Foundational data, standards, and threat case studies that validate the AOT framework. The validation vault.
Industrial Automation and Control Systems Security Standards
Informing the Deterministic Enforcement Engine.
Standard 3-3 (System Security Requirements and Security Levels) dictates the technical capabilities required to secure a zone or conduit. Standard 4-2 defines technical requirements for IACS components.
When generating automated playbooks, the Cognitive Engine cannot propose any boundary shifts that violate the Zones and Conduits access definitions mapped under 62443-3-3.
Guide to Industrial Control Systems (ICS) Security
Justification for the Dual-Engine Isolation model.
Section 3: ICS Security Program Development and Deployment stresses that cybersecurity responses must never undermine physical safety, operational availability, or determinism.
Use this reference to validate why the Advisory LLM is completely air-gapped from direct network command strings.
Malicious Cyber Activity Targeting Safety Instrumented Systems
Proving the requirement for millisecond-scale, deterministic enforcement.
Attackers directly interacted with Triconex Safety Instrumented Systems (SIS) controllers over network lines, injecting malicious code to force an un-commanded safe state trip or mask physical anomalies.
Baseline case study demonstrating why an intermediate Enforcement Engine must analyze network traffic packets natively before they hit the controller backplane.
Analysis of threat actors targeting electrical substations
Proving the limitation of traditional visibility-only software stacks.
Automation of industrial communication protocols (IEC 60870-5-104, IEC 61850, OPC DA) to issue illegitimate breaker open/close loops directly.
Visibility tools alone are inadequate. Once an alert triggers indicating automated protocol looping, time-to-mitigation must drop to milliseconds via micro-segmentation.
Engineering Safety Guardrails for Autonomous Enterprise Orchestrators
Managing the exception-handling feedback loop when the Safety Gate blocks an AI command.
Agent frameworks running local small language models (SLMs) must parse structured constraints (e.g., JSON error schema inputs) to prevent infinite retry loops or parameter hallucination if an environment blocks an execution script.
Serves as the blueprint for Guardrail #3. If the Enforcement Engine rejects a proposed script, it returns an explicit error schema that the agent reads as a raw logic parameter for rapid alternative pathing.
Cross-Sector Cybersecurity Performance Goals Framework
Documenting the workforce capability gap.
Goal 4.1 (Incident Response Planning): Stresses the critical deficiency in skilled ICS incident response personnel across small-to-medium manufacturing and water plants.
The AI's job isn't to take away the operator's control, but to translate raw, dense network artifacts into natural language logs so an over-extended plant operator can confidently handle triage.