry would have surfaced them.
Objective: Ensure telemetry is retained and access-controlled sufficiently to support post-incident investigation and potential regulatory or legal proceedings. Requirement: Defined retention period, access logging, and custody documentation sufficient to establish evidentiary integrity if telemetry is later relied upon outside the organization.