K07 · evidence-bundled critical-infrastructure assurance

Management-plane separation and recovery

Direct answer

Separate management networks and identities, require hardware-rooted attestation where available, restrict update authority, and maintain an independently recoverable management baseline.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Context

BMC, hypervisor, firmware, orchestration and network-management planes can bypass workload security and persist below normal monitoring.

Proposed reference decision

Separate management networks and identities, require hardware-rooted attestation where available, restrict update authority, and maintain an independently recoverable management baseline.

Alternatives considered

  • shared production and management network
  • password-only remote management
  • unverified firmware update

Consequences

  • additional identity and key infrastructure
  • stronger update provenance
  • management recovery becomes testable

Defeaters and reversal conditions

  • internet-exposed management interface
  • unsigned firmware
  • shared root credential
  • unrecoverable key service

Source relationships

Use boundary

This record is a proposed reference decision. A competent owner must bind it to actual site constraints, authority, hazards, license conditions, interfaces, implementation evidence, and change control.