Incident Response & Physical Recovery
Containment, restoration, investigation and learning after physical-AI events.
Domain controls
The following identifiers, titles, objectives and implementation expectations reproduce the canonical public PAI-SF™ v1.0 Control Catalogue. Evidence requirements, assurance expectations, dependencies, exclusions and conformance relevance remain available in the full catalogue.
Objective: Provide predefined, tested procedures for physically containing an active incident, distinct from digital containment. Requirement: Playbooks per system class with defined roles and physical isolation steps (e.g., actuator isolation, area securing).
Objective: Preserve perishable physical evidence (sensor state, actuator position, environmental conditions at incident time) before it is lost or altered. Requirement: Automated snapshot/freeze of relevant telemetry and physical state upon incident declaration.
Objective: Ensure systems involved in an incident undergo physical HITL revalidation, not merely software review, before returning to operation. Requirement: Mandatory HITL test pass tied to root-cause-specific scenarios before reactivation.