K07 · evidence-bundled critical-infrastructure assurance
Restoration known-good chain
Direct answer
Maintain immutable or protected manifests, clean-room recovery, independent key and artifact verification, sequenced restoration, and post-restoration monitoring before readiness is restored.
Context
Recovery can reintroduce compromise when backups, firmware, model artifacts, keys or deployment tools are not independently trusted.
Proposed reference decision
Maintain immutable or protected manifests, clean-room recovery, independent key and artifact verification, sequenced restoration, and post-restoration monitoring before readiness is restored.
Alternatives considered
- restore latest backup without validation
- rebuild from mutable internet sources
- reuse compromised management plane
Consequences
- recovery evidence is part of readiness
- supply-chain and key dependencies are explicit
- negative restoration results block operation claims
Defeaters and reversal conditions
- unknown backup provenance
- unverified firmware
- compromised signing key
- no clean deployment environment
Source relationships
- NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices — National Institute of Standards and Technology; Revision 1 Update 1; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
- Federal Acquisition Regulation Part 46 — Quality Assurance — Federal Acquisition Regulatory Council; FAC 2026 current text reviewed 2026-08-15; CURRENT FEDERAL ACQUISITION REGULATION. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
Use boundary
This record is a proposed reference decision. A competent owner must bind it to actual site constraints, authority, hazards, license conditions, interfaces, implementation evidence, and change control.