Research Reference Index

Foundational data, standards, and threat case studies that validate the AOT framework. The validation vault.

Category 1: Industrial Safety & Architectural Standards

REF-001

ISA/IEC 62443 Series

Industrial Automation and Control Systems Security Standards

Core Application to AOT

Informing the Deterministic Enforcement Engine.

Key Context

Standard 3-3 (System Security Requirements and Security Levels) dictates the technical capabilities required to secure a zone or conduit. Standard 4-2 defines technical requirements for IACS components.

Agent Context Mapping

When generating automated playbooks, the Cognitive Engine cannot propose any boundary shifts that violate the Zones and Conduits access definitions mapped under 62443-3-3.

REF-002

NIST Special Publication 800-82

Guide to Industrial Control Systems (ICS) Security

Core Application to AOT

Justification for the Dual-Engine Isolation model.

Key Context

Section 3: ICS Security Program Development and Deployment stresses that cybersecurity responses must never undermine physical safety, operational availability, or determinism.

Agent Context Mapping

Use this reference to validate why the Advisory LLM is completely air-gapped from direct network command strings.

Category 2: Historical Threat Context & Speed Proof-Points

REF-003

CISA Alert AA23-103A — TRITON/TRISIS Malware

Malicious Cyber Activity Targeting Safety Instrumented Systems

Core Application to AOT

Proving the requirement for millisecond-scale, deterministic enforcement.

Key Context

Attackers directly interacted with Triconex Safety Instrumented Systems (SIS) controllers over network lines, injecting malicious code to force an un-commanded safe state trip or mask physical anomalies.

Agent Context Mapping

Baseline case study demonstrating why an intermediate Enforcement Engine must analyze network traffic packets natively before they hit the controller backplane.

REF-004

Industroyer / CrashOverride

Analysis of threat actors targeting electrical substations

Core Application to AOT

Proving the limitation of traditional visibility-only software stacks.

Key Context

Automation of industrial communication protocols (IEC 60870-5-104, IEC 61850, OPC DA) to issue illegitimate breaker open/close loops directly.

Agent Context Mapping

Visibility tools alone are inadequate. Once an alert triggers indicating automated protocol looping, time-to-mitigation must drop to milliseconds via micro-segmentation.

Category 3: Agentic AI & Deterministic Engineering Runtimes

REF-005

Hardening Agentic Systems & LLM Latency Bounds (2025–2026)

Engineering Safety Guardrails for Autonomous Enterprise Orchestrators

Core Application to AOT

Managing the exception-handling feedback loop when the Safety Gate blocks an AI command.

Key Context

Agent frameworks running local small language models (SLMs) must parse structured constraints (e.g., JSON error schema inputs) to prevent infinite retry loops or parameter hallucination if an environment blocks an execution script.

Agent Context Mapping

Serves as the blueprint for Guardrail #3. If the Enforcement Engine rejects a proposed script, it returns an explicit error schema that the agent reads as a raw logic parameter for rapid alternative pathing.

Category 4: Workforce & Human Factor Dynamics

REF-006

CISA Cybersecurity Performance Goals (CPGs)

Cross-Sector Cybersecurity Performance Goals Framework

Core Application to AOT

Documenting the workforce capability gap.

Key Context

Goal 4.1 (Incident Response Planning): Stresses the critical deficiency in skilled ICS incident response personnel across small-to-medium manufacturing and water plants.

Agent Context Mapping

The AI's job isn't to take away the operator's control, but to translate raw, dense network artifacts into natural language logs so an over-extended plant operator can confidently handle triage.

← Back to AOT Framework Overview