Domain 10Introduced in v1.0

Monitoring and Telemetry

L1L2L330 ACRs (30 defined in current release)

Summary#

Action logging, anomaly alerts, and tamper-evident data

Risk Rationale#

Linked ACR Controls#

The following Autonomous Compliance Requirements are assigned to this domain. Each ACR defines a specific, testable control with its own evaluation method, classification, and evidence requirements.

ACR-10.01

All autonomous actions SHALL be logged with action type, timestamp, input context, decision rational

All autonomous actions SHALL be logged with action type, timestamp, input context, decision rationale, and outcome.

AT+EIAT+EI|Risk weight: 5/10|
L1L2L3
ACR-10.02

Decision boundary logs SHALL record the factors that determined why one action was chosen over alter

Decision boundary logs SHALL record the factors that determined why one action was chosen over alternatives.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.03

The system SHALL provide replay capability allowing operators and auditors to reproduce past behavio

The system SHALL provide replay capability allowing operators and auditors to reproduce past behavior from logged data.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.04

Real-time anomaly alerts SHALL be generated for boundary violations, unusual patterns, and operation

Real-time anomaly alerts SHALL be generated for boundary violations, unusual patterns, and operational anomalies.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-10.05

Telemetry logs SHALL be tamper-evident, with any modification detectable through integrity verificat

Telemetry logs SHALL be tamper-evident, with any modification detectable through integrity verification.

AT+EIAT+EI|Risk weight: 5/10|
L1L2L3
ACR-10.06

Structured logging with consistent schema SHALL enable automated analysis and cross-system correlati

Structured logging with consistent schema SHALL enable automated analysis and cross-system correlation.

EI+ATEI+AT|Risk weight: 4/10|
L1L2L3
ACR-10.07

Telemetry data retention policies SHALL be defined and enforced proportional to the system's risk cl

Telemetry data retention policies SHALL be defined and enforced proportional to the system's risk classification.

EIEvidence Inspection|Risk weight: 3/10|
L1L2L3
ACR-10.08

Dashboard and reporting capabilities SHALL be provided for operational monitoring and compliance ver

Dashboard and reporting capabilities SHALL be provided for operational monitoring and compliance verification.

EI+ATEI+AT|Risk weight: 3/10|
L1L2L3
ACR-10.09

Telemetry infrastructure SHALL NOT itself become a single point of failure for the autonomous system

Telemetry infrastructure SHALL NOT itself become a single point of failure for the autonomous system.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-10.10

Telemetry access controls SHALL prevent unauthorized viewing, modification, or deletion of operation

Telemetry access controls SHALL prevent unauthorized viewing, modification, or deletion of operational logs.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.11

Log collection latency SHALL NOT exceed defined maximum delay from event occurrence to log availabil

Log collection latency SHALL NOT exceed defined maximum delay from event occurrence to log availability.

ATAutomated Testing|Risk weight: 3/10|
L1L2L3
ACR-10.12

The system SHALL implement log rotation and archival without loss of data or query capability.

The system SHALL implement log rotation and archival without loss of data or query capability.

AT+EIAT+EI|Risk weight: 3/10|
L1L2L3
ACR-10.13

Telemetry SHALL capture sufficient context to reconstruct the system's state at any point in time wi

Telemetry SHALL capture sufficient context to reconstruct the system's state at any point in time within the retention window.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.14

The system SHALL implement health and heartbeat monitoring with configurable alerting for missed che

The system SHALL implement health and heartbeat monitoring with configurable alerting for missed check-ins.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-10.15

Telemetry data SHALL be exportable in standardized formats for third-party analysis.

Telemetry data SHALL be exportable in standardized formats for third-party analysis.

EI+ATEI+AT|Risk weight: 3/10|
L1L2L3
ACR-10.16

Cross-organization telemetry correlation SHALL be supported for multi-party autonomous operations.

Cross-organization telemetry correlation SHALL be supported for multi-party autonomous operations.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.17

Telemetry SHALL include performance metrics sufficient for SLA monitoring and compliance.

