Control Packs · OBS-003 · v1.0.0

Failure Visibility and Escalation

Decide which failures a person must be told about, who is told, and how fast — so a broken job, a backed-up queue, or a degraded dependency is not discovered by a customer first.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Ensure the conditions that mean the system is not doing its job reach a named person or channel within a confirmed time, and that a swallowed error is never the end of the story.

  • Something is broken and nobody finds out until a customer says soErrors are caught and swallowed, a queue backs up with no threshold, a scheduled job stops running, or a dependency degrades, and none of it reaches a person because nothing states which conditions are worth telling someone about.
Versioned applicability rule
{
  "any": [
    {
      "characteristic": "CONSEQUENTIAL_ACTION",
      "equals": true
    },
    {
      "characteristic": "EXTERNAL_DEPENDENCY",
      "equals": true
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which failures must reach a person, who is told, and how quickly?Alerting everything is the same as alerting nothing. Naming the conditions that matter, and who acts on them, is the decision only you can make.OBS-003-Q1 · scope

Requirements for the coding agent

  • OBS-003-R1Emit a distinguishable signal for each confirmed failure condition, route it to the confirmed recipient within the confirmed time, never discard an error without recording it, and ensure the notification path does not depend solely on the component it reports about.

Tests and evidence to retain

  • FAILURE_VISIBILITY_TESTInduce each confirmed failure condition, including a dependency timeout and a job that does not run at all, and confirm a signal reaches the confirmed recipient rather than only being logged.
  • configuration_or_policy
  • implementation_location
  • test_result
  • telemetry_definition
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • SI-4 · System MonitoringNIST_SP_800_53_5_2_0 · partially addressesEmitting and routing a signal for confirmed failure conditions is monitoring for this system; it does not cover the full control family.
  • AU-6 · Audit Record Review, Analysis, and ReportingNIST_SP_800_53_5_2_0 · informsA confirmed recipient and time for each condition supports review turning a signal into a finding; it is not a complete review programme.
  • IR-4 · Incident HandlingNIST_SP_800_53_5_2_0 · informsGetting a failure to a person is a precondition for incident handling; it does not establish an incident-response capability.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review