Principlev1
Design recovery procedures to function under the degraded
Design recovery procedures to function under the degraded conditions that typically accompany failures, not ideal conditions.
Why This Is a Principle
Derives from Human memory under stress and cognitive load is unreliable (stress impairs memory) and Catastrophic failures in complex systems rarely result from (failures rarely arrive alone). This principle prescribes designing for compound failure scenarios. The lesson explicitly warns against assuming perfect conditions during recovery.