TWIN-009c requires authorization for permitted interactions that change the state of a Resource.
This requirement enforces that authorization prerequisite by preventing an unauthorized interaction from changing Resource state.
Separating the authorization requirement from enforcement allows the two obligations to be verified independently. A system may correctly determine that authorization is required while failing to prevent an unauthorized state change.
Technical connectivity, interface availability, DDS discovery, Topic matching, or other implementation mechanisms do not provide authorization to change Resource state.
Verification confirms that:
Verification includes an unauthorized interaction that attempts to change Resource state and confirms that the Resource state remains unchanged.
This requirement enforces the authorization prerequisite established by TWIN-009c by preventing unauthorized changes to Resource state.
TBD
Draft
{{section>dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-03-twin-node-requirements:twin-009-control-twin-interaction:twin-009d-prevent-unauthorized-resource-state-changes#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.