Section 88 of 101
87. Fault Containment
Stable section ID: S05-CON-006-SECTION-88 · 36 content blocks
Fault Containment limits the spread of physical, electrical, fluid, digital, control, and security failures.
Containment boundaries may include:
Component;
Cartridge;
Interface;
room;
building zone;
utility branch;
network segment;
BIOS service;
BIOS node;
complete building.
The containment strategy shall identify:
initiating fault;
propagation paths;
affected dependencies;
isolation mechanism;
protected unaffected systems;
degraded operating condition;
restoration sequence.
Containment mechanisms may include:
structural isolation or temporary support;
electrical protective devices;
fluid shutoff;
fire and smoke barriers;
network segmentation;
process isolation;
service sandboxing;
credential revocation;
command blocking;
- selective shutdown.
- The BIOS shall use the Dependency Map to avoid containment actions that create a greater secondary hazard.
A compromised manufacturer service, occupant device, or experimental Cartridge shall be isolatable without disabling unrelated essential BIOS functions.
Fault containment shall preserve forensic and engineering evidence where possible. Isolation shall not erase the events required to determine cause.
After containment, the system shall verify that the boundary is effective and identify any residual risk.
Reintegration shall require confirmation that the cause has been removed and that affected components, credentials, configurations, and services remain trustworthy.