Critical Infrastructure & Resilience
Critical-infrastructure resilience depends on keeping essential services operating, limiting compromise, and recovering safely when components fail.
Essential services rely on technology that must continue through faults, attack, maintenance, and supply-chain change. A security policy should therefore address prevention, containment, detection, response, recovery, and safe degradation.
What capability protection contributes
CHERI can prevent certain invalid memory accesses in covered software. Compartments can restrict an exposed or lower-trust component to explicitly delegated memory and services. These mechanisms can support policy outcomes such as reducing attack paths, limiting lateral movement within a device, and containing the consequences of a software defect.
They do not provide service continuity alone. Operators still need asset knowledge, network architecture, identity and access control, secure configuration, monitoring, incident response, backup, recovery, physical protection, and tested manual alternatives.
Policy and assurance questions
- Which essential functions and unacceptable consequences drive the requirement?
- Which memory-unsafe components can directly influence those functions?
- What remains accessible if each exposed component is compromised?
- Does a capability fault lead to safe recovery, degraded service, or an outage?
- Can suppliers maintain the hardware, toolchain, and software for the asset lifetime?
- What evidence can be shared with operators, authorities, and assessors?
Introduce change safely
Critical environments often cannot replace an entire estate at once. Policy can support adoption through reference architectures, evaluated gateways, test facilities, procurement requirements, and refresh-cycle pilots. New controls should be tested with realistic load, failure, and recovery scenarios before they become a dependency of an essential service.
Use CHERI claims in the language of outcomes. “The network parser cannot access control state” is more useful than “the device uses CHERI.” Link the claim to a configuration, evidence, and accountable owner.
For broader risk-management context, consult the applicable national framework, such as the UK NCSC Cyber Assessment Framework or the EU NIS2 policy material.
