dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-03-twin-node-requirements:twin-010-control-twin-interaction:twin-010d-prevent-unauthorized-resource-state-changes

TWIN-010d — Prevent Unauthorized Resource State Changes

The DIDO-TE SHALL prevent each unauthorized interaction from changing the state of a Resource.

TWIN-010c requires authorization for permitted interactions that change the state of a Resource.

This requirement enforces that authorization requirement by preventing an interaction without the required authorization from changing Resource state.

Separating the authorization requirement from enforcement allows the two obligations to be verified independently. A system may determine that authorization is required while failing to prevent an unauthorized state change.

Technical connectivity, interface availability, DDS discovery, Topic matching, or other implementation mechanisms do not provide authorization to change Resource state.

Verification confirms that:

  1. An interaction lacking required authorization does not change Resource state.
  2. An interaction for which authorization is denied does not change Resource state.
  3. Authorization for one interaction does not authorize a different interaction.
  4. Authorization associated with one Resource does not authorize a state change to another Resource.
  5. Prevention of the unauthorized state change is traceable to the attempted interaction and authorization decision.

Verification includes an unauthorized interaction that attempts to change Resource state and confirms that the Resource state remains unchanged.

This requirement enforces the authorization requirement established by TWIN-010c by preventing unauthorized changes to Resource state.

TBD

Draft

{{section>dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-03-twin-node-requirements:twin-010-control-twin-interaction:twin-010d-prevent-unauthorized-resource-state-changes#Statement&noheader&nofooter&noeditbtn}}

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/03-dido-te/99-annexes/annex-c-requirements/03-functional-requirements/03-03-twin-node-requirements/twin-010-control-twin-interaction/twin-010d-prevent-unauthorized-resource-state-changes.txt
  • Last modified: 2026/08/21 17:36
  • by nick_dido