K07 · evidence-bundled critical-infrastructure assurance

Restoration known-good chain

Direct answer

Maintain immutable or protected manifests, clean-room recovery, independent key and artifact verification, sequenced restoration, and post-restoration monitoring before readiness is restored.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Context

Recovery can reintroduce compromise when backups, firmware, model artifacts, keys or deployment tools are not independently trusted.

Proposed reference decision

Maintain immutable or protected manifests, clean-room recovery, independent key and artifact verification, sequenced restoration, and post-restoration monitoring before readiness is restored.

Alternatives considered

  • restore latest backup without validation
  • rebuild from mutable internet sources
  • reuse compromised management plane

Consequences

  • recovery evidence is part of readiness
  • supply-chain and key dependencies are explicit
  • negative restoration results block operation claims

Defeaters and reversal conditions

  • unknown backup provenance
  • unverified firmware
  • compromised signing key
  • no clean deployment environment

Source relationships

Use boundary

This record is a proposed reference decision. A competent owner must bind it to actual site constraints, authority, hazards, license conditions, interfaces, implementation evidence, and change control.