Telemetry SHALL include performance metrics sufficient for SLA monitoring and compliance.

CM+EICM+EI|Risk weight: 3/10|
L1L2L3
ACR-10.18

Alert fatigue mitigation SHALL be implemented through intelligent alert grouping, deduplication, and

Alert fatigue mitigation SHALL be implemented through intelligent alert grouping, deduplication, and escalation.

EI+ATEI+AT|Risk weight: 3/10|
L1L2L3
ACR-10.19

The system SHALL implement distributed tracing for operations spanning multiple services or componen

The system SHALL implement distributed tracing for operations spanning multiple services or components.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.20

Telemetry collection SHALL be resilient to network partitions with buffering and eventual delivery g

Telemetry collection SHALL be resilient to network partitions with buffering and eventual delivery guarantees.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-10.21

The system SHALL provide configurable telemetry verbosity levels appropriate to operational context.

The system SHALL provide configurable telemetry verbosity levels appropriate to operational context.

EI+ATEI+AT|Risk weight: 3/10|
L1L2L3
ACR-10.22

Telemetry data SHALL be time-synchronized across all system components with documented maximum skew

Telemetry data SHALL be time-synchronized across all system components with documented maximum skew tolerance.

ATAutomated Testing|Risk weight: 3/10|
L1L2L3
ACR-10.23

The system SHALL log all configuration changes with the previous value, new value, change source, an

The system SHALL log all configuration changes with the previous value, new value, change source, and timestamp.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-10.24

Telemetry SHALL support automated compliance checking against ACR requirements.

Telemetry SHALL support automated compliance checking against ACR requirements.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-10.25

The system SHALL implement anomaly detection on telemetry streams to identify unusual behavioral pat

The system SHALL implement anomaly detection on telemetry streams to identify unusual behavioral patterns.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-10.26

Telemetry schema evolution SHALL be backward-compatible to maintain historical query capability.

Telemetry schema evolution SHALL be backward-compatible to maintain historical query capability.

EI+ATEI+AT|Risk weight: 3/10|
L1L2L3
ACR-10.27

Systems certified at Assurance Class B (Monitored) SHALL maintain an active CAPO connection and deli

Systems certified at Assurance Class B (Monitored) SHALL maintain an active CAPO connection and deliver telemetry batches at minimum monthly frequency. A gap of two consecutive months without telemetry batch delivery SHALL be automatically flagged by the CAPO as an Assurance Lapse condition.

CM+ATCM+AT|Risk weight: 4/10|
L1L2L3
ACR-10.28

Systems certified at Assurance Class C (Continuously Assured) SHALL maintain a persistent, real-time

Systems certified at Assurance Class C (Continuously Assured) SHALL maintain a persistent, real-time CAPO telemetry connection. Any telemetry gap exceeding 24 hours (excluding documented scheduled maintenance windows of up to 4 hours, maximum twice per month) SHALL be automatically flagged by the CAPO as an Assurance Lapse condition triggering the 72-hour remediation window.

CM+ATCM+AT|Risk weight: 5/10|
L1L2L3
ACR-10.29

The CAPO SHALL deliver SLA-bound alerting for Assurance Class C systems: Critical-severity complianc

The CAPO SHALL deliver SLA-bound alerting for Assurance Class C systems: Critical-severity compliance events SHALL generate alerts within 5 minutes of detection; Emergency-severity events SHALL generate alerts within 60 seconds. Failure to meet these SLAs for material events constitutes an Assurance Lapse condition.

CM+ATCM+AT|Risk weight: 5/10|
L1L2L3
ACR-10.30

For Platform Certifications, the vendor SHALL document in the Reference Environment Specification wh

For Platform Certifications, the vendor SHALL document in the Reference Environment Specification whether the ARA Behavioral Telemetry SDK is deployed in the reference environment, and if not, the alternative telemetry mechanism used to support ACRs with Continuous or Quarterly evaluation frequency. The AVB SHALL assess whether the documented telemetry mechanism provides evaluation-equivalent coverage.

EI+TIEI+TI|Risk weight: 3/10|
L1L2L3