INVARIANCE | Arc
MenuClose
Industries / Critical infrastructure

Keep essential operations within authority.

High-consequence changes and continued operations when trust is uncertain.

Discuss a workflow ↗
Power infrastructure beside a coastal landscape
Industries

Operational access may be necessary while authority for a particular change remains unresolved. The workflow below illustrates how organizational requirements can vary by result and operating condition.

Representative workflow

Evaluate authority before operational changes take effect.

The workflow is illustrative. Each organization defines its own authority, evidence requirements, exceptions, and operating conditions.

Critical Infrastructure

Operational-technology configuration change before production execution

A proposed configuration change may affect safety, reliability, protection settings, remote operation, authentication, logging, emergency controls, or physical process behavior.

Authority Control point. After the proposed change, target system, operating purpose, safety implications, and required evidence are assembled, but before the configuration is applied to the operational environment.

Normal operations Routine adjustments within approved ranges proceed. Safety and protection changes are deferred or blocked.
Proposed action class
Normal operations
When trust degrades
Restore deliberately
Routine adjustment within approved operating ranges
PermitWithin operating ranges
PermitNarrowed systems and destinations
PermitLimits restored first
Approved mission-essential or safety-preserving operation
PermitWithin approved configuration
PermitWithin restricted conditions
PermitPreserved throughout
Change affecting safety, protection, or sensitive control settings
DeferSafety and protection review
BlockClosed except through emergency controls
DeferReview retained
Nonessential configuration change
PermitWithin approved windows
DeferIndependent confirmation required
PermitReopened through accountable approval
Unsupported remote change to protected functions
BlockOutside supported paths
Block
Block

Workflow references: NERC CIP-010 and NIST guidance on operational technology security. Applicable requirements and revisions must be established for the selected environment.

Sources and evidence →

Illustrative workflow adapted from public regulatory, standards, acquisition, and operational sources. It identifies a recognizable operating sequence and a possible Authority Control point; compliance obligations and sector requirements are determined separately.

Exceptions follow the organization’s review process. A result requiring additional authority, evidence, or review may be deferred and reevaluated when the requirements are resolved. The determinations remain Permit, Defer, and Block.

Related applications

Related critical-infrastructure applications.