K07 · evidence-bundled critical-infrastructure assurance
Management-plane separation and recovery
Direct answer
Separate management networks and identities, require hardware-rooted attestation where available, restrict update authority, and maintain an independently recoverable management baseline.
Context
BMC, hypervisor, firmware, orchestration and network-management planes can bypass workload security and persist below normal monitoring.
Proposed reference decision
Separate management networks and identities, require hardware-rooted attestation where available, restrict update authority, and maintain an independently recoverable management baseline.
Alternatives considered
- shared production and management network
- password-only remote management
- unverified firmware update
Consequences
- additional identity and key infrastructure
- stronger update provenance
- management recovery becomes testable
Defeaters and reversal conditions
- internet-exposed management interface
- unsigned firmware
- shared root credential
- unrecoverable key service
Source relationships
- NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices — National Institute of Standards and Technology; Revision 1 Update 1; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
- CISA Hardware Bill of Materials Framework for Supply Chain Risk Management — Cybersecurity and Infrastructure Security Agency; September 2023 framework; OFFICIAL FRAMEWORK. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
Use boundary
This record is a proposed reference decision. A competent owner must bind it to actual site constraints, authority, hazards, license conditions, interfaces, implementation evidence, and change control.